Cryptographic authorization for AI agents. Scoped delegation, checkpoint escalation, Ed25519 signed receipts. Block prompt injection at the tool boundary.