Skip to content

Open formats bundle, version 1

Status: final, version 1. Repository path spec/xybern-formats-v1/.

The signed and structured formats the Xybern Authorisation Layer produces, so that any party can check an AI agent's authority, an authorised action and its execution without an account and without trusting Xybern. The bundle is the standard; the issuer registry is the network: any implementer that reaches the same outcome on every test vector interoperates.

Format Identifier Token Spec
Authorisation Receipt xybern-authorisation-receipt/v1 document receipt-v1
Authorisation Warrant xybern-warrant-v1 xwt1. warrant-v1
Authorisation Stamp xybern-stamp-v1 xst1. stamp-v1
Execution Attestation xybern-execution-v1 xea1. attestation-v1
Authority Lineage xybern-lineage-v1 document lineage-v1
Pre-flight Answer xybern-preflight-answer-v1 document preflight-v1
Issuer Record xybern-issuer-record-v1 document issuer-record-v1
Authority Slice (draft) xybern-authority-slice-v1 document authority-slice-v1
Authority Bundle (draft) xybern-authority-bundle-v1 document authority-bundle-v1
XAO invariants (draft) xao-invariants-v1 pure checks xao-invariants-v1
Agent Passport (draft) xybern-passport-v1 xpp1. passport-v1

Canonicalisation

Every signed body is canonical JSON: keys sorted at every level, separators , and : with no whitespace, UTF-8 with non-ASCII kept as is, numbers as JSON numbers, null for absent optional fields the format lists. The body hash is the hex SHA-256 of the canonical bytes. The signature is ECDSA P-256 over SHA-256 of the canonical bytes, DER encoded, base64 in signature.value, signature.algorithm = "ecdsa-p256-sha256", signature.key_id naming the issuer's published key.

A token is <prefix> plus base64url without padding of the canonical JSON of {"body", "signature"}. Checkers strip all whitespace before decoding, so tokens survive header folding. Timestamps are ISO 8601 UTC with a Z suffix; a token is valid only inside [not_before, expires_at).

Keys

Issuers publish keys at /.well-known/xybern-issuer/<issuer_id> and /v1/enforce/warrants/keys as {key_id, algorithm, public_key_pem, status}. A signature is accepted only from a matching key_id whose status is not revoked; rotation keeps old keys published as retired.

Test vectors and conformance

spec/xybern-formats-v1/keys.json holds the test key (never trusted by a real issuer) and vectors/*.json hold the vectors with an expect outcome: valid or invalid for tokens (with the check inputs), well-formed for documents (with required keys and the canonical sha256). Negative vectors cover a tampered body, a tampered signature, an unknown key, an expired window, an action outside the families, an argument above a bound, a child warrant that widens its parent, an artefact substituted after stamping, and a token folded across lines.

python spec/xybern-formats-v1/conformance.py                       # reference checker, 56 vectors
python spec/xybern-formats-v1/conformance.py --checker my_checker.py
python tools/xybern-verify/verify.py --vectors spec/xybern-formats-v1

An implementation conforms to version 1 when it reaches the expected outcome of every vector. A checker module exposes check_warrant(token, keys, action_type, metadata, parent_token), check_stamp(token, keys, artefact_sha256) and check_attestation(token, keys), and optionally check_invariant(invariant_id, inputs) and check_passport(token, keys) for the draft xao-invariants-v1 and xybern-passport-v1 vectors.

Reference implementations

Issuer and checkers in package/xybern_api/ (warrants.py, stamps.py, execution_attestations.py, lineage.py, preflight.py); command line tools/xybern-verify/verify.py (--warrant, --stamp, --attestation, --vectors, proof bundles); Python SDK xybern.warrants, xybern.stamps; JavaScript SDK verifyWarrantOffline, verifyStampOffline; browser <issuer>/check.