Autheo

Autheo Platform · Identity Layer

TheoID

TheoID is Autheo's in-development sovereign identity layer for people, validators, devices, and AI agents. It is planned to roll out on mainnet.

Most blockchains do not have a native identity layer. Developers who need authentication, credential issuance, or sovereign identity for users or agents have to stitch together external services — wallet providers, third-party DID registries, centralised OAuth, or Web2 auth vendors. TheoID is being developed to reduce that dependency. As it rolls out, it is intended to integrate with the Autheo OS alongside compute, storage, and AI inference, without requiring a separate identity stack.

What TheoID provides

Planned Post-Quantum Key Material

TheoID is being developed to use NIST-selected algorithms, including ML-KEM (Kyber), ML-DSA (Dilithium), and SLH-DSA (Falcon), to help protect identities against classical and anticipated quantum attacks. Hybrid signing paths are planned for the migration window.

Self-Sovereign by Design

TheoID is designed without a central issuer, so users can control their keys. Its planned on-chain identity model is intended to avoid the single point of failure that centralised identity systems introduce.

Universal Subject Types

TheoID is being designed to issue verifiable credentials for people, enterprises, validator nodes, IoT devices, and autonomous AI agents. The planned credential model spans human and machine identity without requiring a different system for each.

W3C Standards Alignment

TheoID is being designed to interoperate with W3C Decentralized Identifiers (DIDs) and W3C Verifiable Credentials (VCs). As it rolls out, existing identity tooling and compliance workflows that speak the W3C stack are intended to integrate without starting from scratch.

THEO Token Utility

When TheoID rolls out, THEO is intended to support registration, credential management, and post-quantum identity operations. Identity is a planned demand vector for the THEO utility token.

KYA Integration

TheoID is intended to be the anchor layer for Know Your Agent (KYA), Autheo's credential reference framework for AI agent identity, controller identity, merchant identity, and mandate credentials. As autonomous agents transact on behalf of users, the planned design is intended to give counterparties a verifiable answer about who is acting and under what authority.

Post-quantum cryptography

Quantum computers capable of breaking elliptic-curve cryptography (ECDSA, EdDSA) are not yet operational, but credentials and long-lived identities issued today may be harvested and decrypted later. TheoID is being developed around NIST-selected post-quantum algorithms so that, when it rolls out, its identity model is designed to reduce that long-term risk.

The three planned algorithms are:

  • ML-KEM (Kyber), planned for key encapsulation and establishing shared secrets.
  • ML-DSA (Dilithium), planned for credential signing and verification.
  • SLH-DSA (Falcon / SPHINCS+), planned as a stateless hash-based signature scheme for long-lived credentials where signature size is acceptable.

Hybrid signing paths (classical + post-quantum) are planned for the transition period so existing tooling remains compatible while quantum resistance is phased in.

Who and what TheoID identifies

Subject typeUse
Person / userPlanned sovereign wallet authentication, credential holder, KYC/KYB anchor
Enterprise / organizationPlanned corporate identity, partner credentials, compliance anchoring
Validator nodePlanned node ownership proof, on-chain TheoID binding, staking eligibility
IoT / devicePlanned device identity for DePIN workloads, edge compute, sensor networks
AI agentPlanned agent credential, controller binding, KYA mandate authorization

TheoID and AI agents: Know Your Agent

Autonomous AI agents now buy, subscribe, pay for API access, and execute mandates on behalf of users. Existing identity primitives describe people and companies. They do not describe agents. TheoID is being designed as the anchor layer for Know Your Agent (KYA), Autheo's credential reference framework that defines agent credentials, controller credentials, merchant credentials, and mandate credentials, with verification planned as the layer rolls out.

This matters because as autonomous agent transactions scale, the question “who authorized this agent to spend on my behalf?” needs a cryptographically verifiable answer, not a policy document. TheoID is being developed to provide that answer.

THEO token and identity

Staking and transaction fees are live today. When TheoID rolls out, THEO is intended to support registration, credential management, and post-quantum identity operations alongside the planned compute, storage, and AI inference utilities.

Read more about the THEO token identity utility.