Skip to content

Pre-release. v0.1 is not out yet, so there is nothing to install and no public source to clone — the quickstart builds from a checkout.

What Subact ID is, and what it is not

Subact ID sits between the people in your organisation and the agents that act for them. An agent asks Subact ID for a token to act on someone’s behalf. Subact ID answers with a short-lived token whose scope is the intersection of what that person holds, what the agent is registered for, and what the agent asked for. Every answer, including every refusal, is written to an audit ledger. Signed checkpoints seal the ledger, so a later edit can be detected.

Without Subact ID, an agent often holds a static API key. The key does not expire, it carries the key’s permissions rather than the caller’s, and the logs name a service account rather than a person.

With Subact ID, the agent exchanges the user’s access token and its own signed assertion for a task token:

  • The subject (sub) is the user.
  • The actor (act) is the agent.
  • The scope is no wider than what the user holds or the agent is registered for.
  • The token lasts minutes, and never longer than the task it belongs to.
  • Not an identity provider. Subact ID does not hold your users, their passwords or their groups. An upstream OIDC provider authenticates the person, and Subact ID takes that person’s access token as the subject of an exchange.
  • Not an API gateway. Subact ID is not in the request path between an agent and a tool. It issues tokens; the tool server validates them, usually with the SDK.
  • Not a policy engine for business rules. Its policy covers scopes, audiences, lifetimes and delegation depth. Whether a particular ticket may be closed is your application’s decision.
  • Not an agent framework. It does not care how your agent is built or which model it uses.
Component Why In v0.1
An OIDC identity provider Authenticates the person and issues the access token an exchange starts from Any provider that issues JWT access tokens. poll mode also calls the admin API, in Keycloak’s shape
A database Holds the agent registry, tasks and the audit ledger Postgres 16, or an embedded SQLite file for a trial or a single node
The control plane Issues and checks tokens One service

Each agent’s public keys can sit in its registration, and the control plane serves them. An agent may instead publish its own key set over HTTPS.

The control plane is its own OIDC issuer, so agents and tool servers find it through a standard discovery document.

Subact ID checks at every exchange and refresh whether the person may still be acted for. In poll mode (the default) it asks the identity provider’s admin API. In signals mode it asks nothing and acts on what it is told. Connect your identity provider covers both modes.

Subact ID Pre-release. v0.1 is not out yet.

© 2026 Nikola Živković PR Agencija za programerske usluge Novi Sad. Subact ID is its product.

LegalTermsPrivacy