cd /news/ai-agents/show-hn-tkeeper-oss-machine-identiti… · home topics ai-agents article
[ARTICLE · art-99116] src=tkeeper.org ↗ pub= topic=ai-agents verified=true sentiment=· neutral

Show HN: TKeeper – OSS machine identities without a single point of compromise

TKeeper, an open-source cryptographic identity system for AI agents, services, and workflows, enables secure agent identity, tool calls, agentic payments, and production actions with policy and proof before execution. It uses Multi-Party Computation (MPC) to distribute risk across independent parties and supports EVM, Bitcoin, and X.509 signing, with a configurable quorum for compromise tolerance.

read1 min views1 publishedAug 16, 2026
Show HN: TKeeper – OSS machine identities without a single point of compromise
Image: source

AI Agents

Secure agent identity, tool calls, agentic payments, and production actions with policy and proof before execution.

TKeeper is the cryptographic identity of an agent, service, or workflow. Every critical action is bound to intent, policy, quorum, and proof.

Each TKeeper is built for one job. Choose the authorities and cryptography it needs; everything else stays out. New integrations take less work without weakening security.

Secure agent identity, tool calls, agentic payments, and production actions with policy and proof before execution.

Add policy-controlled EVM and Bitcoin flows without building separate signing infrastructure for every product.

Put policy in front of X.509 signing while keeping the CA and certificate workflow you already run.

Turn privileged commands and external risk verdicts into cryptographic conditions your backend must verify.

The applied manifest defines the exact actions this identity can authorize. Permissions, policy, approvals, custody, and audit govern every use of its key.

Just put TKeeper between the machine and your backend, then verify the returned proof before execution.

A single TKeeper identity can run across independent parties instead of concentrating operational risk in one machine. Multi-Party Computation (MPC) lets you share risk across teams, systems, and organizations with a configurable quorum that defines compromise tolerance.

Move to ML-DSA when you need to. Your identity, policy, controls, and integrations remain intact.

Governance without cryptographic enforcement is wishful thinking. TKeeper was built for peace of mind in the age of autonomous machines: identity, policy, and distributed authority are cryptographically bound to every action.

── more in #ai-agents 4 stories · sorted by recency
── more on @tkeeper 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/show-hn-tkeeper-oss-…] indexed:0 read:1min 2026-08-16 ·