Verigrant › Guide for businesses
Take orders and applications from agents
People send you sealed, structured applications through Verigrant. Their AI agents can now also drop complete orders for you to fill, people can fill your forms from their own records, and you can send updates after a booking. This page says how to start, and what is not live yet.
1. Set up your organization
- Create an organization account. Sign up as an organization and confirm your email address.
- Turn on a second factor. Every organization screen needs it.
- Create your organization. You accept the Institution Agreement here.
- Add a card. Card payments are not switched on yet, so no card is charged.
-
Register as an institution.
Name your domain, let the browser make your keys, and publish the small file it gives
you at that domain. Serve it with the header
Access-Control-Allow-Origin: *, because each person’s browser reads it before it seals anything to you. - Wait for approval. Verigrant approves each institution. The checklist in your workspace shows where you are.
If you sell rather than hire, admit, insure, lend or rent, choose Merchant as your kind of institution when you register.
2. Applications, as before
People, or their agents under an assistant code, send you sealed, structured applications. You preview the fields you asked for, and pull the full application only for the people you advance. You open it with your own private key, which Verigrant has never held. You pay for each application you take in, on the plans in the price list.
The institutions page has the whole of it, and the integration guide has the calls.
3. Orders from agents
An agent acting for a person can drop a complete order into Verigrant instead of pushing it through your checkout. You never have to let a bot into your checkout pages.
- The order arrives. It carries your offer, the total, the agent's pass, the person's payment approval, and the person's traveller details, sealed in their browser to your registered key. Verigrant checks it before it keeps it.
-
You get it.
By webhook, at an https address on your registered domain, signed with Verigrant's
published delivery key. Or you pull it with your API key:
GET https://verigrant.com/api/rp/orders, then fetch and acknowledge each order. - You open and complete it. You open the traveller details with your own private key and complete the order in your own system.
- You send a signed result. You post an outcome signed with your registered key: confirmed, pending, failed or needs approval. Verigrant refuses a confirmed or pending outcome above the most the person approved. The person keeps a sealed receipt of it.
What to know today
The payment approval inside an order runs in test mode. It is not money you can collect. Orders have no price yet and are not billed.
Order screens are not in the organization workspace yet, so orders are handled through the interface. Verigrant keeps the sealed order for ten minutes after delivery, so you can pull it again, and deletes the order a week after it arrived.
4. A door for agents
Agents can use a structured interface you publish, instead of your pages built for people. An agent carrying a person's Verigrant pass gets your grant and the sealed path, as below. An agent registered with Verigrant and carrying only its agent ID gets your grant at level one: search, compare and act in the clear. The generator drafts the front from your own site, the gate keeps your pages for people, the dashboard shows every agent that visits, and the directory is where agents find you. All four are in the guide for websites; the steps here are the pass.
-
Save Verigrant's pass key set
Keep
https://verigrant.com/api/.well-known/verigrant-pass-keys.jsonas a file and refresh it on your own schedule. You check passes against it offline, and never call Verigrant to do it. -
Publish a service file
At
/.well-known/verigrant-service.jsonon your domain, listing the operations you offer to agents. - Trade a pass for your own grant Your grant is bound to the same agent key as the pass, and you check both on every call.
- Keep your pages strict Your pages for people can refuse bots as firmly as they do today.
The library for this is vg-service-grant, in Rust. It is not on a public
registry yet. Write to support@verigrant.com to get it. A front hosted by Verigrant goes
live on its own day, so for now you run your own.
5. Fill with Verigrant
A person opens your form with Fill with Verigrant. Their device fills it from their own record and seals the answers to your key before anything is sent. Verigrant passes on ciphertext it cannot open. It keeps a row naming your business until shortly after the form is delivered.
Verigrant registers your business and the forms your domain lists before you can offer it. Write to support@verigrant.com to start.
6. Updates and messages after a booking
When a person allows it for a booking, you can send them updates about it, such as a cancellation with rebooking options.
-
See what you may update
GET https://verigrant.com/api/rp/deliver-backlists the bookings people allowed you to send updates about. - Send a sealed notice Seal the notice to the person's key, sign it, and post it to their address, naming the booking's grant. It lands in their Verigrant inbox under that booking. Verigrant sees that you sent something and when. It cannot read it.
- Give the agent something to act on If the person allows it, add a signed update sealed to the key their agent made for that booking.
- Message without an email address A masked address lets you message the person in their Verigrant inbox without learning their email. It works for you alone and for that one matter. Email and phone relays are not built.
People switch these on for each booking, and the screens for that are not in the app yet, so expect few of them at first.
7. What is not live yet
- Money moving through Verigrant Payment approvals and card payments run in test mode.
- A price for the new services Orders, Fill with Verigrant, booking updates and masked contact have no price and are not billed.
- Order screens in your workspace Use the interface for now.
- Passkeys People cannot approve a step that needs a passkey yet.
- A door hosted by Verigrant It goes live on its own day, after the registry, the directory and Connect. Until then you run your own.
- The egress Requiring that every agent request come through Verigrant's own network goes live on its own day. A front that requires it today refuses every agent.
- Health records and private compute Neither is switched on.