KRUTRIM EKAMAgent-identity control plane

Ekam blog

Ideas on agent identity & reliable AI

Why agents need real identity, how delegation and offline verification make AI accountable and fast, and what to build on Ekam.

Every request an identity. No shared key. API request / collection test / CI runner MCP tool call Ekam broker · short-lived token scoped · revocable · metered your customer's API app under test model / LLM ES256 · verified offline · killable in seconds · cost attributed to the owner
developer platformsAPItestingCIagentsintegration

The shared API key is over: agent identity for developer platforms

API clients, test runners, CI jobs and MCP tools now act on their own — and they all authenticate with the same long-lived, unscoped, un-revocable key. Here's what a real agent identity unlocks for a developer platform and the users who live inside it.

7 July 2026 · 7 min read · The Ekam team

Identity → inference → billing, one loop. Ekammints ES256 JWT BharatRouterverify offline · map owner→orgmeter · (later) bill model / API usage attributed to the owner · revoke kills it in seconds no shared keys · no hot-path call to Ekam · attribution end to end
meteringbillingcost attributiondelegationgateways

Identity and billing in one plane: metering agents by the owner

Every agent-identity system tells you who an agent is. None tell you what it cost. Ekam fuses identity with inference metering — per agent, per owner, and across a delegation chain — so the token that authorizes a call also accounts for it.

7 July 2026 · 6 min read · The Ekam team

human · root owns agt · support-bot agt · data-pipeline agt · mcp-client One chain of authority. Every token short-lived. ES256 · audience-bound · scoped · revocable in seconds · verified offline
agent identityreliabilityDPDPIndiaNHI

Why India needs its own agent-identity control plane

AI agents are about to outnumber human users. They authenticate with shared, long-lived API keys that can't be scoped, attributed, or revoked. For India to build AI the world trusts, agents need real identity — and a control plane that lives under our own law.

30 June 2026 · 9 min read · The Ekam team

Verify offline. Never call home. agentpresents JWT your gatewayverify(jwt)ES256 · iss · aud · expin-process · ~0.05 ms JWKS (cached) introspectonly if live-revoke ~18,000 verifications/sec/core · p99 < 0.1 ms · token ~640 bytes (measured)
architectureperformanceJWKSES256gateways

How offline token verification works (and why it's fast)

An Ekam token is an ES256 JWT your gateway verifies in-process against a cached JWKS — no network call to authorize a request. Here's the architecture, the exact checks, and the measured numbers.

30 June 2026 · 7 min read · The Ekam team

Build it this week. MCP server authAI gatewayCI/CD agentmulti-agenthuman-in-loopJIT-PAMkill-switchbirthright SCIMcross-appBYO PDP copy-paste curl · every endpoint is live in open beta
use casesMCPgatewaystutorialrecipes

10 things to build on Ekam this week

Every endpoint below is live in open beta. Copy a curl, get a working result. From governing an MCP server to a kill-switch drill — concrete use cases, not slideware.

30 June 2026 · 8 min read · The Ekam team

Identity → inference → billing, one loop. Ekammints ES256 JWT BharatRouterverify offline · map owner→orgmeter · (later) bill model / API usage attributed to the owner · revoke kills it in seconds no shared keys · no hot-path call to Ekam · attribution end to end
BharatRoutergatewaysintegrationarchitecturecase study

How BharatRouter runs on Ekam: agent identity for an AI gateway

A model gateway hands out one shared key and hopes for the best. BharatRouter swapped that for verifiable, revocable, human-rooted agent identity — here's the architecture and what it gains.

30 June 2026 · 6 min read · The Ekam team

Krutrim Cloud · DR enabled · Open beta  ·  Home · Blog · Docs · Cookbook · Privacy · Terms · Report a bug