Start by signing a local demo configuration and testing what happens when it changes. Then choose the guide for the boundary you need to enforce.
The first-manifest example supplies the record, keys, and approved inputs used by several follow-up guides. Those pages say where to append their code. Hardware and cMCP integration guidance identifies additional setup and verification requirements.
| Tutorial |
What you'll build |
| Your first manifest |
A signed Agent Manifest from scratch with Ed25519 key generation and CLI verification |
| CI/CD signing |
Signing and verification scripts, plus a workflow triggered by manifest changes on main |
| cMCP session binding |
Configuration guidance and the meaning of the gateway's identity evidence |
| Tutorial |
What you'll build |
| Run a verification service |
A local HTTP verifier with startup-loaded trust and signed revocations, plus container packaging |