The problem: a compromised agent runtime (e.g. a malicious plugin dependency) can leak everything injected into it like API keys or session tokens, and there's no way to prove whether a human actually approved what happened, since chat-based "approvals" are just messages, spoofable and session-hijackable.
AC2 closes both gaps. Approvals become a FIDO2 passkey signature from your device, that's hardware-bound, phishing-resistant, and a real audit trail instead of a chat message. And credentials never enter the runtime at all: the agent gets a signed authorization, not the key. Compromise the runtime, there's nothing to steal.
Under the hood: AC2 opens a direct, end-to-end encrypted WebRTC connection between a user's wallet and an agent. When the agent needs to sign something (a payment, a commit, an API call), it sends the request via AC2, the user approves from their own wallet, and the signature is delegated back. The private key never leaves the user's device.
Built on three open standards: DIDComm v2.0 (messaging), WebAuthn/FIDO2 (hardware-bound auth), and WebRTC DataChannel (P2P transport, no relay servers). Lightweight (~50 lines for a basic flow), blockchain-agnostic, and works alongside your existing setup. One plugin, one command.
Built by the Algorand Foundation team behind Pera Wallet, Rocca, Intermezzo, and LiquidAuth. Use cases include code deploys, client comms, API access, x402 payments, and intent-based delegation via AP2 IntentMandates.
Spec is live and open. Reference implementation (AC2 Wallet) is on GitHub, Play Store, and App Store, with a plugin to try the full flow. This is v1, feedback welcome.