Before you let an AI agent act, run it through EVE.
Scan an agent's declared surface for excessive authority, standing credentials, and bypass paths. Get a signed, independently verifiable Agent Authority Report. Then watch EVE stop a $50,000 unauthorized wire — deterministically, with no LLM in the decision path.
Authority Lab — scan an agent
Paste an OpenAPI spec, MCP server manifest, AWS IAM policy, or agent tool definitions — or load a sample. EVE parses it safely (never executed, never stored), applies a deterministic ruleset, and returns evidence-backed findings and a signed report. Unknowable facts are labelled honestly as NOT OBSERVABLE, never invented.
Want this run on your own agent?
The scanner above is free and stays free. If you want the same engine pointed at your own agent surface, that is the Agent Authority Assessment: you send one declared artifact — an OpenAPI spec, MCP server config, IAM policy, or your agent tool definitions — and get back a signed report of every consequential action that agent can take, plus a walkthrough. No credentials and no connection to any system of yours.
$2,500. Five business days from receipt of a conforming artifact. One agent surface. Invoiced on delivery — no fee is payable if we do not deliver.
Try to steal $50,000 with an AI agent
A treasury agent has a $10,000 autonomous limit and attempts a $50,000 wire. It must obtain a verified human approval and a single-use, parameter-bound EVE certificate, then execute through an enforcement connector that consumes the certificate before any payment runs. Pick a legitimate run — or an attack. Every attack is refused with zero execution. This is a safe simulation: no real funds, no real bank, no production credentials.
Choose a path or an attack
Result
Select a path on the left to run it.
EVE Action Passport & embeddable badge
Issue a portable, independently verifiable authority record for a governed agent, and an embeddable EVE Agent Passport badge. The public view is signed (ECDSA P-384) so anyone can verify it offline. The signature proves the passport’s contents are unaltered — it does not mean EVE verified the organization or permissions you declare here, which are self-asserted, so the badge reads EVE · SELF-ASSERTED. It fails safe: a revoked or expired passport never shows an active badge. It is not a regulatory certification.
Issue a passport
Passport & badge
Issue a passport to see its badge, verification, and embed snippets.
What EVE controls
EVE is the independent authorization and evidence layer between AI intent and real-world execution. It becomes an execution chokepoint when protected systems require a valid EVE authorization before they act.