{"version":"2026-10-04.3","notice":"A changed rulebook is first announced as a rulebook_notice leaf in the public transparency log (/log) with an effective_after date (default notice: 14 days). Only after that date is the new version logged as the rulebook in force. Pending changes and a diff are shown at /rules/notice. The registry cannot technically hold deployed code back, so this is a published commitment you can check in the log, not an enforcement mechanism; there is no emergency path in this preview.","status":"early preview","disclaimer":"EARLY PREVIEW. A prototype under development: not certified, not an audit, not legal or regulatory compliance, and not an official or authoritative registry. Data on the public demo is throwaway.","who_can_get_a_passport":["Any operator (an individual or an organization) that controls a P-256 signing key and registers it. Registration is self-service; there is no human review in this preview.","Each agent needs its own Ed25519 request key and P-256 presentation key, bound to the operator by a signed statement and proofs of possession.","Operator level L0 = key only (self-declared name); L1 = a domain whose control was proven by DNS TXT or a signed .well-known file and is re-checked daily. L2 and L3 are not implemented.","Agent class (software | ai | si_declared) and owner type (individual | organization | unspecified) are self-declared and shown as such. The registry does not verify them."],"permanent_identity":["A passport id is permanent. It is assigned by the registry at issuance, is never reused, never re-registered, and never deleted. Revoking or suspending a passport keeps the record and a tombstone forever; the id can never be registered again.","A passport is bound at issuance to its owner and to the key fingerprints it was issued with, and the public registry shows the issue date, those fingerprints, a hash of the owner reference and the full append-only history.","Non-transferable: there is no transfer, sale or re-assignment of a passport. A new owner needs a new passport.","Non-duplicable: one agent key maps to exactly one passport, forever (retired keys stay claimed). Registering the same key again, or claiming an existing id, is refused with 409.","Key rotation is allowed only with a signature from an active operator signing key; the passport id and the issuance record stay the same. Recovery after a lost agent key is the same operator-authorized rotation and keeps the same id."],"license_versions":["Licenses are separate from the passport: they can be renewed and changed (scopes, regions, expiry, limits) by issuing a new version that supersedes the previous one in the same lineage (POST /v1/licenses with supersedes).","Every version stays in the public history; the superseded version stops working immediately. Changing a license never changes the passport, its id or its issuance record. Revoked licenses are not renewed: issue a fresh license."],"owner_assurance":["Owner levels: L0 key only (self-declared name); L1 a domain whose control was proven and is re-checked daily; L2 an identity check by an allow-listed provider, delivered as a provider-signed attestation; L3 = L2 plus a passkey registered with user verification (an in-person/notary attestation can be recorded, and is shown, but is optional).","Only the level, the provider id, the attestation kind, the expiry and sha256(receipt) are stored. ID documents, selfies and biometrics are never stored by this registry; biometric checks, where used, stay on the user's device (passkeys) or with the provider.","A license may require a minimum owner level (license.min_owner_level); an environment profile may too (min_operator_level). Below it, verification is denied.","The only provider enabled by default is none. A clearly labelled TEST STAND-IN exists for demos and tests and is shown as such; no real identity provider is connected in this preview."],"owner_presence":["If an owner registers a passkey, these need a fresh single-use owner-presence token (passkey assertion with user verification, bound to the exact action): agent key rotation and recovery, owner key rotation, un-freezing a passport, adding or removing passkeys, and any approval for a license that sets approval.require_presence.","Passkeys are an assurance level, not proof of uniqueness: synced passkeys are copyable by design, attestation is not validated in this preview, so assurance is a hint."],"transparency_log":["Issuance, license versions, revocations, key and owner-level changes and the rulebook hash are leaves in an append-only Merkle log (RFC 6962/9162 hashing) with signed checkpoints, inclusion and consistency proofs (GET /log/checkpoint, /log/proof/*, /registry/:id/proof-pack, scripts/log-verify.mjs).","The log is verifiable but NOT independently witnessed: no outside party cosigns checkpoints yet, so the operator of this registry could still serve a split view to different people until witnesses exist."],"token_status":"Revocation is also published as an IETF Token Status List (application/statuslist+jwt, 2-bit entries, random indices, experimental draft) at /v1/status/agents and /v1/status/licenses; agents can staple a short-lived status token from /v1/status-token/:id.","capability_tiers":{"note":"Tier labels describe declared class plus evidence. Evidence kinds: model_card, eval_report (signature-checked), frontier_framework, slsa_provenance, oms_signature, c2pa_manifest, iso42001_ref, aiuc1_ref. The registry stores hashes, signers and URLs; it does not judge truth or safety. Higher limits for si_declared need evidence; T-SI is reserved and never automatic.","si_declared_by_evidence":[{"evidence_level":0,"cumulative_above":"25.00","max_license_total":"100.00","delegation_allowed":false},{"evidence_level":2,"cumulative_above":"50.00","max_license_total":"500.00","delegation_allowed":false},{"evidence_level":3,"cumulative_above":"100.00","max_license_total":"1000.00","delegation_allowed":false}]},"a_passport_alone_permits_nothing":"Identity is not permission. A site registers an environment, proves it controls its origin, and sets rules; an agent can act there only with a license for that exact environment (default deny).","refused":[{"code":"binding.invalid","rule":"agent registration without a fresh operator binding statement matching both agent keys"},{"code":"binding.replayed / agent.key_exists (409)","rule":"reusing a binding statement, or registering a key that already belongs to a passport (including retired keys)"},{"code":"passport.id_taken / passport.id_assigned_by_registry (409)","rule":"claiming an existing passport id, or trying to choose one"},{"code":"passport.non_transferable / passport.permanent (405)","rule":"transferring, selling, re-assigning or deleting a passport"},{"code":"license.already_superseded / license.revoked / license.supersede_mismatch","rule":"branching a license history, renewing a revoked license, or moving a license version to another passport"},{"code":"license.environment_unverified","rule":"licenses for an environment whose origin ownership was never proven (or lapsed)"},{"code":"issuance.outstanding_cap_exceeded / daily_cap_exceeded","rule":"an operator issuing more spendable authority than its configured caps"},{"code":"ceiling.exceeded","rule":"L0/L1 operators cannot issue a license with spend.total_max above the ceiling"},{"code":"class.tier_violation","rule":"si_declared agents: no delegation, regions required, spend.total_max required and capped"},{"code":"license.missing / region.outside_license / region.unknown","rule":"at verification: no license, or the environment's region is outside the license's regions"},{"code":"operator.suspended / agent.frozen / agent.revoked","rule":"kill switch and revocation take effect immediately"}],"class_tiers":[{"agent_class":"software","cumulative_above":"100.00","max_license_total":null,"delegation_allowed":true,"regions_required":false,"min_operator_level":"L0","evidence_level":0},{"agent_class":"ai","cumulative_above":"100.00","max_license_total":null,"delegation_allowed":true,"regions_required":false,"min_operator_level":"L0","evidence_level":0},{"agent_class":"si_declared","cumulative_above":"25.00","max_license_total":"100.00","delegation_allowed":false,"regions_required":true,"min_operator_level":"L0","evidence_level":0}],"regions":{"codes":"ISO 3166-1 alpha-2, the group EU (27 members), or *","enforcement":"license.regions must contain the environment's region (profile.region) or, if the environment declares none, the request's country; unknown means deny"},"revocation":"GET /v1/revocations is signed (ES256) and cacheable; GET /registry/:id shows per-passport state.","not_claimed":["This registry is not certified, audited or approved by any authority, and does not claim legal or regulatory compliance.","It is not the authority for agent identity: it is one registry whose rules are stated on this page.","Self-declared fields are not verified. A passport is not a statement about any person or about the safety of an agent."]}