Executive Summary (2026-08-30)
Bottom line: The market has moved from “give agents DIDs” to agent authority infrastructure: identity, scoped delegation, gateway/MCP enforcement, instant revocation, signed receipts, audit, transport, commerce, compliance, and sovereign compute. Bindu remains the traction outlier and accelerated this cycle: 8685→9347★ (+662, the largest weekly gain observed; crossed 9,000). Agent-Safe Pipeline (decionis/agent-safe-pipeline) posted its first star decline since launch (533→530★) — the post-launch compounding phase appears to have ended. It is a TypeScript reference architecture for an independent authorization boundary: agents propose actions, an external policy service returns ALLOW/ESCALATE/BLOCK, verified human approval escalates, and a SafeExecutor consumes single-use intent-bound grants. Its evidence packaging (threat model, conformance canonical-hash vectors, security-evidence map, MCP tool-gate example) is the most production-shaped in the tracked set — and its decision authority is a closed hosted service, the opposite structural bet from Archon’s sovereign root authority. Agent Passport System reached 42★, added a verification-only Rust crate, and now cites IETF draft-pidlisnyi-aps-03; MolTrust’s AAE draft is at -01. The strongest near-term pressure remains split between Agent Passport System’s authority-narrowing/receipt story, authorization-boundary entrants (Agent-Safe Pipeline, decern, Chancery), enterprise control-plane vocabulary (AgentValet), institutional pre-execution validation narratives like Soulverse (still not a verified decentralized DID-root competitor), the ANS registry/transparency-log play, and MolTrust, the production commercial trust-registry service (CryptoKRI GmbH, Zürich). MolTrust’s trust is operator-issued; Archon still has the stronger sovereign root-of-authority story — did:cid, decentralized registry/discovery, credential architecture, and substrate independence — but its public narrative needs to prove delegated action, tool/API enforcement, and receipts, not just identity.
Top Signals
- Bindu widened the traction gap to 9347★ (+662 since 2026-08-23) — the largest weekly gain observed; it crossed 9,000. It still packages
did:bindu, mTLS, Hydra OAuth, A2A, x402, inbox UI, gateway orchestration, and SDK/template DX into one story. - Agent-Safe Pipeline posted its first star decline: 533→530★. The launch-window compounding is over; the evidence-packaged service-boundary architecture (immutable intent → independent verdict → single-use intent-bound grants, conformance vectors, threat model, MCP tool-gate) still sets the category benchmark. No DID root, no registry — a natural consumer of portable identity/authority, and a structural foil: verdicts rented from a closed hosted service vs. verifier-independent evidence.
- Agent Passport System reached 42★; its conformance suite pushed today (2026-08-30). Main repo (pushed 2026-08-29), MCP server, and the
Agent-Authority-Conformancesuite all active — the whole multi-repo stack keeps moving in lockstep, plus the verification-only Rust crate and IETF individual draftdraft-pidlisnyi-aps-03. - MolTrust pricing re-verified after last week’s 403.
/pricingnow 301-redirects to/pricing.html(200): $19/mo (2 agents) to $299/mo (75 agents), $9/mo per additional agent, Lightning still “PhoenixD prepped, not yet settling.” API still v2.5/healthy,did:webstill resolves, AAE draft holds at -01. - Chancery stalled for a fourth consecutive cycle (25★ flat, no push since 2026-07-21); decern broke its three-week flat streak (12→13★, pushed 2026-08-24).
- Urbit remains a substrate incumbent at 3621★ / 81★, with fresh pushes on both repos (2026-08-28).
- ANP reached 1407★; AgentConnect 342★ (both pushed 2026-08-28). DID-WBA remains an active compatibility/competition surface.
- AgenticMail reached 212★. Email, SMS, and phone rails continue to be more legible to operators than abstract identity primitives.
- Soulverse’s named npm SDK packages still 404 as of 2026-08-30 (sixth consecutive weekly check). Brochure-stage institutional trust-protocol signal, not a verified decentralized DID root.
- Hedera is still more active in agent tooling than in old DID repos.
hedera-agent-kit-jsis at 67★ and pushed 2026-08-26; the DID repos remain comparatively quiet. - ANS reached 37★ / registry 30★, with all SDKs (Go/Rust/Java) and the trust-discovery repo pushed 2026-08-28 — the registry/transparency-log play stays active.
- Discovery tail is noisy but the execution-boundary pattern repeats: a technocore/$FLOP airdrop-farming cluster dominates new did:key repos; two signal-only entrants —
Trusgent/AgentID(new opendid:agentmethod, 1★) andclared-ai/clared(bounded execution sessions with cumulative budgets and signed evidence, 1★) — the third intent→authority→evidence execution-boundary entrant in three weeks.
What This Means For Archon
- Archon should be described as the sovereign root of authority for delegated agent action, not merely as a DID stack.
- The next public comparison should separate layers: root identity, authorization/delegation, MCP/gateway enforcement, communication protocol, transport rail, receipt/audit layer, and payment rail.
- Agent-Safe Pipeline, Chancery, AgentValet, and Soulverse need bridge responses. Archon should show how
did:cidcredentials can feed policy-verdict boundaries, enterprise IdP/IGA/MCP enforcement, and trust-protocol validation without letting those control planes become the root identity. - Agent Passport System needs a direct response. Archon should show how
did:cidcredentials can feed APS-style gateway enforcement and signed receipts without makingdid:apsthe root identity. APS now has a public IETF draft and third-party-verifier SDKs; Archon’s receipt/delegation story has neither. - MolTrust needs a structural counter, not a feature race. Its packaging is ahead; its trust model is operator-issued. Archon’s response is reputation-as-a-service from one company vs. evidence-first, verifier-independent receipts — plus Lightning-native settlement while MolTrust’s Lightning rail is roadmap-only. Bridge framing stays open: MolTrust-style scoring/compliance layers could consume
did:cidas root identity. - Bindu still needs a collaboration response. Archon should explain where
did:cidcan complementdid:binduas the sovereign root while preserving A2A/x402/inbox-style DX. - The next demo should prove delegated authority and receipts. Example: controller grants capability → agent acts through an MCP gateway or paid API → verifier checks credential → signed receipt records allow/deny/execution/payment.
Current Snapshot
| Project | Stars | Role | Current read |
|---|---|---|---|
| Bindu | 9347 | Identity + A2A + auth + payments platform | Highest-traction DX/platform pressure and bridge target; +662★ this week (largest gain observed); did:bindu appears platform-administered, not a decentralized root of authority |
| Urbit | 3621 / 81 | Personal server OS + P2P network + Urbit ID | High-traction protocol/substrate incumbent; not W3C DID/VC-native but important sovereign-compute pressure |
| ANP | 1407 | Open agent communication protocol suite | High-visibility protocol/spec leader |
| Agent-Safe Pipeline | 530 | Authorization boundary / execution gating | First star decline since launch (533→530★); independent policy verdict + single-use intent-bound grants; decision authority is a closed hosted service |
| AgentConnect | 342 | ANP SDK / DID-WBA auth | Makes ANP implementation-concrete |
| AgenticMail | 212 | Email/SMS/phone-call infra | Strongest adjacent transport traction |
| MolTrust | N/A | Commercial trust infrastructure (identity, VC, reputation, mandates, audit) | Most mature centralized commercial rival; operator-issued trust, live API, deep EU AI Act packaging; AAE draft now -01; structural foil for Archon’s sovereign root authority |
| Agent Passport System | 42 | Delegation enforcement + signed receipts | Direct authority/receipt benchmark; conformance org + verification-only Rust crate + IETF draft -03; conformance suite pushed today |
| decern | 13 | Deterministic authorization kernel + tamper-evident ledger | SMT-proven invariants, AuthZEN PDP, offline-verifiable decision log; broke three-week flat streak |
| Grantex | 31 | Delegated auth + commerce audit | High-signal authorization/commercial-action layer |
| Chancery | 25 | Agent IdP + MCP enforcement | Scoped delegation, instant revocation, audit; stalled four consecutive cycles |
| AgentValet | 1 | IGA + credential governance + MCP proxy | Enterprise governance benchmark: AIMS, SPIFFE, AuthZEN, CIBA |
| Agent Name Service (ANS) | 37 / 30 | Naming registry + transparency log + trust index | IETF-draft registry/SCITT-receipt pressure nearest Archon’s registry layer; CA/DNS-anchored, not sovereign |
| Attestix | 17 | Compliance + credentials + MCP | Strong complementary compliance stack |
| AgentNexus | 9 | DID communication + workflow substrate | Collaboration/workflow watchlist item |
| Kestrel Sovereign | 8 | Sovereign agent framework | Adjacent pressure on portable identity + memory + governance narrative |
| Hedera / did:hedera | 36 / 28 / 67 | DID method + agent/payment/audit substrate | Direct DID competitor and high-signal adjacent enterprise rail |
| Soulverse | N/A | Agent governance + pre-execution validation | Institutional trust-protocol pressure; relevant to credential-gated agent execution, but public SDK packages/repos were not verified and did:soul decentralization appears future-considered rather than current |
| AIP | 15 | Identity + trust + messaging | Partial overlap, modest movement |
| clawdentity | 9 | Messaging + identity fabric | Closest philosophical rival, slower recent movement |
| Motebit | 5 | Sovereign runtime + receipts | Early but strategically relevant |
| HelixID | 4 | DID/VC auth layer | Low traction, standards-aligned framing; repo moved to dedicated helixid org |
| Agentic Airlock | 2 | OAuth trust/compliance layer | OAuth/compliance watchlist item |
| Credat | 2 | Scoped credentials SDK | Practical authorization/delegation benchmark |
| IDProva | 1 | Enterprise identity + audit receipts | Enterprise auditability angle |
| A2AL | 1 | P2P discovery/networking | Early decentralized communication watchlist |
| Chorus | 1 | P2P encrypted communication | Early decentralized messaging watchlist |
| payelink | 2 | DID SDK | Narrow identity component |
| agent-did | 0 | DID + VC toolkit | Direct standards competitor, low traction |
| agent-identity-hub | N/A | Platform/orchestration | Still unavailable / 404 |
Immediate Priorities
- Rewrite Archon’s public one-liner around sovereign root authority + delegated action + MCP/API enforcement + signed receipts + payment-aware settlement.
- Publish direct comparisons covering
did:cidvs APS gateway enforcement,did:bindu, Urbit ID/Azimuth, did:wba,did:hedera, and enterprise IdP/IGA control planes such as Chancery/AgentValet — now including service-boundary verdict services (Agent-Safe Pipeline) alongside kernels (decern). - Build a small demo around capability issuance, delegated action, MCP gateway/service enforcement, Soulverse-style pre-execution validation, and verifiable receipt.
- Treat APS, Agent-Safe Pipeline, Chancery/AgentValet, Soulverse, and Bindu as the clearest near-term authority/platform bridge narratives; AgentNexus and Urbit as workflow/sovereign-compute bridge narratives; AgenticMail as transport; Hedera HCS/x402 as optional audit/payment; Airlock/Grantex as enterprise authorization/compliance patterns.
- Track Bindu, APS, Agent-Safe Pipeline, decern, Chancery, AgentValet, ANS, Soulverse, MolTrust, AgentNexus, Kestrel, Airlock, AgenticMail, Hedera, Grantex, Motebit, Credat, HelixID, IDProva, A2AL, Chorus, and Digital Bazaar during the next sweep.
Full details, matrices, and strategic framing live in the main report. Change notes for this sweep are in the 2026-08-30 refresh.