Autheo Platform · Identity Layer
TheoID
TheoID is Autheo's in-development sovereign identity layer for people, validators, devices, and AI agents. It is planned to roll out on mainnet.
Most blockchains do not have a native identity layer. Developers who need authentication, credential issuance, or sovereign identity for users or agents have to stitch together external services — wallet providers, third-party DID registries, centralised OAuth, or Web2 auth vendors. TheoID is being developed to reduce that dependency. As it rolls out, it is intended to integrate with the Autheo OS alongside compute, storage, and AI inference, without requiring a separate identity stack.
What TheoID provides
Planned Post-Quantum Key Material
TheoID is being developed to use NIST-selected algorithms, including ML-KEM (Kyber), ML-DSA (Dilithium), and SLH-DSA (Falcon), to help protect identities against classical and anticipated quantum attacks. Hybrid signing paths are planned for the migration window.
Self-Sovereign by Design
TheoID is designed without a central issuer, so users can control their keys. Its planned on-chain identity model is intended to avoid the single point of failure that centralised identity systems introduce.
Universal Subject Types
TheoID is being designed to issue verifiable credentials for people, enterprises, validator nodes, IoT devices, and autonomous AI agents. The planned credential model spans human and machine identity without requiring a different system for each.
W3C Standards Alignment
TheoID is being designed to interoperate with W3C Decentralized Identifiers (DIDs) and W3C Verifiable Credentials (VCs). As it rolls out, existing identity tooling and compliance workflows that speak the W3C stack are intended to integrate without starting from scratch.
THEO Token Utility
When TheoID rolls out, THEO is intended to support registration, credential management, and post-quantum identity operations. Identity is a planned demand vector for the THEO utility token.
KYA Integration
TheoID is intended to be the anchor layer for Know Your Agent (KYA), Autheo's credential reference framework for AI agent identity, controller identity, merchant identity, and mandate credentials. As autonomous agents transact on behalf of users, the planned design is intended to give counterparties a verifiable answer about who is acting and under what authority.
Post-quantum cryptography
Quantum computers capable of breaking elliptic-curve cryptography (ECDSA, EdDSA) are not yet operational, but credentials and long-lived identities issued today may be harvested and decrypted later. TheoID is being developed around NIST-selected post-quantum algorithms so that, when it rolls out, its identity model is designed to reduce that long-term risk.
The three planned algorithms are:
- ML-KEM (Kyber), planned for key encapsulation and establishing shared secrets.
- ML-DSA (Dilithium), planned for credential signing and verification.
- SLH-DSA (Falcon / SPHINCS+), planned as a stateless hash-based signature scheme for long-lived credentials where signature size is acceptable.
Hybrid signing paths (classical + post-quantum) are planned for the transition period so existing tooling remains compatible while quantum resistance is phased in.
Who and what TheoID identifies
| Subject type | Use |
|---|---|
| Person / user | Planned sovereign wallet authentication, credential holder, KYC/KYB anchor |
| Enterprise / organization | Planned corporate identity, partner credentials, compliance anchoring |
| Validator node | Planned node ownership proof, on-chain TheoID binding, staking eligibility |
| IoT / device | Planned device identity for DePIN workloads, edge compute, sensor networks |
| AI agent | Planned agent credential, controller binding, KYA mandate authorization |
TheoID and AI agents: Know Your Agent
Autonomous AI agents now buy, subscribe, pay for API access, and execute mandates on behalf of users. Existing identity primitives describe people and companies. They do not describe agents. TheoID is being designed as the anchor layer for Know Your Agent (KYA), Autheo's credential reference framework that defines agent credentials, controller credentials, merchant credentials, and mandate credentials, with verification planned as the layer rolls out.
This matters because as autonomous agent transactions scale, the question “who authorized this agent to spend on my behalf?” needs a cryptographically verifiable answer, not a policy document. TheoID is being developed to provide that answer.
THEO token and identity
Staking and transaction fees are live today. When TheoID rolls out, THEO is intended to support registration, credential management, and post-quantum identity operations alongside the planned compute, storage, and AI inference utilities.
Read more about the THEO token identity utility.
Related
KYA: Know Your Agent
Credential framework for AI agent identity, designed to use TheoID as it rolls out.
THEO Token: Identity
How THEO is intended to support TheoID registration and credentials.
Glossary: TheoID
Concise definition and terminology reference.
What is Autheo?
Full overview of the Autheo Layer-0 OS and its components.