Skip to content

Latest commit

 

History

5 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

ATOP Agent Skill

A portable agent skill for exercising the Trusona Account Takeover Protect (ATOP) identity-verification APIs in real agentic workflows. It ships runnable bash scripts so an agent can use the API — create and poll verifications, run DMV/MNO driver-license ID matches, and pull documents and risk scores — instead of only reading docs.

Covers:

  • Verification API — v2.2.0
  • Driver License Verification API — v1.0.0

Both at https://authcloud.trusona.net. Pinned spec copies live in openapi/.

Install

It's a Claude Skill but the body is plain Markdown + bash, so any agent that can read files and run shell commands can use it.

Claude Code — clone into your skills directory:

git clone https://github.com/trusona/atop-agent-skill.git ~/.claude/skills/atop-api

Claude auto-discovers it via SKILL.md. Invoke with /atop-api or just describe an ATOP task.

Other agents — clone anywhere and point the agent at SKILL.md as its entry point; it routes to reference/ and scripts/.

Setup

export ATOP_TOKEN='eyJ...'                              # Bearer JWT (Trusona dashboard)
export ATOP_BASE_URL='https://authcloud.trusona.net'   # optional; this is the default

Requirements: bash, curl, jq. The token is read only into the Authorization header and is never written to disk. See reference/auth.md.

Run local validation before using a live token:

scripts/doctor.sh

Quickstart

# 0. Confirm auth works (lists verifications since a date)
source scripts/_lib.sh && atop_require_env
atop_curl GET "/api/v1/verifications?since=2024-01-01T00:00:00Z" | jq 'length'

# 1. Create a verification, then poll it to resolution
scripts/create-verification.sh examples/verification-request.json
scripts/poll-verification.sh <id-from-previous-step>
scripts/get-results.sh <id> --all
scripts/list-verifications.sh --since 2026-06-01 --count 25

# 2. Or run a DMV/MNO driver-license ID match
scripts/id-verify.sh examples/id-verification-request.json
scripts/poll-id-verification.sh <id-from-previous-step>

For event-driven workflows, set callbackUrl on the create request and use the callback as a signal to re-fetch authenticated results; see reference/webhooks.md.

Every script supports --help. Start from SKILL.md for the full intent → script map.

Layout

SKILL.md            Agent entry point (when-to-use + intent→script table)
reference/          Per-API docs derived from the specs
scripts/            Runnable bash workflows (_lib.sh is shared)
examples/           Editable request bodies
openapi/            Pinned spec copies + FETCHED.md

Keeping it accurate

Scripts and reference docs are derived from the vendored specs. To refresh after an API change:

  1. Re-fetch the upstream specs into openapi/ (URLs in openapi/FETCHED.md).
  2. git diff the specs to spot changed endpoints, enums, or required fields.
  3. Update the affected reference/*.md, scripts, and examples; bump the versions and date in FETCHED.md.

Publishing to Trusona GitHub

This repo is prepared for the Trusona org. To publish:

git remote add origin git@github.com:trusona/atop-agent-skill.git
git push -u origin main

(Adjust the org/repo name to your convention.)

License

Copyright 2026 Trusona, Inc. Licensed under the Apache License, Version 2.0. See LICENSE.

About

No description, website, or topics provided.

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages