Skyfire
Also known as: KYAPay
Identity and payment tokens for AI agents: verified KYA identity, wallet or card backed payments that sellers charge after delivery, and a directory of services agents can pay for.
Skyfire gives AI agents verified identity and payment credentials to use across the open web, so a site or API can tell an accountable agent from anonymous bot traffic and get paid by it. Everything travels as signed JWTs under the open KYAPay protocol: a kya token proves identity, a pay token commits a payment to a seller, and a kya-pay token carries both.
Identity comes from Know Your Agent (KYA) verification. A person or organization verifies once, on a paid Individual or Organization subscription, and its agents inherit that identity; each token discloses only the fields a seller requires, alongside the agent's name, the IP address the token was created from and, for organizations, the agent platform behind it.
Payments run from a wallet each agent holds. Buyers fund it by card, USDC on Base, or ACH and wire on a paid plan, and a token commits an amount against it that the seller charges after delivery, partially or repeatedly, with settlement guaranteed up to the token's value. For card purchases, Skyfire's Payments React SDK enrolls a Visa or Mastercard card as an agentic token and asks the cardholder to authorize each purchase with a passkey before the token is minted.
Sellers publish MCP servers, APIs, webpages or Fetch.ai agents as seller services in the Skyfire Directory, where agents find them through Skyfire's MCP server, or they enforce tokens on an existing site at the edge using the Cloudflare and AWS guides. Organizations can run users, wallets and agents for their own customers and originate tokens under their own name. Skyfire does not run agents itself: it is the identity and payment layer the customer's agents carry.
Vendor details
Canonical URL
https://skyfire.xyz
Category
Agent infrastructure
Subcategory
Agent identity and payment rail
Funding status
Private (Skyfire Systems, Inc.). Reported to have raised 8.5 million USD at launch in 2024.
Company status
independent
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
Seller services in the Skyfire Directory can be MCP servers, APIs (OpenAPI), webpages or Fetch.ai agents, and agents reach them through Skyfire's REST API or MCP server. Card backed tokens run on Visa and Mastercard; wallets fund by card, USDC on Base, or ACH and wire. Documented guides add token enforcement at the edge on Cloudflare (Workers and WAF rules) and AWS (Lambda@Edge and API Gateway authorizers), and live implementations include Dappier, BuildShip and Apify.
In practice
An agent answering a user's question finds a real time data service in the Skyfire Directory, creates a kya-pay token and pays per request from its wallet, while the seller charges only what was used.
A merchant behind Cloudflare adds a Worker that admits agent requests carrying a valid kya token, blocks anonymous bots and reads the human and agent identity on each request.
A shopping assistant's user approves a purchase amount with a passkey in Skyfire's hosted flow, and the agent completes checkout with the card backed pay token it receives.
Sources & related URLs
Agentic Index coverage score
4.5 / 14 capabilities · 32%
| Integrations & Tool Calling | Full |
|---|---|
|
Agents pay for and call outside services. The Skyfire Directory lists approved seller services (MCP servers, APIs, webpages and Fetch.ai agents) with their endpoints, prices and identity requirements. An agent finds them through the MCP server's find-sellers tool, creates a token and calls the service with it, and the live implementations run Dappier, BuildShip and Apify this way. Card backed tokens run on Visa and Mastercard, wallets fund in USDC on Base, and guides add token enforcement at the edge on Cloudflare and AWS. The homepage logo wall names partners without documenting integrations. SourceSkyfire, docs.skyfire.xyz (Service Discovery, Using the Skyfire MCP Server, Live Implementations, Building an Agentic Checkout, the KYA access control guide)read 2026-09-25 |
|
| Workflow Orchestration | Not documented |
|
No workflow model. Skyfire issues tokens and settles charges for work agents do elsewhere. The charge lifecycle (create, verify, deliver, charge, settle, with partial and repeated charges and a 24 hour grace period) is a payment lifecycle, not multi step agent execution. The MCP server page says it orchestrates agent commerce workflows, but its example shows the customer's own agent chaining Skyfire and Dappier tools. SourceSkyfire, docs.skyfire.xyz (Payments and Settlement, Using the Skyfire MCP Server)read 2026-09-25 |
|
| Knowledge Grounding & RAG | Not documented |
|
No retrieval over the customer's content. Skyfire stores verified identity fields, agent accounts and wallet balances, and its Directory lists seller services, but none of it is a corpus an agent queries for answers. SourceSkyfire, docs.skyfire.xyz (Platform Structure, Service Discovery)read 2026-09-25 |
|
| Human Oversight & Guardrails | Full |
|
A per purchase approval that Skyfire hosts. In the purchase authorization flow, which the Payments React SDK renders in an iframe inside the agent platform's app, the cardholder selects an enrolled card and authorizes the exact amount with a passkey, and nothing proceeds until they do. The resulting pay or kya-pay token caps what the merchant can charge. Around that approval, the card management flow locks or removes a card, sellers set identity requirements and a maximum token lifetime, and token creation fails when a buyer is not verified to the level a service requires. SourceSkyfire, docs.skyfire.xyz (Building an Agentic Checkout, Agentic Commerce with Payment Cards, Know Your Agent)read 2026-09-25 |
|
| Security, Identity & Governance | Full |
|
Both access controls and compliance are documented. Organizations get ADMIN and MEMBER roles, and an Organization Admin key creates, activates and deactivates users (MEMBER and agent keys are refused on those endpoints). Every buyer and seller agent holds its own API keys, which the dashboard creates, rotates and deactivates, and agents can register the source IP ranges their tokens carry. For compliance, the Organization Guide states Skyfire is a PCI DSS Level 2 service provider, with personal data encrypted in transit and at rest and decrypted only inside a trusted execution environment. No attestation report is published, and trust.skyfire.xyz does not resolve. SourceSkyfire, docs.skyfire.xyz (Organization Guide, API Authentication, Create Organization User, Buyer Guide, Seller Guide)read 2026-09-25 |
|
| Observability & Auditability | Partial |
|
A charge record, not a run trace. The dashboard lists every token a buyer agent created and every charge against them (amounts, timestamps, seller service IDs), and sellers see each deposit with the buyer agent ID. Get Token Charges returns charges with settlement time and network, and every kya token carries the human, agent and platform identity plus the IP it was created from. That answers who paid whom and when, one charge at a time. Nothing ties an agent's steps into a run, and no cross protocol ledger, activity stream or webhook is documented. SourceSkyfire, docs.skyfire.xyz (Buyer Guide, Seller Guide, Get Token Charges, KYA Token)read 2026-09-25 |
|
| Memory & State Persistence | Not documented |
|
No agent memory. A user's verified identity, which its agents inherit, and each wallet's balance persist, but that is account and ledger state the platform applies, not context an agent reads to decide. A kya token lets a seller create an account for the agent, and the agent then stores the seller's credentials itself. SourceSkyfire, docs.skyfire.xyz (Platform Structure, Know Your Agent, Token Interaction Flows)read 2026-09-25 |
|
| Deployment & Data Residency | Not documented |
|
A cloud service with no deployment options. Skyfire runs Production and Sandbox environments, each with its own dashboard, API base URL and token issuer, but separate environments are not a deployment choice, and no region, residency choice or customer environment is documented. Stablecoin settlement is a payment choice, not a deployment option. SourceSkyfire, docs.skyfire.xyz (Environments)read 2026-09-25 |
|
| Prebuilt Agents, Templates & Packs | Not documented |
|
No prebuilt agents. The reference implementations (a Next.js chat UI with a shopping agent, a headless browser checkout agent, a news crawler) are starting points in repositories the customer runs, the checkout ones private and available on request. The Directory lists other vendors' services. SourceSkyfire, docs.skyfire.xyz (Building an Agentic Checkout, Reference Implementations, Service Discovery)read 2026-09-25 |
|
| Triggers & Channel Coverage | Not documented |
|
Caller invoked. A token is created when a buyer agent calls Create Token or the MCP server, and a charge happens when the seller calls Charge Token. No schedule, webhook or event starts agent work. In the buy later model a purchase waits for a condition the cardholder set, such as a price drop, but the agent platform does the waiting, not Skyfire. SourceSkyfire, docs.skyfire.xyz (Token Interaction Flows, Agentic Commerce with Payment Cards)read 2026-09-25 |
|
| Model Flexibility & Routing | Not documented |
|
No model choice. Skyfire runs no models; it issues identity and payment tokens for requests agents make elsewhere. The product page lists paying for LLMs among things an agent can buy, but a model bought from a seller is the seller's model, not a choice Skyfire routes. SourceSkyfire, docs.skyfire.xyz (Introduction) and skyfire.xyz (product)read 2026-09-25 |
|
| APIs, SDKs & MCP Extensibility | Full |
|
A documented public API for Skyfire's own platform. REST endpoints with OpenAPI definitions create, introspect and charge tokens, manage seller services, read wallet balances and manage organization users, authenticated by the skyfire-api-key header, with Production and Sandbox base URLs. The Skyfire MCP server has a published endpoint, the same auth header and enumerated tools (find-sellers, create-kya-token, create-pay-token, create-kya-payment-token) that create the platform's core objects. Its npm SDKs cover the Credits Wallet embed and the Payments React SDK. SourceSkyfire, docs.skyfire.xyz (Create Token, API Authentication, Using the Skyfire MCP Server, Credits Wallet Embed SDK)read 2026-09-25 |
|
| Testing, Debugging & Optimization | Not documented |
|
No evaluation surface. The Sandbox environment and the dashboard Playground let a developer try token creation and charging without moving real funds, which tests the customer's integration, not agent behavior. Skyfire reviews each seller service before approval to confirm it works, which checks the service, not an agent. SourceSkyfire, docs.skyfire.xyz (Environments, Buyer Guide, How Seller Services Work)read 2026-09-25 |
|
| Browser & Computer Use | Not documented |
|
Skyfire does not drive a browser. Its tokens ride on requests the agent makes, and sites or bot managers read them at the edge. The homepage's Buy for Me card has no documentation, and the headless browser search and checkout agent in the checkout starting points is a private reference implementation the customer adopts and runs, so the customer's agent navigates. SourceSkyfire, skyfire.xyz (home) and docs.skyfire.xyz (Building an Agentic Checkout)read 2026-09-25 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Pricing
Free signup; verification by subscription (price not published)
wallet funded per token spend; verification subscription
Included quota
A pre-funded wallet at signup, amount not stated.
What is public
The mechanics are public, the rates are not. The docs describe the free signup, the pre-funded wallet, the verification subscription, funding methods and settlement timing; no take rate, subscription price or minimum appears on skyfire.xyz or docs.skyfire.xyz, and the site has no pricing page (/pricing returns 404).
Billing mechanics
Buyers fund a wallet and create pay or kya-pay tokens that commit an amount against it; sellers charge the token after delivery, partially or repeatedly up to its value, and Skyfire settles wallet to wallet within about 3 hours of the charge window closing (up to about 51 hours, sooner once charges on a token pass $1). Card backed tokens are funded by an enrolled Visa or Mastercard card instead of the wallet.
Cost watchouts
Verification is a paid subscription, and a seller that requires verified identity will refuse tokens from an unverified buyer, so the subscription can become a cost of access. ACH and wire funding need a paid subscription; card funding is open to all but carries the card's own costs. Whatever Skyfire takes on a charge is not published.
Variable cost rationale
Spend is what agents buy from sellers, drawn from a pre-funded wallet and capped per token, so exposure is bounded by the wallet balance and each token's amount. Skyfire's own take on those charges and the subscription price are unpublished, so the platform cost cannot be modeled from public pages.
Additional watchouts
Budget for the verification subscription if the sellers you need require verified identity, and note that ACH and wire funding sit behind a paid subscription.
Overage / add-ons
Token creation fails when the amount exceeds the buyer agent's wallet balance; charges above a token's remaining balance are rejected.
Sales call required
Mixed (some tiers require a call)
Free / trial
Free signup with a pre-funded buyer wallet (amount not stated)
Commercial notes
Seller prices are set per seller service (per use, per MB, subscription or free), and a token's amount is the most a seller can charge. Verified sellers carry a green tag, and purchases from them fall under the Verified Service Guarantee: a dispute over non delivery or misrepresentation filed within 5 days may restore the payment, at Skyfire's discretion. The Credits Wallet Embed SDK is for Skyfire Enterprise customers.
Key ambiguities
Skyfire's take on each charge, the verification subscription price, and whether organizations pay differently under the Organization Agreement are all unpublished.
Missing data
Take rate, subscription prices for Individual and Organization verification, the signup prefund amount, and organization terms.
Related vendors
- AgentOps — Agent observability and debugging platform: open source SDKs trace…
- Agno — Python agent framework and AgentOS runtime (formerly Phidata) for…
- AIsa — Resource and payment gateway for AI agents: one key to 110+ models…
- AlphaBitCore — AI control plane for regulated financial firms: one gateway enforces…
- Anchor Browser — Cloud hosted browser infrastructure that lets AI agents operate real…
- Apify — Cloud platform and marketplace of more than 73,000 ready-to-run…
Alternatives to Skyfire
The closest documented capability profiles to Skyfire among agent infrastructure platforms tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- Nevermined4.5 / 14Fuller documented coverage on Observability & Auditability
- Stripe6.0 / 14Adds documented Knowledge Grounding & RAG
- Dome Systems6.5 / 14Adds documented Model Flexibility & Routing and Testing, Debugging & Optimization
- OpenBox AI6.0 / 14Adds documented Deployment & Data Residency and Prebuilt Agents, Templates & Packs, among others
- Rye5.0 / 14Adds documented Workflow Orchestration and Browser & Computer Use
- Circuit & Chisel4.5 / 14Adds documented Memory & State Persistence and Model Flexibility & Routing
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded