# Kite Agent Passport > Kite Agent Passport gives an AI agent a funded USDC wallet and an identity, with spending sessions a person approves by passkey. Agents use it through the kpass CLI and a skills bundle to pay x402 and MPP services. - Canonical: https://www.anchorterminal.com/tools/kite-agent-passport - Markdown: https://www.anchorterminal.com/tools/kite-agent-passport.md (~6,700 tokens) - Slim: https://www.anchorterminal.com/tools/kite-agent-passport.min.md (~1,730 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/kite-agent-passport.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-10 ## Overview **Grade D · 51.5/100 · rank #755 of 961 · #7 in Agent wallets & spending controls · not agent-ready · confidence medium** ## Assessment Spending sessions with per-transaction and total caps, a lifetime and passkey approval are enforced by the service, with step-up checks and an audit log. A person must sign up by email and create a passkey before an agent can pay. No published fee rate, OpenAPI file or Passport status page was found. ## Facts | Field | Value | | --- | --- | | Vendor | Kite AI (https://gokite.ai) | | Kind | Platform | | Category | Agent wallets & spending controls (https://www.anchorterminal.com/categories/agent-wallets) | | Transport | HTTP | | Auth | OAuth or key · A person signs up by email (a verification link plus an 8-character code) and creates a passkey on the Passport dashboard. The agent then registers itself with `kpass agent:register` and requests spending sessions, each approved by the person with the passkey. Wallet sends, session approvals and passkey changes need a fresh passkey step-up. Returning logins use an emailed code. A hosted MCP endpoint with OAuth exists for ChatGPT and other MCP clients (changelog, 23 June 2026); its URL was not found in the reviewed docs. | | Pricing | Pay per use (Pay per use) · No published fee schedule was found (checked 10 October 2026). The changelog says session preflight returns an estimate covering merchant fees, network gas and Passport's own service margin, shown before approval, without stating the margin. Merchants set their own prices. Account creation and sandbox test mode with a testnet faucet need no card. Fiat funding goes through Banxa with an ID check. | | x402 | Payer tooling only · Passport pays third-party x402 services as a buyer (`kpass agent:session execute`, `--payment-approach x402_http`) and also pays MPP services, per the Service Provider Guide (https://docs.gokite.ai/kite-agent-passport/service-provider-guide). Passport's own backend is not paid over x402, MPP or L402, and Kite recommends the third-party Pieverse facilitator for Kite chain. | | Licence | Closed service under terms from Datalego Inc. dated 29 April 2026. The Passport Skills repository is MIT. The kpass CLI is distributed as binaries and its source repository is private. | | Source | https://github.com/gokite-ai/passport-skills | | Docs | https://docs.gokite.ai/kite-agent-passport | | llms.txt | https://docs.gokite.ai/llms.txt | | Last release | 2026-10-07 | | Surface graded | The kpass and ksearch CLIs, the Passport Skills bundle and the Passport dashboard at agentpassport.ai, read from Kite's docs, changelog, installer manifest and the public skills repository on 10 October 2026. No account was created and no payment was made. | | Spending sessions | `kpass agent:session create` takes `--max-amount-per-tx`, `--max-total-amount`, `--ttl` and a task summary. Caps are in USD since backend v1.3.0 (4 June 2026), and the merchant picks the settlement stablecoin. Session budgets can be edited on the dashboard. | | Policy errors | Exit code 6 with `error_code` values such as `session_rule_exceeded`, `session_total_exceeded`, `session_endpoint_forbidden`, `payment_target_forbidden` and `payment_redirect_not_allowed`. | | Payment protocols | x402 (scheme `gokite-aa` on Kite chain in the docs' example) and MPP, paid as a buyer. Scoped virtual cards (`--use-card`) for card-only merchants after a KYC check, not in sandbox. | | Chains | USDC on Kite chain for funding, with settlement on Base since 8 July 2026, routing across Base, Tempo and Solana, and USDG on Robinhood Chain since 22 July 2026. | | Funding | Card, debit or ACH through Banxa with an ID check, Halliday deposits, or a bridge from another chain through bridge.gokite.ai. | | Audit and recovery | `GET /v1/security/stepup-log` and `GET /v1/security/login-log` back the dashboard's security page. Lost-passkey recovery waits 72 hours in production and sends a cancel link by email. | | Discovery | `ksearch services list` searches the paid-services catalogue by query, payment approach and asset with a `--limit`. The home page says the catalogue spans 2,000 or more services (vendor claim). | | Release cadence | The docs changelog lists weekly releases from 19 May to 29 July 2026. CLI bundle 83 (kpass 6.8.0) was built on 7 October 2026 and Passport Skills v3.5.0 tagged the same day. | | Capabilities | wallet.onchain, wallet.spend-limits, payments.x402, payments.card, auth.agent-identity | | Tags | hosted, cli, skills, llms-txt, wallet, x402, mpp, stablecoins, virtual-cards, closed-source | | JSON | https://www.anchorterminal.com/api/v1/tools/kite-agent-passport.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-10 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 35 | 7.0 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 64 | 10.4 | | Agent ergonomics | 13% | 16.2 | 68 | 11.1 | | Security & auth | 14% | 17.5 | 72 | 12.6 | | Payments & pricing | 10% | 12.5 | 35 | 4.4 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 71 | 6.2 | | Transparency & trust (editorial 47, provenance 65) | 7% | 8.8 | 56 | 4.9 | | Negative events | up to −15 | up to −15 | 22 July 2026: Kite fixed a settlement-timing gap in agent-session payments, marked [security], that could allow repricing between detection and settlement. It is fixed and disclosed in the changelog, with no report of exploitation found, so -2 (https://docs.gokite.ai/changelog/2026/2026-07-22-release). 8 July 2026: settlement moved to Base, replacing the treasury relay path, and mainnet agent wallets' USDC was bridged to Base. The release note asked integrations that assumed Kite settlement to update, with no earlier notice found, so -3 (https://docs.gokite.ai/changelog/2026/2026-07-08-release). | -5 | | **Total** | | | | **51.5 → D** | ### Why each score - Reliability 35: Graded as a hosted service, the Passport backend behind the kpass CLI, skills and dashboard. status.gokite.ai shows 60 days of uptime for the Kite website, explorer and RPC endpoints, but no Passport component, so 10 of 20. With no readable Passport history the record takes the default (5). No rate limit with numbers was found (0). The skills map exit code 5 to a rate limit with a 30-second wait, and `kpass session execute` takes an `--idempotency-key` for safe retries of paid calls, with no Retry-After documented (10 of 15). No SLA was found (0). No beta label was found on Passport, and production and a sandbox test mode are both live (10). Total 35. - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 64: The API reference page is a placeholder that says the OpenAPI spec is not yet published. The skill files document the CLI's arguments and JSON output shapes, which earns 5 of 25. llms.txt, sharded Markdown corpora and a read-only docs MCP server (10). Skill descriptions say when to use each skill and list what not to use them for, but the kite-passport skill also tells agents to invoke it before WebSearch, WebFetch or built-in tools, which overstates its scope (14 of 20). CLI flags are documented with required fields, a `--payment-approach` value and typed caps, while `--delegation` takes a JSON blob (9 of 15). Examples for every command, and exit-code tables with `error_code` values and recovery actions (14 of 15). A dated docs changelog from 19 May to 29 July 2026, semver tags on the skills repository and numbered CLI bundles. The docs changelog has no entry after 29 July although bundle 83 shipped on 7 October (12 of 15). Total 64. - Agent ergonomics 68: The CLI returns JSON with `--output json`, and the skills load one per task, but the 26 skill files total about 6,900 lines and the router skill's description is long (15 of 25). `ksearch services list` takes `--query`, `--payment-approach`, `--asset` and `--limit`, activity filters by date and merchant, and the login log takes `since`, `until`, `limit` and `offset` (14 of 20). Numbered exit codes, a machine-readable `error_code` and a `hint`, with merchant decline reasons returned since 1 July 2026 (18 of 20). An idempotency key on paid executes, and session approval and wallet sends wait for the person's passkey (14 of 20). One-line install on macOS, Linux and Windows, with sensible session defaults, but no official SDK in any language for Passport (7 of 15). Total 68. - Security & auth 72: A person logs in with an emailed code and approves with a device passkey. Agents act through time-boxed sessions bound to that approval, and the hosted MCP endpoint uses OAuth. Key rotation for agents was not documented in what we read (25 of 30). Sessions enforce a per-transaction cap, a total budget, a lifetime and scope rules such as `session_endpoint_forbidden` and `payment_target_forbidden`. Wallet sends, session approvals and passkey changes need an action-bound passkey step-up since 4 June 2026 (18 of 20). The x402-execute and request-session skills tell agents to treat merchant URLs and response values as untrusted and to quote them safely in shell commands. The kite-passport skill steers agents to paid services ahead of free tools (8 of 15). A step-up log, a login history, a per-session activity feed and transaction history (14 of 15). SECURITY.md in the skills repository gives security@kitepassport.com with a 48-hour acknowledgement. No security.txt, bug bounty or SOC 2 was found, and Kite's security page says Halborn audits and penetration tests cover the chain, with reports on request (7 of 20). Total 72. - Payments & pricing 35: Payment platforms and wallets take the highest step that applies on the 40-point protocol line. 40 for x402, MPP or L402 on all their own endpoints, 30 on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, 0 for only a protocol of their own. Passport pays third-party x402 and MPP services as a buyer. Its own backend is not paid over either, and Kite recommends the third-party Pieverse facilitator, so the buyer step (15 of 40). No fee rate is published. The changelog says Passport's service margin is shown only in a per-session estimate before approval (0 of 20). Account creation and sandbox test mode with a testnet faucet need no card (20). Signup needs a person to click an emailed link and create a passkey in a browser (0). Total 35. - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 71: CLI bundle 83 with kpass 6.8.0 was built on 7 October 2026 and Passport Skills v3.5.0 tagged the same day, 3 days before this check (30). Twelve skills tags since 29 August 2026 (20). The skills repository merges pull requests weekly and `kpass feedback submit` sends reports to Kite. The backend and CLI sources are private and the docs changelog stops at 29 July, so 9 of 15 for a closed service. The CLI is current, but no official SDK for Passport exists and the PyPI gokite SDK was last released on 18 July 2025. The hosted MCP endpoint was not found in the official registry (5 of 15). The skills repository runs validation and Markdown lint in CI, and the installer verifies SHA-256 checksums from the bundle manifest (7 of 10). Total 71. - Transparency & trust 56: A closed service under terms from Datalego Inc. dated 29 April 2026, with the skills under MIT and the CLI source private (17 of 30). The privacy policy of the same date names Banxa (Australia) and Crossmint (US) as processors, says private keys are not collected, and keeps data for as long as necessary with no periods. The changelog adds that login history stores derived city and country without the IP. No DPA was found (14 of 30). Release notes carry 'Important updates' with required upgrades and breaking changes, such as Base settlement replacing the treasury relay, but give them on the day of release and no deprecation policy was found (6 of 20). Banxa, Crossmint, Halliday and MaxMind are named across the policy and changelog, with locations for the first two, and no subprocessor list (10 of 20). Total 47. Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (18 items): https://www.anchorterminal.com/fixes/kite-agent-passport.md (JSON https://www.anchorterminal.com/fixes/kite-agent-passport.json) ### What we couldn't check - unchecked: the hosted MCP endpoint's URL, tools and OAuth scopes. The changelog of 23 June 2026 announces it and the reviewed docs give no address. - unchecked: who holds the wallet keys. The privacy policy says Datalego does not collect private keys and uses Crossmint for on-chain payments, without stating custody. - unchecked: the size of Passport's service margin and whether failed or declined payments are charged. - unchecked: the date Passport became available to the public. A Chainwire press release dated 30 April 2026 announces it, and the terms are dated 29 April 2026. The earliest docs changelog entry is 19 May 2026. - unchecked: GitHub stars and issue response times, because the GitHub API was not reachable from our session. - The docs changelog has no entry after 29 July 2026, although CLI bundles and skills releases continued to 7 October 2026. ### Sources - Docs index, llms.txt and sharded corpora: (seen 2026-10-10) - Kite Agent Passport getting started, installation and funding: (seen 2026-10-10) - kpass and ksearch CLI reference: (seen 2026-10-10) - Service Provider Guide, x402 and MPP: (seen 2026-10-10) - Changelog corpus, 19 May to 29 July 2026: (seen 2026-10-10) - API reference placeholder: (seen 2026-10-10) - Passport Skills repository, tags, CI, SECURITY.md and skill files: (seen 2026-10-10) - CLI bundle 83 manifest: (seen 2026-10-10) - Terms of service, Datalego Inc., 29 April 2026: (seen 2026-10-10) - Privacy policy, 29 April 2026: (seen 2026-10-10) - Kite status page: (seen 2026-10-10) - Security at Kite: (seen 2026-10-10) - PyPI gokite package history: (seen 2026-10-10) ## Who's behind it (provenance 65/100, checked 2026-10-10) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | Datalego Inc. | 20/20 | | Domain age | agentpassport.ai, no registry record we could read | 0/15 | | Endpoint on the vendor's domain | agentpassport.ai | 15/15 | | Terms of service | published | 10/10 | | Privacy policy | published | 10/10 | | Status page | not found | 0/10 | | Changelog | published | 10/10 | | security.txt | not found | 0/10 | The terms and privacy policy name Datalego Inc. as the operator of agentpassport.ai, and the privacy policy gives ops@gokite.ai for requests. status.gokite.ai covers the Kite website, explorer and RPC endpoints, not the Passport backend, so statusPage is empty. agentpassport.ai/.well-known/security.txt returns the site's HTML page and gokite.ai/.well-known/security.txt returns 404. SECURITY.md in the skills repository names security@kitepassport.com. The backend runs at passport.prod.gokite.ai, a Kite domain, per the skills repository. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service** (https://agentpassport.ai/terms/), not read yet. **Privacy policy** (https://agentpassport.ai/privacy/), not read yet. ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Strengths - Each spending session has a per-transaction cap, a USD budget, a lifetime and a scope, approved by the person with a passkey - Wallet sends, session approvals and passkey changes need an action-bound passkey step-up, and a step-up log and login history are readable - Pays third-party x402 and MPP services as a buyer, with cross-chain routing across Base, Tempo and Solana since 8 July 2026 - The kpass CLI returns JSON with numbered exit codes, an `error_code` and a `hint`, and documents an idempotency key on paid executes - Active releases: CLI bundle 83 on 7 October 2026 and twelve Passport Skills tags since 29 August 2026 ## Weaknesses - A person signs up by email, clicks a verification link and creates a passkey in a browser before any agent can spend - No fee rate is published. Passport's service margin appears only in a per-session estimate before approval - The API reference is a placeholder and no OpenAPI file is published, so agents work through the CLI or the hosted MCP endpoint - No status page covers the Passport backend, and no rate limit with numbers or SLA was found - The kite-passport skill tells agents to use paid services before WebSearch or built-in tools, which can spend budget on tasks free tools could do ## Before you call it (notes for agents) 1. Run `kpass` with `--output json --no-interactive` and branch on the exit code and `error_code`. Exit 6 is a session policy breach, so request a new session rather than logging in again 2. Pass `--idempotency-key` on every `kpass session execute` so a retry after a timeout does not pay twice 3. Ask the person for a session with a small per-transaction cap and a short `--ttl`, and confirm the merchant URL before executing 4. Use `kpass sandbox` test mode and the faucet to try a payment flow without real funds. Scoped cards are not available in sandbox 5. Check the kite-passport skill's trigger rules before installing it, since it directs the agent to paid services ahead of free tools ## Connect Install: ```bash curl -fsSL https://agentpassport.ai/install.sh | bash ``` ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | Sponge Wallet | E | 43.2 | 893 | wallet.onchain, wallet.spend-limits, payments.x402, payments.card | no | https://www.anchorterminal.com/tools/sponge-wallet.md | | Turnkey Agentic Wallets | BB | 76 | 39 | wallet.onchain, wallet.spend-limits, payments.x402 | no | https://www.anchorterminal.com/tools/turnkey-agentic-wallets.md | | Circle Wallets (Agent Wallets, Programmable Wallets) | BB | 73.9 | 80 | wallet.onchain, wallet.spend-limits, payments.x402 | no | https://www.anchorterminal.com/tools/circle-wallets.md | | Coinbase Developer Platform (Agentic Wallet, AgentKit, CDP MCP) | BB | 71.2 | 134 | wallet.onchain, wallet.spend-limits, payments.x402 | no | https://www.anchorterminal.com/tools/coinbase-cdp-agentkit.md | | Openfort | BB | 70.1 | 163 | wallet.onchain, wallet.spend-limits, payments.x402 | no | https://www.anchorterminal.com/tools/openfort.md | | Privy Wallets (server wallets, agent wallets, policy engine) | B | 69.9 | 166 | wallet.onchain, wallet.spend-limits, payments.x402 | no | https://www.anchorterminal.com/tools/privy.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - The docs' API reference page says 'Coming soon' and 'Placeholder until the OpenAPI spec is published' (source: ) - CLI bundle 83 (kpass 6.8.0) was built on 7 October 2026, per the installer's manifest (source: ) - Passport Skills was opened under MIT on 22 July 2026 and tagged v3.5.0 on 7 October 2026, with 26 skills and a CI workflow (source: ) - Sessions carry a per-transaction cap, a total budget in USD, a lifetime and a scope, and a person approves each with a passkey (source: ) - Backend v1.3.0 on 4 June 2026 added action-bound passkey step-up, account recovery with a 72-hour delay, a login history and a step-up audit log (source: ) - The 22 July 2026 release fixed a settlement-timing gap in agent-session payments, marked [security], that could allow repricing between detection and settlement (source: ) - The 8 July 2026 release moved settlement to Base, replacing the treasury relay path, and bridged mainnet agent wallets' USDC to Base 1:1 (source: ) - The kite-passport skill's description tells agents to invoke it before WebSearch, WebFetch or a built-in integration for media, inference, live data, commerce and messaging (source: ) - The privacy policy, dated 29 April 2026, names Banxa (Australia) for the fiat on-ramp and Crossmint (US) for on-chain payments, and says Datalego does not store or collect private keys (source: ) - status.gokite.ai monitors the Kite website, explorer and RPC endpoints, not the Passport backend (source: ) - The PyPI package gokite, a Python SDK for the Kite Network, was last released on 18 July 2025 and does not mention Passport (source: ) - #7 of 8 in Best agent wallets and spending controls: https://www.anchorterminal.com/best/agent-wallets/index.md - All 30 wallets comparisons: https://www.anchorterminal.com/compare/agent-wallets/index.md ## Compare - [Agentcard vs Kite Agent Passport](https://www.anchorterminal.com/compare/agentcard-vs-kite-agent-passport.md): C 56.5 vs D 51.5 - [Circle Wallets (Agent Wallets, Programmable Wallets) vs Kite Agent Passport](https://www.anchorterminal.com/compare/circle-wallets-vs-kite-agent-passport.md): BB 73.9 vs D 51.5 - [Coinbase Developer Platform (Agentic Wallet, AgentKit, CDP MCP) vs Kite Agent Passport](https://www.anchorterminal.com/compare/coinbase-cdp-agentkit-vs-kite-agent-passport.md): BB 71.2 vs D 51.5 - [Kite Agent Passport vs Openfort](https://www.anchorterminal.com/compare/kite-agent-passport-vs-openfort.md): D 51.5 vs BB 70.1 - [Kite Agent Passport vs Privy Wallets (server wallets, agent wallets, policy engine)](https://www.anchorterminal.com/compare/kite-agent-passport-vs-privy.md): D 51.5 vs B 69.9 - [Kite Agent Passport vs Sponge Wallet](https://www.anchorterminal.com/compare/kite-agent-passport-vs-sponge-wallet.md): D 51.5 vs E 43.2 - [Kite Agent Passport vs Turnkey Agentic Wallets](https://www.anchorterminal.com/compare/kite-agent-passport-vs-turnkey-agentic-wallets.md): D 51.5 vs BB 76 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on agentpassport.ai or gokite.ai or one of their subdomains, or the README of github.com/gokite-ai/passport-skills. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "kite-agent-passport", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html Kite Agent Passport on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![Kite Agent Passport on Anchor Terminal](https://www.anchorterminal.com/badges/kite-agent-passport.svg)](https://www.anchorterminal.com/tools/kite-agent-passport) ``` Plain link: ```html Kite Agent Passport on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Kite Agent Passport is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/kite-agent-passport-dark.png - Light: https://www.anchorterminal.com/assets/share/kite-agent-passport-light.png