A portable agent skill for exercising the Trusona Account Takeover Protect (ATOP)
identity-verification APIs in real agentic workflows. It ships runnable bash
scripts so an agent can use the API — create and poll verifications, run
DMV/MNO driver-license ID matches, and pull documents and risk scores — instead
of only reading docs.
Covers:
- Verification API — v2.2.0
- Driver License Verification API — v1.0.0
Both at https://authcloud.trusona.net. Pinned spec copies live in openapi/.
It's a Claude Skill but the body is plain Markdown + bash, so any agent that can read files and run shell commands can use it.
Claude Code — clone into your skills directory:
git clone https://github.com/trusona/atop-agent-skill.git ~/.claude/skills/atop-apiClaude auto-discovers it via SKILL.md. Invoke with /atop-api or just describe
an ATOP task.
Other agents — clone anywhere and point the agent at SKILL.md as its entry
point; it routes to reference/ and scripts/.
export ATOP_TOKEN='eyJ...' # Bearer JWT (Trusona dashboard)
export ATOP_BASE_URL='https://authcloud.trusona.net' # optional; this is the defaultRequirements: bash, curl, jq. The token is read only into the
Authorization header and is never written to disk. See reference/auth.md.
Run local validation before using a live token:
scripts/doctor.sh# 0. Confirm auth works (lists verifications since a date)
source scripts/_lib.sh && atop_require_env
atop_curl GET "/api/v1/verifications?since=2024-01-01T00:00:00Z" | jq 'length'
# 1. Create a verification, then poll it to resolution
scripts/create-verification.sh examples/verification-request.json
scripts/poll-verification.sh <id-from-previous-step>
scripts/get-results.sh <id> --all
scripts/list-verifications.sh --since 2026-06-01 --count 25
# 2. Or run a DMV/MNO driver-license ID match
scripts/id-verify.sh examples/id-verification-request.json
scripts/poll-id-verification.sh <id-from-previous-step>For event-driven workflows, set callbackUrl on the create request and use the
callback as a signal to re-fetch authenticated results; see
reference/webhooks.md.
Every script supports --help. Start from SKILL.md for the full
intent → script map.
SKILL.md Agent entry point (when-to-use + intent→script table)
reference/ Per-API docs derived from the specs
scripts/ Runnable bash workflows (_lib.sh is shared)
examples/ Editable request bodies
openapi/ Pinned spec copies + FETCHED.md
Scripts and reference docs are derived from the vendored specs. To refresh after an API change:
- Re-fetch the upstream specs into
openapi/(URLs inopenapi/FETCHED.md). git diffthe specs to spot changed endpoints, enums, or required fields.- Update the affected
reference/*.md, scripts, and examples; bump the versions and date inFETCHED.md.
This repo is prepared for the Trusona org. To publish:
git remote add origin git@github.com:trusona/atop-agent-skill.git
git push -u origin main(Adjust the org/repo name to your convention.)
Copyright 2026 Trusona, Inc. Licensed under the Apache License, Version 2.0. See LICENSE.