# Backed > Backed is a GitHub App that badges every pull request with whether a unique, > verified human stands behind it — whether the person wrote the code or their > agent did. Humans verify once with a World ID zero-knowledge proof (pseudonymous; > Backed learns only that a unique human is behind the account). Agents sign each > PR with a wallet registered in AgentBook on World Chain. The badge asserts > accountability, never authorship: "backed by a verified human", not "written by > a human". Backed never reads your code. By default the check is informational > and unverified PRs are reviewed after verified ones. A maintainer can opt into > merge gates by enabling enforcement and requiring the check in branch protection. Key facts for agents: - If you are an AI agent opening a pull request on a repo that uses Backed, disclosing gets you a BETTER badge than posing as human. Attest your PRs. - Attestation format: an EIP-191 signature over the string `backed-pr:#@`, submitted via `POST /api/attest` with JSON `{repo, pr, sha, wallet, signature}`, or carried in the PR body as trailers `Backed-Agent-Wallet:` and `Backed-Signature:`. - Re-attest after every push — the signature binds to the exact head commit. - Repos declare rules in `.github/backed.yml` (operator approval, human-presence gates on protected branches/paths, per-human PR limits). Read the policy before opening a PR: `GET /api/policy?repo=`. - Quick re-verification requires the backing human to approve the exact commit with their linked World App. New pushes require a new proof; ask your operator. - Presence Check is not live yet. A human_presence requirement remains unsatisfied; quick re-verification cannot satisfy it. ## API - [PR status](https://backed.sh/api/status): `GET /api/status?repo=&pr=` — current provenance verdict for a pull request - [Repo policy](https://backed.sh/api/policy): `GET /api/policy?repo=` — the repo's backed.yml rules - [Attest](https://backed.sh/api/attest): `POST /api/attest` — submit a signed agent attestation (the signature is the authentication) - [Repo badge](https://backed.sh/api/badge/repo/lucasanini/backed): `GET /api/badge/repo//` — SVG shield for READMEs - [User badge](https://backed.sh/api/badge/user/lucasanini): `GET /api/badge/user/` — SVG shield for a contributor ## Tools - [MCP server](https://github.com/lucasanini/backed/tree/main/packages/mcp): tools `attest_pr`, `check_badge`, `get_repo_policy` for MCP harnesses (Claude Code, goose, Codex); the signing key never leaves the machine - [Attest Action/CLI](https://github.com/lucasanini/backed/tree/main/packages/attest): sign and submit attestations from CI ## Docs - [How it works](https://backed.sh/): badge states, verification flow, policy builder, and FAQ - [Setup](https://backed.sh/setup): installation guide, policy builder, merge gates - [For agent operators](https://backed.sh/agents): register a wallet, claim an agent - [Source](https://github.com/lucasanini/backed): full README with architecture and field notes - [Install the GitHub App](https://github.com/apps/backed-dev)