AC2 Protocol

Agentic Communication + Control Protocol (AC2) upgrades your stack with hardware-bound, non-custodial signatures that ensure every action is a verifiable expression of your sovereign will, all without ever sharing your keys.

It's cryptographic control for the agentic age.

Frame 1000005656-2
Frame 1000005649

The gap in today's HITL frameworks

As AI agents take on payments, code signing, and other sensitive operations, today's human-in-the-loop approaches lack verifiable identity, standardized delegation, and cryptographic proof of user intent. AC2 fills those gaps with hardware-bound approvals, credential isolation, and signed, defensible audit trails.

  • Credential isolation: Private keys never leave your device. Agents request intent, but never see your keys.
  • Phishing-resistant: FIDO2 hardware-bound approvals protect against phishing and replay attacks. 
  • Verifiable intent: Cryptographic proof of who approved what, when, and for which action.

You have automation. You need sovereignty.

Native Chat HITL is the standard. AC2 is the sovereign upgrade.

Stop trusting chat button clicks and start owning your actions with cryptographic proof.

 

AC2-Website-Comparison chart-Desktop-2

 

AC2 is an open protocol that sits between your AI agent and sensitive actions.

Instead of giving agents credentials, AC2 requests a hardware-bound signature from the user, generating cryptographic proof of intent before execution.

Frame 1000005651-1

Add AC2 to your agent

Already running an agent framework like OpenClaw?

AC2 installs as a plugin — your agent gets a signing channel to the user's wallet without touching a single key.

To install it:

1. Run openclaw plugins install and openclaw ac2 setup.

2. Pair it with the AC2 Wallet on your phone.

What you can prove

Upgrade your existing frameworks with one plugin and one command line. AC2 uses DIDComm v2.0 message formats for interoperability, passkey-based authentication via Liquid Auth (built on FIDO2/WebAuthn), and supports real-time voice and text streaming alongside signing delegation. It requires no central message relay and no blockchain to operate. AC2 supports any type of agentic workflow – you can use it for any custom schema you define via JSON-LD.

Here are some examples of what you can do with AC2:

 

Code deploys

Signed commits with hardware-backed proof that a human exercised final authority over the change set before the merge.

Client communications

A signed approval on the exact message body sent by the agent, proof a human signed off before anything reached the outbox.

API access

The agent presents exact request parameters for approval before execution, the signature proves what was authorized, by whom, and when.

x402 payments

Payment details route straight to the user's wallet for approval, authorization without ever exposing the private key.

Intent-based actions

The agent submits a Google AP2 IntentMandate defining what it may do and under what constraints, signed once, enforced cryptographically after.

Try AC2 in action

Test how hardware-bound signatures work for secure agent approvals by downloading the AC2 Wallet. Approvals are secured using your device's FIDO2 authenticator — facial recognition, fingerprint, or a device PIN. To try it:

  1. Download the AC2 Wallet app.
  2. Scan the QR code shown in your agent's pairing screen.

Why Algorand?

Algorand has spent years building secure, decentralized systems where cryptographic proof, peer-to-peer communication, and user sovereignty are foundational. The agent approval problem felt familiar: agents need to act on behalf of users, but users need a way to retain control, protect their credentials, and prove what they authorized.

Security-transparent-bg
Security heritage

The foundations of AC2 come from problems we've been solving for years. Our work on LiquidAuth and peer-to-peer communication focused on how users could retain control of their credentials while securely authorizing actions across distributed systems. AC2 extends that thinking to AI agents, replacing trust-based approvals with hardware-bound cryptographic proof of intent.

Documents-transparent-bg
Open by design

AC2 is a transparent, open protocol designed for any agent stack. It gives developers a verifiable standard for agent approvals without requiring proprietary middleware or relay infrastructure.

Certainty-transparent-bg
Building on proven standards

AC2 uses battle-tested security primitives, including FIDO2 authenticators and secure enclave technology. Instead of inventing a new trust model, AC2 applies widely adopted cryptographic standards to the emerging problem of agent authorization.

 
Solving the AI trust problem with hardware-bound authentication and peer-to-peer communication.

© 2026 AC2 Protocol. All rights reserved. An open-source project by the Algorand Foundation.

Terms of Service

 

Disclaimer: AC2 is a self-custodial Algorand wallet. You — and only you — hold your seed phrase, your keys, and your crypto-assets on your own device. Pera Wallet, Lda does not hold, custody, or have access to your seed phrase, your keys, or your crypto-assets, and cannot recover them on your behalf.

If you lose your device or your recovery phrase, your access to anything you have linked through AC2 may be permanently lost. Your recovery phrase is the only way to restore access to your wallet. Pera cannot recover it for you. If you lose it, your crypto-assets and account associations are lost permanently. Do not share it with anyone, including anyone claiming to be Pera support.

Crypto-asset transactions are irreversible once confirmed on the Algorand network. Crypto-assets are volatile, may lose value, and may become illiquid or unavailable. You are responsible for any tax or other legal obligations arising from your use of crypto-assets.

The use of agentic commerce involves risks, including potential fraud and identity verification issues. Users and merchants should ensure they are using verified agents and follow best practices for security and compliance.