Receiver guide for banks and counterparties¶
You received an email, a payment instruction, a document or an API call from an AI agent, and it carries a Xybern Authorisation Stamp. This page says what you can conclude, how to check it in under a minute, and what to do when a check fails. No account with Xybern is needed for any of it.
What a stamp tells you¶
- The action was authorised before it ran by the organisation whose issuer id is on the stamp, under a signed Charter version, by a named agent.
- The artefact is the one that was authorised: the stamp binds the SHA-256 of the email, document or payment reference. If the content changed after stamping, the check fails.
- A named accountable human exists, as a pseudonymous id the issuer resolves on lawful request (decision D8). The stamp never carries a name or an email.
- What class of data the action touched (
data: class, PII, origins), never the data. - Since Phase 9, whether the action was actually executed, and whether exactly as declared: the resolver's Executed line.
How to check it¶
- Offline, with the issuer's published key:
python -m xybern.stamps <token>ortools/xybern-verify/verify.py --stamp <token> --keys keys.json [--artefact <file>], or paste it at<issuer>/check. The signature, the format, the validity window and the artefact hash are checked in your environment. - At the issuer's resolver (
<resolver>/<stamp_id>?format=json): whether the stamp still stands (not revoked), how many times it was checked and honoured, and the execution status. - Pin the issuer. Fetch
/.well-known/xybern-issuer/<issuer_id>once, store the keys, and refuse stamps from issuers you have not pinned. The public mirror atxybern.com/.well-known/xybern-issuerslists issuers that opted in; Sovereign issuers may publish only at their own path.
If you run Xybern too¶
Set the issuer as a trusted issuer in your workspace and let the Charter's inbound rule refuse instructions that carry no valid stamp. When you honour a stamp, your decision is sealed in the issuer's Vault as well as yours (counterparty handshake), on the same install or across installs.
When a check fails¶
| Failure | Meaning | Do |
|---|---|---|
| Signature does not verify | The token was altered, or it was not issued by that key | Treat the message as unauthorised; do not act |
| Artefact hash does not match | The content was substituted after authorisation | Do not act; report to the issuer with the stamp id |
| Expired | The stamp's window passed | Ask for a fresh action |
| Resolver says revoked | The issuer withdrew it | Do not act |
Execution failed or missing |
The action may not have run | Confirm with the issuer before relying on it |
What Xybern will not say¶
Xybern is not a certification body and does not describe any issuer as SAMA certified, approved, compliant or regulated. The stamp proves an authorisation by that issuer under its own Charter; whether to rely on it is your decision under your own controls (SAMA CSF 3.4.1 contract and vendor management applies to your relationship with the issuer, not with Xybern).