1. Go to this page and download the library: Download agentadmit/agentadmit-sdk library. Choose the download type require.
2. Extract the ZIP file and open the index.php.
3. Add this code to the index.php.
<?php
require_once('vendor/autoload.php');
/* Start to develop here. Best regards https://php-download.com/ */
$result = $introspectionClient->verify($token);
if (!$result->consentGranted()) {
abort(403, 'The data owner has not enabled external agent access.');
}
use AgentAdmit\ConsentClient;
$consent = new ConsentClient(config('agentadmit'));
$verdict = $consent->checkConsent('user_8842', ConsentClient::CALLER_CLASS_IN_APP_AI);
if (!$verdict['granted']) {
// do not run AI over this user's data
}
// config/agentadmit.php
'caller_consent' => [
// derive the class from your own credential structure, never caller input
'classify_non_agent' => fn ($request) => $request->headers->get('x-internal-ai') === env('INTERNAL_AI_SECRET')
? 'in_app_ai' : 'human_session',
'resolve_data_owner_id' => fn ($request) => $request->route('owner_id'),
],
// routes: the middleware parameter is the
$result = $introspectionClient->verify($token);
if (!$result->presenceVerified()) {
abort(403, 'This action
$result = $introspectionClient->verify($token);
$result->purpose; // 'Reorder the usual weekly groceries', or null when none was declared
$issued = $tokens->issueToken(
'user_42',
['read:orders'],
purpose: 'Reorder the usual weekly groceries', // the app's words
userIntent: 'get my usual Tuesday order', // the user's own words
);
$result = $introspectionClient->verify($token);
$result->userIntent; // 'get my usual Tuesday order', or null when none was declared
use AgentAdmit\AppAttestedPresence;
$issued = $tokensClient->issueToken(
'user_42',
['read:orders'],
presence: new AppAttestedPresence('my_webauthn', $attestation->createdAt)
);
use AgentAdmit\Webhook;
use AgentAdmit\AgentAdmitException;
Route::post('/agentadmit/alerts', function (Request $request) {
try {
Webhook::verifySignature(
$request->getContent(),
$request->header('X-AgentAdmit-Signature', ''),
config('agentadmit.webhook_secret'), // whsec_… from AGENTADMIT_WEBHOOK_SECRET
);
} catch (AgentAdmitException $e) {
return response()->json(['error' => 'invalid_signature'], 400);
}
$event = $request->json()->all();
// ...
});
use AgentAdmit\TokensClient;
$tokens = app(TokensClient::class);
// Duration is tri-state:
// omit the argument → AgentAdmit default (30 days)
// null → until the user revokes
// int seconds (60–31536000) → explicit duration
// The optional purpose (max 300 chars) is shown to the human at the consent
// moment and recorded on the grant — see "Declared Purpose" above. The
// optional userIntent (1-300 chars) is the user's own words — see
// "User-Declared Intent" above.
$issued = $tokens->issueToken(
'user_42',
['read:orders'],
role: 'user',
durationSeconds: null,
purpose: 'Reorder the usual weekly groceries',
userIntent: 'get my usual Tuesday order',
);
$connectionToken = $issued['token']; // ag_ct_…
// Agent side - no API key needed; the connection token is the credential.
$granted = $tokens->exchange($connectionToken, agentLabel: 'MyAssistant');
// Revoke when the user disconnects the agent.
$tokens->revoke($granted['connection_id'], reason: 'user_requested');
Loading please wait ...
Before you can download the PHP files, the dependencies should be resolved. This can take some minutes. Please be patient.