Coding

certen

Try it

Give this agent a CERTEN identity and let it execute proof-gated actions on any chain it is linked to. It never spends without the owner's explicit consent.

What it does

Give this agent a CERTEN identity and let it execute proof-gated actions on any chain it is linked to. It never spends without the owner's explicit consent.

The skill document

CERTEN for agents

CERTEN gives an agent an on-chain identity it does not custody a key for, accounts on any supported chain that only execute what a validator quorum has proved, and a receipt a stranger can verify without trusting the agent or its owner. Use it for anything where money is at stake and more than one party has to agree: escrow legs, settlement, arbitration, insurance, a regulator's seat.

Do NOT use it for chat, discovery, or small per-message fees. A proof costs money (about $0.35 on Base, about $1 to $4 on Ethereum) and takes 60 to 110 seconds. Putting that in front of a $3 fee makes everything slow and proves nothing anyone needs proved.

Every command below prints JSON with --json, wrapped as {"ok": true, "data": ...} on success and {"ok": false, "error": {"code": ..., "message": ...}} on failure. Read data, never the prose.

An identity costs money. Every proof-gated action costs money and moves the owner's funds. So:

  1. Quote first: certen quote --chain --json and certen balance --json.
  2. Show the owner the cost and the balance.
  3. Ask, in plain words, whether to proceed. Do not proceed on silence.
  4. Only then run the action. Never run identity create, call, tx create, or governance * without an explicit yes for that specific action.

If the owner has not told you which chain, use base-sepolia on testnet. It is the cheapest chain CERTEN runs and every command here works on it.

certen keys generate --name agent --no-passphrase        # an Ed25519 key that never leaves this machine
certen signup --with-key agent --org-name - --no-keyring --json
certen doctor --json                                     # names the one thing blocking you, if any

signup proves you hold the key and returns an organization with a $10 trial. It prints only the API key's prefix; the key is stored in ~/.certen/config.json. Nothing goes into this skill's environment, and nothing needs to.

Sandboxed hosts: if this agent runs in a container whose home directory is wiped between sessions, ~/.certen vanishes with it. Persist ~/.certen/keys/agent.json and ~/.certen/config.json in the workspace and restore them at session start, or the identity you created cannot be signed for.

Where am I

Run scripts/where-am-i.sh (bundled) or the three commands inside it:

certen whoami --json          # org, key prefix, gateway, standing
certen identity list --json   # identities and their accounts per chain
certen balance --json         # spendable, held, and whether a shortfall is refused or only recorded

balance.enforcing is the fact that matters: false means the gateway meters and records shortfalls but refuses nothing (testnet today); true means a run short of funds stops with a 402.

Get an identity

certen identity create --name  --sign-with agent --chains base-sepolia --wait --json

The result carries id (a uuid: use it in every later command), adi_url (the identity itself, acc://.acme), and chain_accounts[] with an address per chain. That address is this agent's msg.sender on that chain.

One identity, many chains — no new identity, no new key:

certen identity link-chain  --chain arbitrum-sepolia --json

Execute something, proof-gated

Any contract call from the agent's account. The validators execute exactly this target, value and calldata, after a quorum has proved it, or nothing.

certen call --identity  --chain base-sepolia --to  \
  --fn "ship(bytes32,string)" --arg 0x --arg "TRACK-1" \
  --sign-with agent --wait --json
  • --value forwards native value with the call. Wei, as a string.
  • An ERC-20 move is a call on the token contract: --to --fn "transfer(address,uint256)" --arg --arg . USDC has 6 decimals.
  • --proof-class on_cadence batches the proof (cheaper, default in most kits); on_demand is immediate and costs more on Ethereum.

Wait for the outcome with certen tx status --wait --json. Two failures mean different things:

  • status: failed with reason_code: target_reverted — CERTEN did its whole job and the contract said no. A business outcome. Retrying the identical call reverts again.
  • anything else — CERTEN did not complete. Infrastructure or funding. Read certen errors --json for the code you got.

Hand the counterparty a proof, not a promise

certen proof get  --json                 # the proof artifact, once it has anchored
certen proof share  --hours 72 --json     # a link that resolves with NO API key

The artifact anchors 60 to 120 seconds after the leg completes. If proof get says there is none yet, wait and retry; do not send the counterparty a bare transaction hash instead. They open the link with certen proof open and verify it against CERTEN, not against you.

Being regulated

The owner can make their policy signer a required co-signer on this identity. From then on every transaction this agent submits waits until the owner's rules approve it, and the agent cannot opt out. The owner runs:

certen governance add-authority --identity acc://.acme \
  --authority acc://.acme/book --sign-with agent --json

Once that is in place, a call or tx create returns with the transaction pending; the policy signer decides and the transaction proceeds or is rejected. Treat pending as normal, not as an error. certen pending list --json shows what is waiting.

When something refuses you

  • CHAIN_NOT_PRICEABLE: CERTEN's price book will not sell on that chain right now. That is on CERTEN's side; tell the owner and try another chain.
  • CHAIN_SUSPENDED: the chain is paused while costs are investigated. Wait retry_after_sec.
  • 402 / INSUFFICIENT_BALANCE: only when enforcing is true. certen fund --chain --json prints where to send testnet USDC.
  • no proof artifact yet: normal for about two minutes after a leg completes. Wait.

Never work around a refusal by changing amounts, retrying in a loop, or using another identity. Report it to the owner with the code and the exact message.

Related skills

Certn (certn.co). Use this skill for ANY Certn request — searching and reading data. Whenever a task involves Certn, use this skill instead of calling the AP...

1 installs

Verify wallets, tokens, smart contracts, AI agents and web applications before trusting them, paying per call in USDC over x402

1 installs

Look up ERC-8004 agents in the on-chain identity index and read their Cybercentry risk scores with ERC-8126scan before trusting them.

1 installs

Quantum Circuit Builder with Proof: Use this product when a quantum circuit needs verifiable evidence, not just. Use when an agent needs quantum circuit builder with proof, formally verified quantum circuit design, proof carrying quantum circuit certificates (qpcert), independent verification of a quantum proof certificate from another party, audit ready quantum computing artifacts for research and compliance, certify circuit, circuit, claims through AgentPMT-hosted remote tool calls.

1 installs

Confirm a SAR v0.1 settlement receipt is cryptographically valid before acting on it.

86 installs1 stars

Query the CertainLogic Timechain from any Y Combinator QM deployment. 75K+ cryptographically verified agent execution traces for training, audit, and research. Free open-source skill (API sold separately).

1 installs