Identity · Registration · Verification

Give every AI an identity.

A digital passport for enterprise AI — the canonical AI identity registry your organization needs to register, manage, and verify every asset from a single source of truth.

Register it once. Verify it anywhere. Not a governance suite, not a scanner — the identity layer beneath them.

AI Keypass
No. ai_pspt_7F3A92K1

Name

Claims Assistant

Active
ai_pspt_7F3A92K1

Type

Agent

Environment

Production

Owner

Jane Smith

Organization

Acme Corporation

Registered

Aug 12, 2026

Last Attested

Aug 12, 2026

Identity · Registration · Verificationv1
Example credential

Already known by different IDs across your stack? Keypass connects them all to the same AI.

The problem

Organizations are rapidly accumulating AI — applications, agents, models, copilots, automations, vendor AI.

But there is often no universal answer to a simple question:

"Which AI is this?"

AI Keypass provides that identity — a digital passport for every AI, backed by a canonical AI identity registry your whole organization can rely on.

How it works

Register · Identify · Verify

1Register

Create the permanent identity

Register an AI in under a minute. It receives a Passport ID that never changes and is never reused.

2Identify

Reference the Passport ID anywhere

Repositories, CMDBs, CI/CD pipelines, governance platforms, tickets, and APIs all share one identifier.

3Verify

Confirm the registration is current

Anyone or any system can check whether a Passport exists and its registration is active — one API request.

The next level

From registry to identity graph

Registration is the foundation. The differentiator is binding — connecting the fragmented identifiers already spread across your stack to one accountable record.

A Vault entity, a SPIFFE ID, a cloud deployment, a GRC record, a cost tag — each resolves back to the registered AI it belongs to. The registry you build today is designed to become that identity graph tomorrow.

How linked identities work →

One AI · Many system IDs · One accountable identity

HashiCorp Vault

fe2a8568-91cc-…

Access→ai_pspt_7F3A92K1

SPIFFE

spiffe://acme/claims

Runtime→ai_pspt_7F3A92K1

Azure OpenAI

claims-assistant-prod

Governance→ai_pspt_7F3A92K1

Apptio

cost-center:402

FinOps→ai_pspt_7F3A92K1

Every binding resolves to one registered, owned AI — no matter which system it came from.

For teams building their own program

Not ready to register your AI yet?

Take the complete program with you.

Download the free AI Identity & Attestation Program-in-a-Box and get everything you need to make the case, assess readiness, launch a 30-day pilot, and run the program internally.

Get the free Program-in-a-Box

The embedding moment

One AI. One ID. Everywhere it runs.

A Passport ID is just a string. Attach it wherever the AI makes a request, and any downstream system can verify it in one call.

GitHub Actions — tag the run with its Passport ID
# .github/workflows/claims-agent.yml
name: Claims Assistant
on: [push]
jobs:
  run:
    runs-on: ubuntu-latest
    env:
      AI_KEYPASS_ID: ai_pspt_7F3A92K1   # this job's registered AI
    steps:
      - run: |
          curl -s "https://aikeypass.com/functions/api/v1/passports/verify?id=$AI_KEYPASS_ID" \
            -H "x-api-key: ${{ secrets.KEYPASS_API_KEY }}" | jq .status
Model gateway — send the ID on every request
# Any model gateway, agent runtime, or inference call
curl https://gateway.example.com/v1/chat/completions \
  -H "Authorization: Bearer $GATEWAY_TOKEN" \
  -H "X-AI-Keypass-ID: ai_pspt_7F3A92K1" \
  -H "Content-Type: application/json" \
  -d '{ "model": "claims-assistant", "messages": [...] }'

# The gateway checks that the supplied Passport ID maps to an
# active, attested registration. This identifies the claimed AI
# record; it does not cryptographically authenticate the workload.
When the system only knows its native ID
curl "https://aikeypass.com/functions/api/v1/resolve" \
  --get \
  --data-urlencode "system=hashicorp_vault" \
  --data-urlencode "external_id=$VAULT_ENTITY" \
  -H "x-api-key: $KEYPASS_KEY"

The system does not need to know the Key ID in advance. Give Keypass the identifier it already has, and Keypass resolves it to the registered, accountable AI.

The X-AI-Keypass-ID header is the integration convention — any system that touches the AI can resolve the ID to a registered, accountable record. It identifies the claimed AI; it does not authenticate the calling workload.

Demo registry

What a Registry looks like

Fictional examples — no real customer data.

Passport IDNameTypeOwnerStatus
ai_pspt_7F3A92K1Claims AssistantAgentJane SmithActive
ai_pspt_3B8D11X9Customer Support AgentAgentMarco DiazActive
ai_pspt_5C2E44M7Demand Forecast ModelModelPriya NairExpiring
ai_pspt_9A1B22Q4Employee CopilotCopilotTom WalkerActive
ai_pspt_6D4F88R2Fraud Detection ModelModelLena OrtizRevoked
ai_pspt_2E7C33T8Product Recommendation EngineAI ApplicationSam ChenActive

Why use it

A canonical AI inventory, without the bureaucracy.

Create a persistent identifier for every AI. Establish ownership. Make AI references portable across systems. Create lifecycle accountability. Enable other systems to verify registration.

"We identify your AI. We don't need to ingest your AI."
AI Keypass never requires prompts, model outputs, source code, datasets, or secrets.

  • Know what AI exists.
  • Know who owns it.
  • Give systems a common identifier.
  • Create accountability without bureaucracy.
  • Stop recreating AI inventories in spreadsheets.
  • Make AI registration easier than avoiding it.
  • Provide a foundation other governance systems can build upon.

Pricing

Priced by Passports, not seats

Every account starts with 5 free Passports. Buy credit packs as you grow — 1 credit = 1 registered AI, valid for 12 months. Buying a new pack extends the clock on your remaining credits; registered Passports persist independently and aren't affected by credit expiry.

Early adopter: platform access is free for your first year. A paid subscription comes later — credits are separate.

Every Passport includes Linked Identities. Bindings do not consume additional Registry Credits.

Flex

$49

50 Passports

Valid 12 months from purchase

  • Pilot your first AI identity
  • Test workflows and reviews
  • Top off as you go
Start Flex

Growth

Most popular

$179

200 Passports

Valid 12 months from purchase

  • Centralize a team or product line
  • Consistent ownership across your stack
  • Add packs as you add departments
Start Growth

Business

$425

500 Passports

Valid 12 months from purchase

  • Federated, distributed environments
  • Vendor management and audits
  • Larger transformations
Start Business

Enterprise

$750

1,000 Passports

Valid 12 months from purchase

  • Organization-wide rollouts
  • Governance across business units
  • Scale before going Custom
Start Enterprise

Custom

Let's talk

1,000+ Passports

  • High-volume identity resolution
  • Batch binding and resolution
  • Larger identity graphs
  • Custom system mappings
  • Managed integration support
  • SSO & SCIM
  • Custom integrations & services
  • Priority support
Contact sales

Migrate in minutes

Bring your existing inventory, not your overhead.

Already tracking AI in spreadsheets or across disconnected systems? A one-click ingestion tool and a corresponding CSV template make it easy to migrate from existing trackers or consolidate multiple tracking systems into one registry.

Download the CSV template

A clean, documented schema — one row per AI. Drop in what you already track: name, type, owner, environment, purpose.

One-click ingestion

Upload the file and Keypass validates, maps, and registers every row as a Passport in a single pass — no field-by-field re-entry.

One identity connects them all

Consolidate fragmented AI records around one persistent Key ID while letting governance, security, FinOps, CMDB, and engineering systems remain authoritative for their own data. Keypass replaces spreadsheets and shadow trackers — not the operational systems maintaining specialized records.

Import supports the same fields as the register form and API — including tags via the key:value convention.

No anonymous AI.

Register your first AI in under a minute.

Register your first AI