The scale of automated activity

Automated systems already generate more than half of internet traffic, while AI-sourced visits are growing across industries. The two sources below measure different things, but both show the scale of the decision facing service providers. Treating all automation as one class cannot distinguish intended agent activity from abuse. TSAI adds verified evidence about the agent and operator to that decision.

What are trust signals?

A TSAI credential carries two layers of information: operator-level signals about the company behind the agent, and agent-level signals about the specific agent program. The trust authority signs the credential, and the service provider verifies it offline against published material — the common verification path does not contact the trust authority during the request.

Operator signals

The company behind the agent — verified once, shared across all its agents

  • Legal identityAcme Corporation GmbH
  • KYC levelEnhanced
  • CertificationsISO 27001
  • Controlled domainacme-corp.example
  • Domain age2 years, 4 months

Agent signals

This specific agent program — builds its own track record over time

  • Agent identityacme-corp.example/shopper
  • Reputation score0.94
  • Observation windowpast 90 days
  • Interactions3,518
  • Credential expiry30 minutes

Example payload

{
  "iss": "https://trust-authority.example",
  "vct": "https://tsaiprotocol.org/credential/tsai/1",
  "vct#integrity":
    "sha256-VWaSSviMOFcp1vsoU3ReObfIF8+sKBiEyfkL9npfZmA=",
  "iat": 1781863200,
  "exp": 1781865000,
  "sub": "https://acme-corp.example/agents/shopper",
  "cnf": { "jwk": { "kty": "EC", "crv": "P-256",
    "x": "TCAER19Zvu3OHF4j4W4vfSVoHIP1ILilDls7vCeGemc",
    "y": "ZxjiWWbZMQGHVWKVQ4hbSIirsVfuecCE6t4jT9F2HZQ" } },
  "signals": [
    { "cat": "idn", "typ": "org",
      "val": "Acme Corporation GmbH" },
    { "cat": "idn", "typ": "jur", "val": "DE" },
    { "cat": "idn", "typ": "kyc", "val": "enhanced" },
    { "cat": "idn", "typ": "dct",
      "val": "acme-corp.example", "asof": 1781860000 },
    { "cat": "idn", "typ": "dag",
      "val": "P850D", "asof": 1781860000 },
    { "cat": "cmp", "typ": "iso27001",
      "prv": "did:web:cert-corp.example",
      "asof": 1780000000 },
    { "cat": "rep", "typ": "ecommerce",
      "mtd": "https://trust-authority.example/rep/v1",
      "mtd#integrity":
        "sha256-Td9FdWbwljmeY78DD/gKxGxPSjjV9vzvOU3oXPH4dJY=",
      "scr": 0.94, "cnt": 3518, "wdw": "P90D",
      "asof": 1781800000 }
  ]
}
Illustrative credential following the canonical TSAI v1 schema. vct and vct#integrity pin the credential definition, cnf carries the holder-binding key, and iat and exp mark the 30-minute lifetime. Each signal has a category (cat) and type (typ) with type-specific fields; reputation carries a normalised score (scr, 0–1), interaction count (cnt), observation window (wdw), and a pinned methodology (mtd, mtd#integrity). asof is when the trust authority last confirmed the fact.