Skip to content

Receiver guide for banks and counterparties

You received an email, a payment instruction, a document or an API call from an AI agent, and it carries a Xybern Authorisation Stamp. This page says what you can conclude, how to check it in under a minute, and what to do when a check fails. No account with Xybern is needed for any of it.

What a stamp tells you

  • The action was authorised before it ran by the organisation whose issuer id is on the stamp, under a signed Charter version, by a named agent.
  • The artefact is the one that was authorised: the stamp binds the SHA-256 of the email, document or payment reference. If the content changed after stamping, the check fails.
  • A named accountable human exists, as a pseudonymous id the issuer resolves on lawful request (decision D8). The stamp never carries a name or an email.
  • What class of data the action touched (data: class, PII, origins), never the data.
  • Since Phase 9, whether the action was actually executed, and whether exactly as declared: the resolver's Executed line.

How to check it

  1. Offline, with the issuer's published key: python -m xybern.stamps <token> or tools/xybern-verify/verify.py --stamp <token> --keys keys.json [--artefact <file>], or paste it at <issuer>/check. The signature, the format, the validity window and the artefact hash are checked in your environment.
  2. At the issuer's resolver (<resolver>/<stamp_id>?format=json): whether the stamp still stands (not revoked), how many times it was checked and honoured, and the execution status.
  3. Pin the issuer. Fetch /.well-known/xybern-issuer/<issuer_id> once, store the keys, and refuse stamps from issuers you have not pinned. The public mirror at xybern.com/.well-known/xybern-issuers lists issuers that opted in; Sovereign issuers may publish only at their own path.

If you run Xybern too

Set the issuer as a trusted issuer in your workspace and let the Charter's inbound rule refuse instructions that carry no valid stamp. When you honour a stamp, your decision is sealed in the issuer's Vault as well as yours (counterparty handshake), on the same install or across installs.

When a check fails

Failure Meaning Do
Signature does not verify The token was altered, or it was not issued by that key Treat the message as unauthorised; do not act
Artefact hash does not match The content was substituted after authorisation Do not act; report to the issuer with the stamp id
Expired The stamp's window passed Ask for a fresh action
Resolver says revoked The issuer withdrew it Do not act
Execution failed or missing The action may not have run Confirm with the issuer before relying on it

What Xybern will not say

Xybern is not a certification body and does not describe any issuer as SAMA certified, approved, compliant or regulated. The stamp proves an authorisation by that issuer under its own Charter; whether to rely on it is your decision under your own controls (SAMA CSF 3.4.1 contract and vendor management applies to your relationship with the issuer, not with Xybern).