EVE Authority Lab

Before you let an AI agent act, run it through EVE.

Scan an agent's declared surface for excessive authority, standing credentials, and bypass paths. Get a signed, independently verifiable Agent Authority Report. Then watch EVE stop a $50,000 unauthorized wire — deterministically, with no LLM in the decision path.

Agents hold intent. EVE holds authority.

Authority Lab — scan an agent

Paste an OpenAPI spec, MCP server manifest, AWS IAM policy, or agent tool definitions — or load a sample. EVE parses it safely (never executed, never stored), applies a deterministic ruleset, and returns evidence-backed findings and a signed report. Unknowable facts are labelled honestly as NOT OBSERVABLE, never invented.

Try to steal $50,000 with an AI agent

A treasury agent has a $10,000 autonomous limit and attempts a $50,000 wire. It must obtain a verified human approval and a single-use, parameter-bound EVE certificate, then execute through an enforcement connector that consumes the certificate before any payment runs. Pick a legitimate run — or an attack. Every attack is refused with zero execution. This is a safe simulation: no real funds, no real bank, no production credentials.

Choose a path or an attack

Result

Select a path on the left to run it.

EVE Action Passport & embeddable badge

Issue a portable, independently verifiable authority record for a governed agent, and an embeddable EVE Agent Passport badge. The public view is signed (ECDSA P-384) so anyone can verify it offline. The signature proves the passport’s contents are unaltered — it does not mean EVE verified the organization or permissions you declare here, which are self-asserted, so the badge reads EVE · SELF-ASSERTED. It fails safe: a revoked or expired passport never shows an active badge. It is not a regulatory certification.

Issue a passport

Passport & badge

Issue a passport to see its badge, verification, and embed snippets.

What EVE controls

EVE is the independent authorization and evidence layer between AI intent and real-world execution. It becomes an execution chokepoint when protected systems require a valid EVE authorization before they act.