EARLY PREVIEWa prototype: not certified, not an audit, not an official or authoritative registry. Demo data is throwaway.

Owner assurance

How much do we know about the owner?

Every passport names an accountable owner. The level says how much was checked, and the registry limits what the agent can do accordingly. It never says the owner is "good".

L0

Key only

A key and an operator record. Nothing about the owner is checked. Shown as unverified.

L1

Domain proven

The owner proved control of a domain (DNS challenge). Says nothing about who they are.

L2

Identity checked

An allow-listed identity provider checked the owner and returned a receipt. We keep the level and a receipt hash; no documents, no biometrics.

L3

Identity + passkey

L2 plus a passkey (WebAuthn) assertion with user verification, checked by the registry. Shows a person with a device was present.

What is stored

Level, provider name, a receipt hash and an expiry. Not stored: documents, selfies, face or fingerprint data, or raw biometric templates. Passkeys store a public key and a counter only.

Test identity providers are labelled as test stand-ins wherever they appear. Level is a signal for relying parties, not a guarantee.