Proofroom Passport (Spec v1)
A Passport is a short-lived signed snapshot an agent presents: Proofroom Agent ID, identity grade, sponsor alias (accountability by inquiry), capabilities at current scope version, evidence state (chain head, receipt counts, three trust signals, incidents), issued/expires, and a live verify URL.
- Asserts, never authorises. Embedded
does_not_verifycaveats travel with the artifact. - Format: W3C Verifiable Credential profile (
ProofroomPassport). - Audience binding: M2M presentations bind
audience+nonce; replayed or stolen passports fail elsewhere. - Grades: Enrolled (Sponsored) passports are bearer artifacts and labelled as such; sensitive contexts should require Verified grade.
- Young agents:
trajectory(age_days, receipts, incidents) so thin passports read as honest youth.
Verifier-first surfaces
| Surface | Path |
|---|---|
| Issue (audience-bound) | GET /api/passport/{pag_…}?audience=…&nonce=… |
| Live check | POST /api/passport/check with { claims, signature, audience, nonce } |
| Offline | node scripts/verify-passport.mjs passport.json key.json |
| Signing key | /.well-known/proofroom-signing-key.json |
Offline check proves genuine and unexpired. The live URL confirms current state and revocation.
Auto-issued at agent enrollment (§17). Buyer requirement kit may require Passport presentation alongside receipts.