Issuance rulebook · early preview
Superintelligence Passport: rules of issuance
What can be issued, what is refused, and how this registry changes its own rules. Version 2026-10-04.3; each version's hash is a leaf in the transparency log. Not a certification or a legal standard.
Who can get a passport
- Any operator (an individual or an organization) that controls a P-256 signing key and registers it. Registration is self-service; there is no human review in this preview.
- Each agent needs its own Ed25519 request key and P-256 presentation key, bound to the operator by a signed statement and proofs of possession.
- Operator level L0 = key only (self-declared name); L1 = a domain whose control was proven by DNS TXT or a signed .well-known file and is re-checked daily. L2 and L3 are not implemented.
- Agent class (software | ai | si_declared) and owner type (individual | organization | unspecified) are self-declared and shown as such. The registry does not verify them.
Permanent passport identity
- A passport id is permanent. It is assigned by the registry at issuance, is never reused, never re-registered, and never deleted. Revoking or suspending a passport keeps the record and a tombstone forever; the id can never be registered again.
- A passport is bound at issuance to its owner and to the key fingerprints it was issued with, and the public registry shows the issue date, those fingerprints, a hash of the owner reference and the full append-only history.
- Non-transferable: there is no transfer, sale or re-assignment of a passport. A new owner needs a new passport.
- Non-duplicable: one agent key maps to exactly one passport, forever (retired keys stay claimed). Registering the same key again, or claiming an existing id, is refused with 409.
- Key rotation is allowed only with a signature from an active operator signing key; the passport id and the issuance record stay the same. Recovery after a lost agent key is the same operator-authorized rotation and keeps the same id.
Licenses: renewable, changeable, versioned
- Licenses are separate from the passport: they can be renewed and changed (scopes, regions, expiry, limits) by issuing a new version that supersedes the previous one in the same lineage (POST /v1/licenses with supersedes).
- Every version stays in the public history; the superseded version stops working immediately. Changing a license never changes the passport, its id or its issuance record. Revoked licenses are not renewed: issue a fresh license.
Identity is not permission. A site registers an environment, proves it controls its origin, and sets rules; an agent can act there only with a license for that exact environment (default deny).
What is refused
| code | rule |
|---|---|
binding.invalid | agent registration without a fresh operator binding statement matching both agent keys |
binding.replayed / agent.key_exists (409) | reusing a binding statement, or registering a key that already belongs to a passport (including retired keys) |
passport.id_taken / passport.id_assigned_by_registry (409) | claiming an existing passport id, or trying to choose one |
passport.non_transferable / passport.permanent (405) | transferring, selling, re-assigning or deleting a passport |
license.already_superseded / license.revoked / license.supersede_mismatch | branching a license history, renewing a revoked license, or moving a license version to another passport |
license.environment_unverified | licenses for an environment whose origin ownership was never proven (or lapsed) |
issuance.outstanding_cap_exceeded / daily_cap_exceeded | an operator issuing more spendable authority than its configured caps |
ceiling.exceeded | L0/L1 operators cannot issue a license with spend.total_max above the ceiling |
class.tier_violation | si_declared agents: no delegation, regions required, spend.total_max required and capped |
license.missing / region.outside_license / region.unknown | at verification: no license, or the environment's region is outside the license's regions |
operator.suspended / agent.frozen / agent.revoked | kill switch and revocation take effect immediately |
Agent class tiers (illustrative defaults)
| class | cumulative approval above | max license total | delegation | regions required |
|---|---|---|---|---|
| software | 100.00 | tier default | allowed | no |
| ai | 100.00 | tier default | allowed | no |
| si_declared | 25.00 | 100.00 | no | yes |
Owner assurance levels
- Owner levels: L0 key only (self-declared name); L1 a domain whose control was proven and is re-checked daily; L2 an identity check by an allow-listed provider, delivered as a provider-signed attestation; L3 = L2 plus a passkey registered with user verification (an in-person/notary attestation can be recorded, and is shown, but is optional).
- Only the level, the provider id, the attestation kind, the expiry and sha256(receipt) are stored. ID documents, selfies and biometrics are never stored by this registry; biometric checks, where used, stay on the user's device (passkeys) or with the provider.
- A license may require a minimum owner level (license.min_owner_level); an environment profile may too (min_operator_level). Below it, verification is denied.
- The only provider enabled by default is none. A clearly labelled TEST STAND-IN exists for demos and tests and is shown as such; no real identity provider is connected in this preview.
Owner presence (passkeys)
- If an owner registers a passkey, these need a fresh single-use owner-presence token (passkey assertion with user verification, bound to the exact action): agent key rotation and recovery, owner key rotation, un-freezing a passport, adding or removing passkeys, and any approval for a license that sets approval.require_presence.
- Passkeys are an assurance level, not proof of uniqueness: synced passkeys are copyable by design, attestation is not validated in this preview, so assurance is a hint.
Transparency log
- Issuance, license versions, revocations, key and owner-level changes and the rulebook hash are leaves in an append-only Merkle log (RFC 6962/9162 hashing) with signed checkpoints, inclusion and consistency proofs (GET /log/checkpoint, /log/proof/*, /registry/:id/proof-pack, scripts/log-verify.mjs).
- The log is verifiable but NOT independently witnessed: no outside party cosigns checkpoints yet, so the operator of this registry could still serve a split view to different people until witnesses exist.
Token status list
Revocation is also published as an IETF Token Status List (application/statuslist+jwt, 2-bit entries, random indices, experimental draft) at /v1/status/agents and /v1/status/licenses; agents can staple a short-lived status token from /v1/status-token/:id.
Capability tiers & evidence
Tier labels describe declared class plus evidence. Evidence kinds: model_card, eval_report (signature-checked), frontier_framework, slsa_provenance, oms_signature, c2pa_manifest, iso42001_ref, aiuc1_ref. The registry stores hashes, signers and URLs; it does not judge truth or safety. Higher limits for si_declared need evidence; T-SI is reserved and never automatic.
| SI-declared evidence level | cumulative approval above | max license total |
|---|---|---|
| 0 | 25.00 | 100.00 |
| 2 | 50.00 | 500.00 |
| 3 | 100.00 | 1000.00 |
Regions
ISO 3166-1 alpha-2, the group EU (27 members), or *. license.regions must contain the environment's region (profile.region) or, if the environment declares none, the request's country; unknown means deny.
What this page does not claim
- This registry is not certified, audited or approved by any authority, and does not claim legal or regulatory compliance.
- It is not the authority for agent identity: it is one registry whose rules are stated on this page.
- Self-declared fields are not verified. A passport is not a statement about any person or about the safety of an agent.