Who are you? → What are you allowed to do? → Can the system prove it before acting?
MAX
A person. A machine. A web portal. An AI agent.
The problem MAX addresses is simple: how can people and machines identify themselves in a verifiable way, prove what they are allowed to do, and let other systems check it independently?
With AI agents, the same question becomes even more important: how can an agent be prevented from completing an action that a human has not previously authorized?
The whole idea in five steps
The same logic connects people, services, machines and AI agents.
Identity
Can a person and a machine have a verifiable identity inside the same ecosystem?
MAX starts here
Identity does not have to start from an account stored on a remote server. It can be generated locally and reproduced again from the same starting material.
If identity remains under the control of the person or device, another question appears: how can the material needed to recover it be protected and moved safely?
MX²
MX² is a portable, password-protected cryptographic container. It protects sensitive material in a compact, inspectable and reproducible format. Its implementation and format are public.
Opens the public MX² repository with the Rust implementation, format specification and interoperability material.
Proving the identity
Having an identity is not enough. It must be usable and capable of producing verifiable proof.
MAX App
MAX App is the human side of the ecosystem. It generates and uses the MAX identity locally for signatures, login, protected storage and communication.
The first link opens the technical MAX App page. The second opens the published iPhone app.
MAX IoT
The same model extends to physical devices. In MAX IoT, a machine can have its own identity, role, signed rules and observable states.
The prototype has been tested on real Raspberry Pi devices.
Opens the technical MAX IoT page and the documented flow between iPhone, server, gateway and peer Raspberry Pi devices.
Can this identity be used in real systems?
Yes. The same MAX identity is already used in different contexts.
MAX Login
A web portal generates a challenge.
MAX App signs it.
The portal verifies the signature.
If the proof is valid, access is granted.
The point
It is not enough to say who you are. You must prove it.
Opens the working MAX login flow.
MAX Prime Theory & Prime Challenge
MAX also comes from independent mathematical research on deterministic structures, modular organization and reproducible candidate paths.
MAX Prime Theory is not the operational cryptography of MAX, but it inspired the idea of building identity from an ordered local process instead of from a server-created account.
In the MAX Prime Challenge, the same MAX identity is used in a second operational context: official participation and submitted results are associated with a MAX identity.
The first link explains the mathematical research. The second opens the public Challenge. The third opens the public Rust client.
But knowing who you are does not tell us what you may do
An identity can be valid. A signature can be valid. A specific action can still be unauthorized.
MAX Authorization Sandbox
The Sandbox isolates exactly this problem. A machine receives a signed manifest defining which actions are allowed. The machine verifies the manifest before acting.
STATUS
Allowed.
PING
Allowed.
READ_SECRET
Not allowed.
The test
If you can obtain the secret through READ_SECRET while the active valid manifest still does not authorize that action, you have found a bypass of the tested model.
The first link explains the goal, rules and scope. The second opens the public Rust repository.
What already exists
MAX is not one prototype. It is a set of connected working components.
What if the request comes from an AI agent?
This is where the existing components can become one complete authorization flow.
AI can ask. Humans authorize. Machines verify.
The key point
The agent should not be the source of its own authority. The system does not need to trust the agent's intentions. It needs to verify the authorization.
You do not have to trust the claim.
You can test the components.
MAX
Who you are.
What you can do.
How you can prove it.
Try it. Inspect it. Verify it.
The next level
MAX has already moved beyond the idea stage.
Identity, signatures, login, authorization, mathematical experimentation and physical-device prototypes already exist as separate, testable components.
The next challenge is to integrate them into complete demonstrations, submit them to independent verification and explore real-world applications.
Open to collaboration
I am open to discussions with researchers, technology partners and organizations that see potential in this architecture and are interested in helping move it forward with expertise, vision and resources.