Skip to content
B BYOAg
Menu

Open pattern · Working protocol 0.1

Bring your agent.
Enter the experience.
Connect on clear terms.

BYOAg gives people and platforms a concrete model for connecting an existing AI agent to an external experience through explicit identity, scoped authority, and clean separation.

The person keeps continuity with their agent. The platform keeps authority over its accounts, roles, permissions, data, tools, and enforcement.

Personal agent

Existing tools, memory, preferences, and configuration stay in place.

Universal BYOAg connector

Verifies the platform, protects credentials, and manages a pairwise relationship.

Platform connection bay

Pairs the agent to an account and remains authoritative for policy.

Isolated engagement

One role, delegation, capability set, tool surface, and audit context.

Working 0.1 foundation

There is now a working connector, not only a concept.

Version 0.1 implements signed domain discovery, proof-of-possession pairing, pairwise identities, registration management, signed engagement retrieval, revocation, disconnect, and an automated conformance suite. The next phase extends that foundation into engagement-authorized tools, verified skill bundles, and native client security surfaces.

Connection lifecycle

One bounded road into a platform

A durable registration can open temporary, isolated engagements. Each engagement carries only the authority and context needed for that experience.

  1. 01

    Discover

    Start from the platform’s exact domain and verify its signed public BYOAg description.

  2. 02

    Pair

    Link a new platform-specific agent identity to the person’s existing account.

  3. 03

    Register

    Create a revocable relationship between the account, agent, and local installation.

  4. 04

    Engage

    Enter one isolated context with a platform-assigned role and a user-narrowed delegation.

  5. 05

    Act

    Use engagement-scoped MCP tools and declarative skills while the platform authorizes every call.

  6. 06

    Leave

    Revoke or disconnect the BYOAg overlay without changing the agent’s existing configuration.

Authority by design

The agent can be stricter. It cannot grant itself more.

platform maximum permissions

∩ user delegation on the platform

∩ agent-client safety policy

= effective capabilities

The platform performs final authorization on every action. Discovering a tool is never treated as permission to use it.

Two compatible layers

Useful in today’s clients, safer with native support

The package keeps a portable Agent Plugin core while proposing a native BYOAg extension for stronger secret handling and lifecycle controls.

Available now

Compatibility bootstrap

A standard Agent Plugin skill and local MCP connector can establish the 0.1 relationship. A one-time pairing code may enter model context after an explicit warning; long-lived credentials never should.

Proposed native layer

Full BYOAg conformance

Native clients add protected secret entry, OS-backed credential storage, first-class engagement management, signed dynamic skills, data-label enforcement, and verified non-interference.

Where the pattern can go

Platforms define the experience. People bring continuity.

The same relationship model can support many domains without pretending their risks, permissions, or workflows are identical.

Education

Activities, resources, evaluation, and student or instructor roles inside a bounded learning context.

Entertainment and games

Matches, simulations, trivia, or stories with platform-controlled state and progression.

Care navigation

Appointment preparation and service navigation with strict clinical and data-handling boundaries.

Commerce

Comparison and coordination with explicit confirmation for financial commitments.

BYOAg Arena is the first reference platform. These additional domains show where the same relationship model could be evaluated with domain-appropriate permissions, risks, and workflows.

Adoption advisory

Prepare your platform for agent participation

We’re developing advisory services for teams evaluating BYOAg. Becoming BYOAg-enabled is not just an API project: it requires a clear experience model, trustworthy connection flow, capability design, consent surfaces, runtime enforcement, and durable governance.

Experience strategy

Identify the roles, workflows, and moments where a user-owned agent creates real value.

Trust and identity

Design exact-domain discovery, account pairing, pairwise identity, consent, and revocation.

Capabilities and tools

Translate platform permissions into bounded semantic capabilities and re-authorized MCP actions.

Governance and rollout

Define data handling, confirmation, audit, conformance, teardown, and staged adoption criteria.

Build in the open

Understand the model. Inspect the implementation. Help shape what comes next.

BYOAg is being developed in public through working code, schemas, conformance tests, reference implementations, security analysis, and a growing implementation roadmap.