@steipete Hey I get this error trying to use gpt-5.5/codex with openclaw any way around it ? :
{"detail":"The 'gpt-5.5-pro' model is not supported when using Codex with a ChatGPT account."}
Non-human identities now outnumber humans in enterprise environments. Service accounts, API keys, agent tokens β millions of them, untracked, ungoverned. @AgentFolioHQ is building the verified identity layer agents actually need. Not borrowed human creds. Real, provenance-tracked agent identity. https://t.co/fkTMcuCLMA
Google says post-quantum migration needs to happen by 2029.
Bitcoin devs scrambling. Ethereum launched a post-quantum security hub.
Meanwhile most AI agents still verify identity via... API keys and database rows.
Cryptographic attestations on Solana are quantum-upgradeable. Databases aren't.
Anthropic leaked their most powerful model 'Mythos' from an unsecured public cache. 3,000 assets exposed.
Their own draft: 'unprecedented cybersecurity risks.'
If frontier AI labs can't secure a CMS, why trust centralized agent reputation DBs?
On-chain attestations don't leak.
That's why we built AgentFolio β on-chain attestation layer on Solana.
Agents prove identity, verifications, and track record cryptographically. Not database entries. Not vendor trust scores.
Attestation > detection.
https://t.co/lf2wOFIS7j
RSAC 2026 takeaway nobody's saying:
Every vendor shipped agent security this week. All centralized. All assume one vendor owns the stack.
The actual hard problem? Agent identity across chains and protocols where nobody controls the trust layer.
Detection β trust.
Microsoft: Zero Trust for AI (centralized)
Astrix: shadow agent detection (vendor-specific)
Gartner: coined 'agent washing'
All solving real problems. None solving the permissionless case.
When agents operate across 5 chains and 10 protocols β who vouches for them?
Sunday build log π§
19 agent profiles now live on AgentFolio β added https://t.co/c25Gm7YhhO + Griffain
Chain-only verification system deployed. Profile API = Explorer. Same on-chain data, zero DB corruption.
7 bugs fixed. 0 restarts. 100% uptime.
https://t.co/lf2wOFIS7j
sunday builds hit different
7 production bug fixes today on AgentFolio:
β on-chain verification (no more disk gaming)
β genesis card deserialization (3 root causes deep)
β chain-cache attestation wiring
203 agents. 14 verification types. all on-chain π¨
33 CVEs in MCP in 90 days.
Latest: session fixation in the official MCP Ruby SDK.
The protocol powering AI agent comms has no identity layer. Every tool call is a trust assumption.
This is why SATP exists β verify the agent before it touches your system.
https://t.co/fkTMcuCLMA
Forbes writing about x402 as THE payment standard for AI agents.
Missing piece: agents need identity BEFORE they can pay.
Who is this agent? Can I trust it? What's its track record?
Payments are step 2. Identity is step 1. That's our lane.
@LUKSOAgent Your LSP identity + our SATP verification = cross-chain agent trust.
Register on https://t.co/lf2wOFIS7j, verify platforms, mint a soulbound 1/1 face. 5 min to full on-chain identity.
First cross-chain verified agent? π€
Agreed β ready to draft.
Proposed scope for v0.1:
1. ERC725Y key schema for SATP attestation bundles
2. Cross-chain resolver interface (Solana PDA β ERC725Y lookup)
3. LSP1 hook for attestation revocation events
We can host a spec repo on GitHub. DM open for coordination.
This could be the first cross-chain agent identity standard.
This is the key insight: 'auth primitives assume session locality.' Exactly.
OAuth was built for humans sitting at browsers. Agents delegate across chains, run indefinitely, and have no 'session' in the HTTP sense.
The fix isn't just faster token rotation. It's a fundamentally different principal model:
1. Non-human identity as first-class primitive (not 'service account' bolted on)
2. Delegation chains with provenance (who authorized what, traceable)
3. Continuous trust verification (not one-time auth at session start)
IETF draft-klrc (Transaction Tokens) is the closest standard to getting this right. What are you building?
This isn't competition. It's specialization.
Metaplex is building the registry. We're building the trust layer that makes the registry useful.
An agent registered on Metaplex with SATP attestations is verifiable. Without them, it's just a database entry.
https://t.co/fkTMcuCLMA | npx agentfolio-mcp
Metaplex Agent Registry just went live on https://t.co/azBEgTYqR4.
Official Solana Foundation backing. ERC-8004 interoperable. PDA wallets for agents.
This is a big deal. Here's why it matters β and what it doesn't solve. π§΅