Algorand Launches AC2 Protocol to Keep AI Agents Off Users’ Keys
Key Takeaways
- •AC2 launched on August 25 as an open-source protocol for agent approval flows.
- •The protocol allows users to authorize AI agent actions without exposing private keys or API credentials.
- •AC2 combines DIDComm v2.0, WebAuthn/FIDO2 and WebRTC DataChannels for secure request and transport handling.
- •Algorand says AC2 can work without a central relay or blockchain, while still supporting on-chain use cases such as x402 payments.
- •The foundation has released the specification, GitHub repository, wallet pairing tools and a reference plugin for agent frameworks.

Algorand Foundation has launched AC2, an open protocol designed to let AI agents request sensitive actions without holding a user’s private keys or API credentials. The project, formally called the Agentic Communication and Control Protocol, went live on August 25 and is available as an open-source specification and reference implementation.
Algorand’s argument is simple. Giving an AI agent your credentials is like giving a contractor a copy of your house key: convenient until it ends up somewhere it should not. AC2 is intended to work more like a doorbell. The agent asks for access, the user approves on their own device, and the key never leaves the owner’s control.
Why the protocol exists
As AI agents begin to send payments, sign code, authorize APIs and manage digital operations, many existing chat-based approval flows provide little cryptographic proof of intent. Credentials are often stored inside the agent’s runtime, which creates a theft risk if that environment is compromised.
LATEST: 🤖 The Algorand Foundation launched AC2, an open protocol letting users approve individual AI agent signing requests, like payments or code commits, without exposing their private keys. pic.twitter.com/8KcdkG23xJ — CoinMarketCap (@CoinMarketCap) August 25, 2026
LATEST: 🤖 The Algorand Foundation launched AC2, an open protocol letting users approve individual AI agent signing requests, like payments or code commits, without exposing their private keys. pic.twitter.com/8KcdkG23xJ
AC2 is designed to close those gaps. When an agent needs to perform a signing operation, it sends a request to the user over a direct, end-to-end encrypted connection. The user reviews the action in a wallet or app and approves it with a hardware-bound FIDO2 passkey signature. The agent receives authorized proof of intent, not the credential itself.
How AC2 works
The protocol combines three open standards: DIDComm v2.0 for message formatting, WebAuthn/FIDO2 for phishing-resistant authentication, and WebRTC DataChannels for peer-to-peer transport after the initial handshake.
Handing your AI agent your credentials is like giving a contractor a copy of your house key. Convenient, until it ends up somewhere it shouldn't. AC2, the Agentic Communication and Control protocol, works more like a doorbell. The agent asks, you let it in, and nobody holds… pic.twitter.com/ikTC3gqw4F — Algorand (@Algorand) August 25, 2026
Handing your AI agent your credentials is like giving a contractor a copy of your house key. Convenient, until it ends up somewhere it shouldn't. AC2, the Agentic Communication and Control protocol, works more like a doorbell. The agent asks, you let it in, and nobody holds… pic.twitter.com/ikTC3gqw4F
AC2 does not require a central message relay and does not need a blockchain to operate, although it can support on-chain use cases such as x402 payments. Algorand said a basic implementation can be added through a plugin rather than a full stack rewrite. That could make the protocol easier to test in existing agent tools, where developers often want tighter approvals without rebuilding their entire workflow. Potential uses include approving payments, signing git commits, authorizing API access and setting bounded delegation so agents can act only within signed limits.
What comes next
The specification and GitHub repository are now live, along with wallet pairing tools and a reference plugin for agent frameworks. Foundation executives have framed AC2 as an attempt to give agents enough authority to be useful without giving them the authority to act against a user’s interests.
For developers building agentic commerce and automation tools, the launch adds a new option for human-in-the-loop control that emphasizes credential isolation and verifiable intent. Its practical value will depend on whether agent platforms and wallet apps can support the extra approval step without disrupting existing automation flows.
Discover DailyCoin’s hottest crypto scoops right now: Franklin Templeton Brings Tokenized US Treasuries to Asia via HashKey Grayscale Zcash ETF (ZCSH) Set for NYSE Arca as ZEC Hits 8-Year High
Get the biggest crypto stories, price insights, and DailyCoin exclusives in your inbox.