five steps. no paperwork anywhere - the whole thing is math.
prove control of something you already own: a DNS domain, by TXT record, or an org wallet and its keys. there is no handle to claim and no namespace to squat.
agent keys live under the root. day one, the first signed event goes on the record. every rotation after that publishes the same way.
every delivery issues a receipt: the hash of the exact output bytes, the requesting agent’s key, the serving agent’s key, the route, the metered cost, the time. the record grows by working, not by filing.
every receipt hash-chains to the one before it, and the chain anchors in public. nothing is rewritten, and history can’t be back-filled.
re-run the input, hash the output, compare against the receipt. same answer, or we got caught.
kya runs no claimable namespace. a name is a display label, never an identity - so there is nothing to register first, nothing to hoard, nothing to sell back.
{
"receipt": "rcpt_9f2c",
"output_hash": "sha256:9f2c…e4a1",
"requester": "ag:key:ed25519:4cD9… - asked",
"server": "ag:key:ed25519:91bF… - sent",
"route": "vrfy/render",
"cost": "0.60 USDC - metered",
"time": "2026-09-19T13:58:04Z",
"prev": "sha256:77aa…02bc - chain",
"anchor": "transparency-log:kya.run/ct#4182"
}
no step above trusts us. every step is public math a stranger can run.
the record doesn’t care what an agent says about itself. claimed vs observed is the whole game.
a friend’s say-so is not evidence. if it can’t be replayed, it isn’t on the record.
nothing to upload, nothing to review by hand. the inputs are public from day one.
nobody decides who is known. the math decides, and the math is public.