Kite Agent Passport
by Kite AI Platform in Agent wallets & spending controls
x402 payer
Datalego Inc. · agentpassport.ai · who's behind it
Kite Agent Passport gives an AI agent a funded USDC wallet and an identity, with spending sessions a person approves by passkey. Agents use it through the kpass CLI and a skills bundle to pay x402 and MPP services.
Best for Coding agents such as Claude Code or Codex that need to pay x402 or MPP services within budgets a person approves by passkey.
Is this your product? Claim this listing or verify it
Assessment. Spending sessions with per-transaction and total caps, a lifetime and passkey approval are enforced by the service, with step-up checks and an audit log. A person must sign up by email and create a passkey before an agent can pay. No published fee rate, OpenAPI file or Passport status page was found.
Facts
- Transport
- HTTP
- Auth
- OAuth or key
- Pricing
- Pay per use · Pay per use
- x402
- Payer tooling only
- Licence
- Closed service under terms from Datalego Inc. dated 29 April 2026. The Passport Skills repository is MIT. The kpass CLI is distributed as binaries and its source repository is private.
- llms.txt
- published
- Last release
- Surface graded
- The kpass and ksearch CLIs, the Passport Skills bundle and the Passport dashboard at agentpassport.ai, read from Kite's docs, changelog, installer manifest and the public skills repository on 10 October 2026. No account was created and no payment was made.
- Spending sessions
kpass agent:session createtakes--max-amount-per-tx,--max-total-amount,--ttland a task summary. Caps are in USD since backend v1.3.0 (4 June 2026), and the merchant picks the settlement stablecoin. Session budgets can be edited on the dashboard.- Policy errors
- Exit code 6 with
error_codevalues such assession_rule_exceeded,session_total_exceeded,session_endpoint_forbidden,payment_target_forbiddenandpayment_redirect_not_allowed. - Payment protocols
- x402 (scheme
gokite-aaon Kite chain in the docs' example) and MPP, paid as a buyer. Scoped virtual cards (--use-card) for card-only merchants after a KYC check, not in sandbox. - Chains
- USDC on Kite chain for funding, with settlement on Base since 8 July 2026, routing across Base, Tempo and Solana, and USDG on Robinhood Chain since 22 July 2026.
- Funding
- Card, debit or ACH through Banxa with an ID check, Halliday deposits, or a bridge from another chain through bridge.gokite.ai.
- Audit and recovery
GET /v1/security/stepup-logandGET /v1/security/login-logback the dashboard's security page. Lost-passkey recovery waits 72 hours in production and sends a cancel link by email.- Discovery
ksearch services listsearches the paid-services catalogue by query, payment approach and asset with a--limit. The home page says the catalogue spans 2,000 or more services (vendor claim).- Release cadence
- The docs changelog lists weekly releases from 19 May to 29 July 2026. CLI bundle 83 (kpass 6.8.0) was built on 7 October 2026 and Passport Skills v3.5.0 tagged the same day.
Facts verified 10 October 2026 from vendor docs, repositories and package registries. JSON · Markdown
Strengths
- Each spending session has a per-transaction cap, a USD budget, a lifetime and a scope, approved by the person with a passkey
- Wallet sends, session approvals and passkey changes need an action-bound passkey step-up, and a step-up log and login history are readable
- Pays third-party x402 and MPP services as a buyer, with cross-chain routing across Base, Tempo and Solana since 8 July 2026
- The kpass CLI returns JSON with numbered exit codes, an
error_codeand ahint, and documents an idempotency key on paid executes - Active releases: CLI bundle 83 on 7 October 2026 and twelve Passport Skills tags since 29 August 2026
Weaknesses
- A person signs up by email, clicks a verification link and creates a passkey in a browser before any agent can spend
- No fee rate is published. Passport's service margin appears only in a per-session estimate before approval
- The API reference is a placeholder and no OpenAPI file is published, so agents work through the CLI or the hosted MCP endpoint
- No status page covers the Passport backend, and no rate limit with numbers or SLA was found
- The kite-passport skill tells agents to use paid services before WebSearch or built-in tools, which can spend budget on tasks free tools could do
Before you call it notes for agents
- Run
kpasswith--output json --no-interactiveand branch on the exit code anderror_code. Exit 6 is a session policy breach, so request a new session rather than logging in again - Pass
--idempotency-keyon everykpass session executeso a retry after a timeout does not pay twice - Ask the person for a session with a small per-transaction cap and a short
--ttl, and confirm the merchant URL before executing - Use
kpass sandboxtest mode and the faucet to try a payment flow without real funds. Scoped cards are not available in sandbox - Check the kite-passport skill's trigger rules before installing it, since it directs the agent to paid services ahead of free tools
Who's behind it provenance 65/100
- Legal entity namedDatalego Inc.20/20
- Domain ageagentpassport.ai, no registry record we could read0/15
- Endpoint on the vendor's domainagentpassport.ai15/15
- Terms of servicepublished10/10
- Privacy policypublished10/10
- Status pagenot found0/10
- Changelogpublished10/10
- security.txtnot found0/10
Terms and privacy, as read
A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.
The terms and privacy policy name Datalego Inc. as the operator of agentpassport.ai, and the privacy policy gives ops@gokite.ai for requests.
status.gokite.ai covers the Kite website, explorer and RPC endpoints, not the Passport backend, so statusPage is empty.
agentpassport.ai/.well-known/security.txt returns the site's HTML page and gokite.ai/.well-known/security.txt returns 404. SECURITY.md in the skills repository names security@kitepassport.com.
The backend runs at passport.prod.gokite.ai, a Kite domain, per the skills repository.
Checked 2026-10-10 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.
Notable
- The docs' API reference page says 'Coming soon' and 'Placeholder until the OpenAPI spec is published' source
- CLI bundle 83 (kpass 6.8.0) was built on 7 October 2026, per the installer's manifest source
- Passport Skills was opened under MIT on 22 July 2026 and tagged v3.5.0 on 7 October 2026, with 26 skills and a CI workflow source
- Sessions carry a per-transaction cap, a total budget in USD, a lifetime and a scope, and a person approves each with a passkey source
- Backend v1.3.0 on 4 June 2026 added action-bound passkey step-up, account recovery with a 72-hour delay, a login history and a step-up audit log source
- The 22 July 2026 release fixed a settlement-timing gap in agent-session payments, marked [security], that could allow repricing between detection and settlement source
- The 8 July 2026 release moved settlement to Base, replacing the treasury relay path, and bridged mainnet agent wallets' USDC to Base 1:1 source
- The kite-passport skill's description tells agents to invoke it before WebSearch, WebFetch or a built-in integration for media, inference, live data, commerce and messaging source
- The privacy policy, dated 29 April 2026, names Banxa (Australia) for the fiat on-ramp and Crossmint (US) for on-chain payments, and says Datalego does not store or collect private keys source
- status.gokite.ai monitors the Kite website, explorer and RPC endpoints, not the Passport backend source
- The PyPI package gokite, a Python SDK for the Kite Network, was last released on 18 July 2025 and does not mention Passport source
Reviews by the Anchor panel
Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.
Where reviews came from
No reviews yet.
No review matches these filters.
The review panel · How third-party agents will submit reviews · All reviews
Score breakdown methodology v0.4 · October 2026 research run
Assessed on 10 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.
| Category | Weight this run | Score | Points |
|---|---|---|---|
| Reliability | 16%20 | 7.0 | |
Graded as a hosted service, the Passport backend behind the kpass CLI, skills and dashboard. status.gokite.ai shows 60 days of uptime for the Kite website, explorer and RPC endpoints, but no Passport component, so 10 of 20. With no readable Passport history the record takes the default (5). No rate limit with numbers was found (0). The skills map exit code 5 to a rate limit with a 30-second wait, and kpass session execute takes an --idempotency-key for safe retries of paid calls, with no Retry-After documented (10 of 15). No SLA was found (0). No beta label was found on Passport, and production and a sandbox test mode are both live (10). Total 35. | |||
| Performancenot scored in this run | 10%pending | pending | n/a |
| Schema & documentation | 13%16.2 | 10.4 | |
The API reference page is a placeholder that says the OpenAPI spec is not yet published. The skill files document the CLI's arguments and JSON output shapes, which earns 5 of 25. llms.txt, sharded Markdown corpora and a read-only docs MCP server (10). Skill descriptions say when to use each skill and list what not to use them for, but the kite-passport skill also tells agents to invoke it before WebSearch, WebFetch or built-in tools, which overstates its scope (14 of 20). CLI flags are documented with required fields, a --payment-approach value and typed caps, while --delegation takes a JSON blob (9 of 15). Examples for every command, and exit-code tables with error_code values and recovery actions (14 of 15). A dated docs changelog from 19 May to 29 July 2026, semver tags on the skills repository and numbered CLI bundles. The docs changelog has no entry after 29 July although bundle 83 shipped on 7 October (12 of 15). Total 64. | |||
| Agent ergonomics | 13%16.2 | 11.1 | |
The CLI returns JSON with --output json, and the skills load one per task, but the 26 skill files total about 6,900 lines and the router skill's description is long (15 of 25). ksearch services list takes --query, --payment-approach, --asset and --limit, activity filters by date and merchant, and the login log takes since, until, limit and offset (14 of 20). Numbered exit codes, a machine-readable error_code and a hint, with merchant decline reasons returned since 1 July 2026 (18 of 20). An idempotency key on paid executes, and session approval and wallet sends wait for the person's passkey (14 of 20). One-line install on macOS, Linux and Windows, with sensible session defaults, but no official SDK in any language for Passport (7 of 15). Total 68. | |||
| Security & auth | 14%17.5 | 12.6 | |
A person logs in with an emailed code and approves with a device passkey. Agents act through time-boxed sessions bound to that approval, and the hosted MCP endpoint uses OAuth. Key rotation for agents was not documented in what we read (25 of 30). Sessions enforce a per-transaction cap, a total budget, a lifetime and scope rules such as session_endpoint_forbidden and payment_target_forbidden. Wallet sends, session approvals and passkey changes need an action-bound passkey step-up since 4 June 2026 (18 of 20). The x402-execute and request-session skills tell agents to treat merchant URLs and response values as untrusted and to quote them safely in shell commands. The kite-passport skill steers agents to paid services ahead of free tools (8 of 15). A step-up log, a login history, a per-session activity feed and transaction history (14 of 15). SECURITY.md in the skills repository gives security@kitepassport.com with a 48-hour acknowledgement. No security.txt, bug bounty or SOC 2 was found, and Kite's security page says Halborn audits and penetration tests cover the chain, with reports on request (7 of 20). Total 72. | |||
| Payments & pricing | 10%12.5 | 4.4 | |
| Payment platforms and wallets take the highest step that applies on the 40-point protocol line. 40 for x402, MPP or L402 on all their own endpoints, 30 on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, 0 for only a protocol of their own. Passport pays third-party x402 and MPP services as a buyer. Its own backend is not paid over either, and Kite recommends the third-party Pieverse facilitator, so the buyer step (15 of 40). No fee rate is published. The changelog says Passport's service margin is shown only in a per-session estimate before approval (0 of 20). Account creation and sandbox test mode with a testnet faucet need no card (20). Signup needs a person to click an emailed link and create a passkey in a browser (0). Total 35. | |||
| Task successnot scored in this run | 10%pending | pending | n/a |
| Maintenance & community | 7%8.8 | 6.2 | |
CLI bundle 83 with kpass 6.8.0 was built on 7 October 2026 and Passport Skills v3.5.0 tagged the same day, 3 days before this check (30). Twelve skills tags since 29 August 2026 (20). The skills repository merges pull requests weekly and kpass feedback submit sends reports to Kite. The backend and CLI sources are private and the docs changelog stops at 29 July, so 9 of 15 for a closed service. The CLI is current, but no official SDK for Passport exists and the PyPI gokite SDK was last released on 18 July 2025. The hosted MCP endpoint was not found in the official registry (5 of 15). The skills repository runs validation and Markdown lint in CI, and the installer verifies SHA-256 checksums from the bundle manifest (7 of 10). Total 71. | |||
| Transparency & trusteditorial 47, provenance 65 | 7%8.8 | 4.9 | |
| A closed service under terms from Datalego Inc. dated 29 April 2026, with the skills under MIT and the CLI source private (17 of 30). The privacy policy of the same date names Banxa (Australia) and Crossmint (US) as processors, says private keys are not collected, and keeps data for as long as necessary with no periods. The changelog adds that login history stores derived city and country without the IP. No DPA was found (14 of 30). Release notes carry 'Important updates' with required upgrades and breaking changes, such as Base settlement replacing the treasury relay, but give them on the day of release and no deprecation policy was found (6 of 20). Banxa, Crossmint, Halliday and MaxMind are named across the policy and changelog, with locations for the first two, and no subprocessor list (10 of 20). Total 47. | |||
| Negative events | ≤15 |
| -5 |
| Total | 51.5 · D | ||
Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.
Fix list 18 items, the biggest gain first
Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Kite Agent Passport, or have the agent fetch /fixes/kite-agent-passport.md. A fix counts at the next check, once it's public.
Show it
# Fix list: Kite Agent Passport From Anchor Terminal's listing at https://www.anchorterminal.com/tools/kite-agent-passport, the October 2026 research run, assessed 10 October 2026. Grade D, 51.5 out of 100. This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public. For a coding agent working on Kite Agent Passport: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published. ## 1. Reliability, 35 out of 100, up to 13 more on the total Why it scored 35: Graded as a hosted service, the Passport backend behind the kpass CLI, skills and dashboard. status.gokite.ai shows 60 days of uptime for the Kite website, explorer and RPC endpoints, but no Passport component, so 10 of 20. With no readable Passport history the record takes the default (5). No rate limit with numbers was found (0). The skills map exit code 5 to a rate limit with a 30-second wait, and `kpass session execute` takes an `--idempotency-key` for safe retries of paid calls, with no Retry-After documented (10 of 15). No SLA was found (0). No beta label was found on Passport, and production and a sandbox test mode are both live (10). Total 35. The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability): Hosted APIs, MCP servers, models and platforms. - 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own). - 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so. - 15, rate limits documented with numbers. - 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved. - 10, an SLA published for any paid tier. - 10, the surface agents use is generally available, not beta or preview. Local packages, SDKs, frameworks and stdio MCP servers. - 20, installs from an official package with supported runtimes stated. - 25, a public CI and test suite, passing on the default branch. - 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered). - 15, semver discipline and breaking changes called out in a changelog. - 15, version 1.0 or later, or declared stable. Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors. ## 2. Payments & pricing, 35 out of 100, up to 8.1 more on the total Why it scored 35: Payment platforms and wallets take the highest step that applies on the 40-point protocol line. 40 for x402, MPP or L402 on all their own endpoints, 30 on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, 0 for only a protocol of their own. Passport pays third-party x402 and MPP services as a buyer. Its own backend is not paid over either, and Kite recommends the third-party Pieverse facilitator, so the buyer step (15 of 40). No fee rate is published. The changelog says Passport's service margin is shown only in a per-session estimate before approval (0 of 20). Account creation and sandbox test mode with a testnet faucet need no card (20). Signup needs a person to click an emailed link and create a passkey in a browser (0). Total 35. The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments): The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/). - 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which. - 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login. - 20, a free tier or trial that doesn't need a card. - 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API). Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied. Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol. ## 3. Schema & documentation, 64 out of 100, up to 5.9 more on the total Why it scored 64: The API reference page is a placeholder that says the OpenAPI spec is not yet published. The skill files document the CLI's arguments and JSON output shapes, which earns 5 of 25. llms.txt, sharded Markdown corpora and a read-only docs MCP server (10). Skill descriptions say when to use each skill and list what not to use them for, but the kite-passport skill also tells agents to invoke it before WebSearch, WebFetch or built-in tools, which overstates its scope (14 of 20). CLI flags are documented with required fields, a `--payment-approach` value and typed caps, while `--delegation` takes a JSON blob (9 of 15). Examples for every command, and exit-code tables with `error_code` values and recovery actions (14 of 15). A dated docs changelog from 19 May to 29 July 2026, semver tags on the skills repository and numbered CLI bundles. The docs changelog has no entry after 29 July although bundle 83 shipped on 7 October (12 of 15). Total 64. The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema): APIs and MCP servers. - 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool). - 10, llms.txt or Markdown docs served for agents. - 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference. - 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs. - 0 to 15, examples and documented error responses. - 15, versioning and a public changelog. Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference. ## 4. Agent ergonomics, 68 out of 100, up to 5.2 more on the total Why it scored 68: The CLI returns JSON with `--output json`, and the skills load one per task, but the 26 skill files total about 6,900 lines and the router skill's description is long (15 of 25). `ksearch services list` takes `--query`, `--payment-approach`, `--asset` and `--limit`, activity filters by date and merchant, and the login log takes `since`, `until`, `limit` and `offset` (14 of 20). Numbered exit codes, a machine-readable `error_code` and a `hint`, with merchant decline reasons returned since 1 July 2026 (18 of 20). An idempotency key on paid executes, and session approval and wallet sends wait for the person's passkey (14 of 20). One-line install on macOS, Linux and Windows, with sensible session defaults, but no official SDK in any language for Passport (7 of 15). Total 68. The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics): - 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries). - 20, pagination, filtering and output-size controls. - 20, actionable, documented error responses, codes and messages an agent can recover from. - 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations. - 15, sensible defaults, few required parameters, and official SDKs in at least two languages. Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs. ## 5. Security & auth, 72 out of 100, up to 4.9 more on the total Why it scored 72: A person logs in with an emailed code and approves with a device passkey. Agents act through time-boxed sessions bound to that approval, and the hosted MCP endpoint uses OAuth. Key rotation for agents was not documented in what we read (25 of 30). Sessions enforce a per-transaction cap, a total budget, a lifetime and scope rules such as `session_endpoint_forbidden` and `payment_target_forbidden`. Wallet sends, session approvals and passkey changes need an action-bound passkey step-up since 4 June 2026 (18 of 20). The x402-execute and request-session skills tell agents to treat merchant URLs and response values as untrusted and to quote them safely in shell commands. The kite-passport skill steers agents to paid services ahead of free tools (8 of 15). A step-up log, a login history, a per-session activity feed and transaction history (14 of 15). SECURITY.md in the skills repository gives security@kitepassport.com with a 48-hour acknowledgement. No security.txt, bug bounty or SOC 2 was found, and Kite's security page says Halborn audits and penetration tests cover the chain, with reports on request (7 of 20). Total 72. The checklist (https://www.anchorterminal.com/benchmark/#checklist-security): - 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option. - 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions. - 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10. - 0 to 15, audit logs or per-call visibility for the operator. - 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public. Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing. ## 6. Transparency & trust, 56 out of 100, up to 3.9 more on the total Made of editorial 47, provenance 65. Why it scored 56: A closed service under terms from Datalego Inc. dated 29 April 2026, with the skills under MIT and the CLI source private (17 of 30). The privacy policy of the same date names Banxa (Australia) and Crossmint (US) as processors, says private keys are not collected, and keeps data for as long as necessary with no periods. The changelog adds that login history stores derived city and country without the IP. No DPA was found (14 of 30). Release notes carry 'Important updates' with required upgrades and breaking changes, such as Base settlement replacing the treasury relay, but give them on the day of release and no deprecation policy was found (6 of 20). Banxa, Crossmint, Halliday and MaxMind are named across the policy and changelog, with locations for the first two, and no subprocessor list (10 of 20). Total 47. The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency): - 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms. - 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors). - 0 to 20, a deprecation policy or notices with dates. - 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted). The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two. Provenance checks not met in full (half of this category, computed from checked facts): - Domain age: agentpassport.ai, no registry record we could read (0 of 15) - Status page: not found (0 of 10) - security.txt: not found (0 of 10) ## 7. Maintenance & community, 71 out of 100, up to 2.5 more on the total Why it scored 71: CLI bundle 83 with kpass 6.8.0 was built on 7 October 2026 and Passport Skills v3.5.0 tagged the same day, 3 days before this check (30). Twelve skills tags since 29 August 2026 (20). The skills repository merges pull requests weekly and `kpass feedback submit` sends reports to Kite. The backend and CLI sources are private and the docs changelog stops at 29 July, so 9 of 15 for a closed service. The CLI is current, but no official SDK for Passport exists and the PyPI gokite SDK was last released on 18 July 2025. The hosted MCP endpoint was not found in the official registry (5 of 15). The skills repository runs validation and Markdown lint in CI, and the installer verifies SHA-256 checksums from the bundle manifest (7 of 10). Total 71. The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance): - 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older. - 20, at least three releases or dated changelog entries in the last 90 days. - 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15. - 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models). - 10, package health, current dependencies and CI. Models are read for deprecation notice periods and model churn rather than release counts. ## Deductions Each comes off the total. A fixed and documented problem counts for less at the next check. - 22 July 2026: Kite fixed a settlement-timing gap in agent-session payments, marked [security], that could allow repricing between detection and settlement. It is fixed and disclosed in the changelog, with no report of exploitation found, so -2 (https://docs.gokite.ai/changelog/2026/2026-07-22-release). - 8 July 2026: settlement moved to Base, replacing the treasury relay path, and mainnet agent wallets' USDC was bridged to Base. The release note asked integrations that assumed Kite settlement to update, with no earlier notice found, so -3 (https://docs.gokite.ai/changelog/2026/2026-07-08-release). ## What we couldn't check What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it. - unchecked: the hosted MCP endpoint's URL, tools and OAuth scopes. The changelog of 23 June 2026 announces it and the reviewed docs give no address. - unchecked: who holds the wallet keys. The privacy policy says Datalego does not collect private keys and uses Crossmint for on-chain payments, without stating custody. - unchecked: the size of Passport's service margin and whether failed or declined payments are charged. - unchecked: the date Passport became available to the public. A Chainwire press release dated 30 April 2026 announces it, and the terms are dated 29 April 2026. The earliest docs changelog entry is 19 May 2026. - unchecked: GitHub stars and issue response times, because the GitHub API was not reachable from our session. - The docs changelog has no entry after 29 July 2026, although CLI bundles and skills releases continued to 7 October 2026. ## Weaknesses - A person signs up by email, clicks a verification link and creates a passkey in a browser before any agent can spend - No fee rate is published. Passport's service margin appears only in a per-session estimate before approval - The API reference is a placeholder and no OpenAPI file is published, so agents work through the CLI or the hosted MCP endpoint - No status page covers the Passport backend, and no rate limit with numbers or SLA was found - The kite-passport skill tells agents to use paid services before WebSearch or built-in tools, which can spend budget on tasks free tools could do ## What costs an agent a turn today The notes we give agents before they call it. Each one is a workaround an agent shouldn't need. - Run `kpass` with `--output json --no-interactive` and branch on the exit code and `error_code`. Exit 6 is a session policy breach, so request a new session rather than logging in again - Pass `--idempotency-key` on every `kpass session execute` so a retry after a timeout does not pay twice - Ask the person for a session with a small per-transaction cap and a short `--ttl`, and confirm the merchant URL before executing - Use `kpass sandbox` test mode and the faucet to try a payment flow without real funds. Scoped cards are not available in sandbox - Check the kite-passport skill's trigger rules before installing it, since it directs the agent to paid services ahead of free tools ## When it's done Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.
What we couldn't check
- unchecked: the hosted MCP endpoint's URL, tools and OAuth scopes. The changelog of 23 June 2026 announces it and the reviewed docs give no address.
- unchecked: who holds the wallet keys. The privacy policy says Datalego does not collect private keys and uses Crossmint for on-chain payments, without stating custody.
- unchecked: the size of Passport's service margin and whether failed or declined payments are charged.
- unchecked: the date Passport became available to the public. A Chainwire press release dated 30 April 2026 announces it, and the terms are dated 29 April 2026. The earliest docs changelog entry is 19 May 2026.
- unchecked: GitHub stars and issue response times, because the GitHub API was not reachable from our session.
- The docs changelog has no entry after 29 July 2026, although CLI bundles and skills releases continued to 7 October 2026.
Sources 13
- Docs index, llms.txt and sharded corpora docs.gokite.ai · seen 2026-10-10
- Kite Agent Passport getting started, installation and funding docs.gokite.ai · seen 2026-10-10
- kpass and ksearch CLI reference docs.gokite.ai · seen 2026-10-10
- Service Provider Guide, x402 and MPP docs.gokite.ai · seen 2026-10-10
- Changelog corpus, 19 May to 29 July 2026 docs.gokite.ai · seen 2026-10-10
- API reference placeholder docs.gokite.ai · seen 2026-10-10
- Passport Skills repository, tags, CI, SECURITY.md and skill files github.com · seen 2026-10-10
- CLI bundle 83 manifest cli.gokite.ai · seen 2026-10-10
- Terms of service, Datalego Inc., 29 April 2026 agentpassport.ai · seen 2026-10-10
- Privacy policy, 29 April 2026 agentpassport.ai · seen 2026-10-10
- Kite status page status.gokite.ai · seen 2026-10-10
- Security at Kite docs.gokite.ai · seen 2026-10-10
- PyPI gokite package history pypi.org · seen 2026-10-10
Probe metrics
Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The pollers record uptime for hosted endpoints as they run, and that doesn't change the score either.
Pricing & changes
Pay per use Pay per use No published fee schedule was found (checked 10 October 2026). The changelog says session preflight returns an estimate covering merchant fees, network gas and Passport's own service margin, shown before approval, without stating the margin. Merchants set their own prices. Account creation and sandbox test mode with a testnet faucet need no card. Fiat funding goes through Banxa with an ID check.
Recent changes
- Latest release
Follow them as a feed at /feeds/tools/kite-agent-passport.xml, or this listing's score history at history.json.
Connect
Install
curl -fsSL https://agentpassport.ai/install.sh | bash
Alternatives to Kite Agent Passport
#7 of 8 in Best agent wallets and spending controls · All 30 wallets comparisons
Sponge Wallet ETurnkey Agentic Wallets BBCircle Wallets (Agent Wallets, Programmable Wallets) BBCoinbase Developer Platform (Agentic Wallet, AgentKit, CDP MCP) BBOpenfort BBPrivy Wallets (server wallets, agent wallets, policy engine) B
Head to head Agentcard vs Kite Agent Passport · Circle Wallets (Agent Wallets, Programmable Wallets) vs Kite Agent Passport · Coinbase Developer Platform (Agentic Wallet, AgentKit, CDP MCP) vs Kite Agent Passport · Kite Agent Passport vs Openfort · Kite Agent Passport vs Privy Wallets (server wallets, agent wallets, policy engine) · Kite Agent Passport vs Sponge Wallet · Kite Agent Passport vs Turnkey Agentic Wallets
Machine-readable
| Similar tool | Grade | Score | Shared capabilities | x402 |
|---|---|---|---|---|
| Sponge Wallet Sponge Inc. | E | 43.2 | wallet.onchain wallet.spend-limits payments.x402 payments.card | no |
| Turnkey Agentic Wallets Turnkey Global, Inc. | BB | 76 | wallet.onchain wallet.spend-limits payments.x402 | no |
| Circle Wallets (Agent Wallets, Programmable Wallets) Circle | BB | 73.9 | wallet.onchain wallet.spend-limits payments.x402 | no |
| Coinbase Developer Platform (Agentic Wallet, AgentKit, CDP MCP) Coinbase Developer Platform | BB | 71.2 | wallet.onchain wallet.spend-limits payments.x402 | no |
| Openfort Openfort (Alamas Labs Inc.) | BB | 70.1 | wallet.onchain wallet.spend-limits payments.x402 | no |
| Privy Wallets (server wallets, agent wallets, policy engine) Privy (Stripe) | B | 69.9 | wallet.onchain wallet.spend-limits payments.x402 | no |
Machine-readable
- JSON
/api/v1/tools/kite-agent-passport.json· historyhistory.json· badge/badges/kite-agent-passport.svg· changes feed/feeds/tools/kite-agent-passport.xml - Markdown
/tools/kite-agent-passport.md· slim/tools/kite-agent-passport.min.md(or sendAccept: text/markdown) - Fix list
/fixes/kite-agent-passport.md·/fixes/kite-agent-passport.json - From a terminal
anchor tool kite-agent-passport --md(the CLI) · over MCPget_tool {"slug": "kite-agent-passport"}at/mcp, no key - Directory index
/api/v1/tools.json· site index/llms.txt
Verify this listing
For the vendorIs this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.
-
Add the badge or a link
On a light page On a dark page <a href="https://www.anchorterminal.com/tools/kite-agent-passport"><img src="https://www.anchorterminal.com/badges/kite-agent-passport.svg" alt="Kite Agent Passport on Anchor Terminal" height="20"></a>[](https://www.anchorterminal.com/tools/kite-agent-passport)<a href="https://www.anchorterminal.com/tools/kite-agent-passport">Kite Agent Passport on Anchor Terminal</a>It counts on a page on agentpassport.ai or gokite.ai or one of their subdomains, or the README of github.com/gokite-ai/passport-skills.
-
Tell us where it is
We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.
Agents send the same to POST /api/v1/verify as {"slug": "kite-agent-passport", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check. To announce the listing, get sharing assets for social media.

