Verification

How sites verify a passport

Prefer the standards that are winning: Web Bot Auth (HTTP Message Signatures / RFC 9421) for who signed the request, and this registry's license + environment check for what they may do. Identity alone never opens the door.

1. Cryptographic agent identity (Web Bot Auth)

  1. Require Signature-Agent, Signature-Input (tag="web-bot-auth"), and Signature on agent requests.
  2. Resolve keys from the agent's JWKS directory (/.well-known/http-message-signatures-directory) or from a Signature Agent Card's jwks_uri.
  3. Import curated cards from this registry: https://superintelligencepassport.com/registry.txt (plain-text list) or /v1/web-bot-auth/registry (JSON).
  4. CDN path: Cloudflare Bot Management "Request Signature" / signed agents — submit the directory URL via their Bot Submission Form when you are ready for edge verification.

Specs: Cloudflare Web Bot Auth · Signature Agent Card / registry draft · registry format blog.

2. Permission (this registry)

  1. Register an environment for your origin: POST https://superintelligencepassport.com/v1/environments.
  2. Prove ownership (DNS TXT _agentpass-env.<host> or /.well-known/agentpass-environment.json), then POST …/verify-ownership.
  3. Set a deny-by-default profile (allowed actions, regions, spend ceilings). Use the Site console for presets.
  4. On each agent request, forward signatures + license to POST https://superintelligencepassport.com/v1/verify with your environment Bearer key. Expect allow, deny, or approval_required plus a signed stamp.
POST https://superintelligencepassport.com/v1/verify
Authorization: Bearer ape_…
Content-Type: application/json

{ "rp": { "origin": "https://yoursite.example" },
  "request": { "method":"GET", "url":"https://yoursite.example/…",
               "headers": { "signature-agent":"…", "signature-input":"…", "signature":"…", "agent-license":"…" } },
  "intent": { "action":"http:GET", "resource":"https://yoursite.example/…" } }

3. Demo verifier on this origin

When a domain-proven environment for https://superintelligencepassport.com is active, use /demo/verifier to exercise an end-to-end check against a real license (demo verifier, not a production trust decision).

Public registry lookup (no key needed): /registry. Refusal dictionary: /why.

Honest limits

← How to get a passport · registry.txt · For agents