AC2 Protocol: Giving AI Agents Cryptographic Proof of Intent
AC2 Protocol: The missing security layer for AI agents

The AC2 Protocol, an open-source project by the Algorand Foundation, adds a missing security layer for AI agents. It uses hardware-bound FIDO2 signatures to verify human intent before agents execute sensitive actions like payments or code deploys. Credentials stay on the user's device, and every approval is cryptographically signed for a defensible audit trail. AC2 integrates with agent frameworks like OpenClaw via a plugin and works without a blockchain or central relay.
Stop trusting chat button clicks and start owning your actions with cryptographic proof.
- semiquaver
I can’t help but see the crypto stink all over this and recoil. This is just trying to salvage ideas and tools from the last fad into the current one.
Seems like “ask for approval, except you approve by spending a little of some random altcoin”
> Disclaimer: AC2 is a self-custodial Algorand wallet. You — and only you — hold your seed phrase, your keys, and your crypto-assets on your own device. Pera Wallet, Lda does not hold, custody, or have access to your seed phrase, your keys, or your crypto-assets, and cannot recover them on your behalf.
- josephcecala
AC2 is an open standard that puts users back in control of AI-driven signing operations, providing verifiable proof of intent and credential isolation.
The problem: a compromised agent runtime (e.g. a malicious plugin dependency) can leak everything injected into it like API keys or session tokens, and there's no way to prove whether a human actually approved what happened, since chat-based "approvals" are just messages, spoofable and session-hijackable.
AC2 closes both gaps. Approvals become a FIDO2 passkey signature from your device, that's hardware-bound, phishing-resistant, and a real audit trail instead of a chat message. And credentials never enter the runtime at all: the agent gets a signed authorization, not the key. Compromise the runtime, there's nothing to steal.
Under the hood: AC2 opens a direct, end-to-end encrypted WebRTC connection between a user's wallet and an agent. When the agent needs to sign something (a payment, a commit, an API call), it sends the request via AC2, the user approves from their own wallet, and the signature is delegated back. The private key never leaves the user's device.
Built on three open standards: DIDComm v2.0 (messaging), WebAuthn/FIDO2 (hardware-bound auth), and WebRTC DataChannel (P2P transport, no relay servers). Lightweight (~50 lines for a basic flow), blockchain-agnostic, and works alongside your existing setup. One plugin, one command.
Built by the Algorand Foundation team behind Pera Wallet, Rocca, Intermezzo, and LiquidAu […]
- chrisjj
> You need sovereignty.
You keep using that word. I do not think it means what you think it means.