Verification
How sites verify a passport
Prefer the standards that are winning: Web Bot Auth (HTTP Message Signatures / RFC 9421) for who signed the request, and this registry's license + environment check for what they may do. Identity alone never opens the door.
1. Cryptographic agent identity (Web Bot Auth)
- Require
Signature-Agent,Signature-Input(tag="web-bot-auth"), andSignatureon agent requests. - Resolve keys from the agent's JWKS directory (
/.well-known/http-message-signatures-directory) or from a Signature Agent Card'sjwks_uri. - Import curated cards from this registry:
https://superintelligencepassport.com/registry.txt(plain-text list) or/v1/web-bot-auth/registry(JSON). - CDN path: Cloudflare Bot Management "Request Signature" / signed agents — submit the directory URL via their Bot Submission Form when you are ready for edge verification.
Specs: Cloudflare Web Bot Auth · Signature Agent Card / registry draft · registry format blog.
2. Permission (this registry)
- Register an environment for your origin:
POST https://superintelligencepassport.com/v1/environments. - Prove ownership (DNS TXT
_agentpass-env.<host>or/.well-known/agentpass-environment.json), thenPOST …/verify-ownership. - Set a deny-by-default profile (allowed actions, regions, spend ceilings). Use the Site console for presets.
- On each agent request, forward signatures + license to
POST https://superintelligencepassport.com/v1/verifywith your environment Bearer key. Expectallow,deny, orapproval_requiredplus a signed stamp.
POST https://superintelligencepassport.com/v1/verify
Authorization: Bearer ape_…
Content-Type: application/json
{ "rp": { "origin": "https://yoursite.example" },
"request": { "method":"GET", "url":"https://yoursite.example/…",
"headers": { "signature-agent":"…", "signature-input":"…", "signature":"…", "agent-license":"…" } },
"intent": { "action":"http:GET", "resource":"https://yoursite.example/…" } }
3. Demo verifier on this origin
When a domain-proven environment for https://superintelligencepassport.com is active, use /demo/verifier to exercise an end-to-end check against a real license (demo verifier, not a production trust decision).
Public registry lookup (no key needed): /registry. Refusal dictionary: /why.
Honest limits
- Default deny never loosens for a high reputation score.
- This feed is curated by a single early-preview operator — not an independent root of trust.
- Prefer plugging into Web Bot Auth / card-network / CDN programs rather than treating this registry as the only authority.