Skyfire KYAPay
DataDome integrates with Skyfire as an identity trust authority for AI agent traffic. Through this integration, DataDome can verify the identity and source of AI agents that send requests to your protected resources.
How Skyfire identifies AI agents
Skyfire uses the KYA (Know Your Agent) framework to establish the identity of an AI agent. Skyfire extends this framework through KYAPay, which adds transaction and payment information to the agent identity context.
For more information, see the KYAPay framework.
As part of this process, Skyfire provides AI agents with cryptographically signed tokens. These tokens contain information about the agent's identity and source. DataDome uses the token to associate incoming traffic with the corresponding AI agent and to determine whether the token can be trusted.
Verification behavior
DataDome handles Skyfire tokens differently depending on whether the Skyfire integration is activated in your workspace.
Skyfire deactivated
When the Skyfire partner is deactivated, DataDome can parse the KYAPay token, but does not verify its cryptographic signature.
Traffic containing a parsed but unverified Skyfire token is associated with the following AI agent model:
Skyfire KYA Unverified Agent
This traffic is blocked because DataDome cannot cryptographically confirm the identity asserted by the token.
Skyfire activated
When the Skyfire partner is activated, DataDome cryptographically verifies each Skyfire token.
If verification succeeds, the traffic is associated with the following AI agent model:
Skyfire KYA Verified Agent
By default, this model uses the intent-based response policy. This policy is designed to only block fraudulent or abusive activity while allowing legitimate AI agent traffic to proceed.
You can adapt this behavior to your requirements from Agentic Trust > Access Control. For example, you can change the response policy or apply different policies based on the AI agent, traffic context, or detection model.
Verification is required for trusted identityActivating the Skyfire integration enables DataDome to verify the cryptographic signature of Skyfire tokens. Without verification, DataDome cannot confirm that the token was issued by a trusted authority or that it reliably represents the identified AI agent.
Traffic information and observability
DataDome records the Skyfire identity information and verification result with the associated traffic. You can use these fields to investigate requests, create filters, and analyze traffic from specific AI agents or trust authorities.
| Field | Description |
|---|---|
trustauthorityagentid | The unique identifier of the AI agent provided by the trust authority. |
trustauthorityagentName | The name of the AI agent provided by the trust authority. |
trustauthority | The trust authority associated with the AI agent, such as Skyfire. |
trustauthorityverificationstatus | The result of the cryptographic signature verification process. |
You can also analyze traffic by grouping it by trust authority agent ID or agent name in Agentic Trust > Explore.
Before you begin
To use Skyfire identity verification:
- Activate Skyfire from Agentic Trust > Partners.
- Configure the relevant AI agent policies in Agentic Trust > Access Control.
- Use Agentic Trust > Explore to review verified agent traffic and analyze the associated identity and verification fields.
After activation, DataDome continues to perform its standard traffic analysis. Skyfire provides the agent identity and signature, while DataDome verifies the token, classifies the traffic, and applies the response policy configured for the matching AI agent model.
Updated about 4 hours ago

