Skip to main content
This v2.7.4 source says it verifies token audiences, but verify_audience remains disabled and the issued tokens have no aud claim. To reject tokens created for another AgentOS, set verify_audience=True in AuthorizationConfig and add "aud": "my-agent-os" to the token payload. Until then, another instance using the same HMAC secret can accept these tokens.
Issue HS256 tokens for five privilege tiers and use global, per-agent, and wildcard scopes to filter agents and gate runs.
advanced_scopes.py

Run the Example

The source falls back to a public demonstration secret. Local demos can use it, but before exposing this server set JWT_VERIFICATION_KEY to a private random value of at least 32 bytes and use the same value to sign tokens.
1

Set up your virtual environment

2

Install dependencies

3

Export your OpenAI API key

4

Run PgVector

5

Run the example

Save the code above as advanced_scopes.py, then run:
Full source: cookbook/05_agent_os/rbac/symmetric/advanced_scopes.py