Open formats bundle, version 1¶
Status: final, version 1. Repository path spec/xybern-formats-v1/.
The signed and structured formats the Xybern Authorisation Layer produces, so that any party can check an AI agent's authority, an authorised action and its execution without an account and without trusting Xybern. The bundle is the standard; the issuer registry is the network: any implementer that reaches the same outcome on every test vector interoperates.
| Format | Identifier | Token | Spec |
|---|---|---|---|
| Authorisation Receipt | xybern-authorisation-receipt/v1 |
document | receipt-v1 |
| Authorisation Warrant | xybern-warrant-v1 |
xwt1. |
warrant-v1 |
| Authorisation Stamp | xybern-stamp-v1 |
xst1. |
stamp-v1 |
| Execution Attestation | xybern-execution-v1 |
xea1. |
attestation-v1 |
| Authority Lineage | xybern-lineage-v1 |
document | lineage-v1 |
| Pre-flight Answer | xybern-preflight-answer-v1 |
document | preflight-v1 |
| Issuer Record | xybern-issuer-record-v1 |
document | issuer-record-v1 |
| Authority Slice (draft) | xybern-authority-slice-v1 |
document | authority-slice-v1 |
| Authority Bundle (draft) | xybern-authority-bundle-v1 |
document | authority-bundle-v1 |
| XAO invariants (draft) | xao-invariants-v1 |
pure checks | xao-invariants-v1 |
| Agent Passport (draft) | xybern-passport-v1 |
xpp1. |
passport-v1 |
Canonicalisation¶
Every signed body is canonical JSON: keys sorted at every level, separators , and : with no whitespace, UTF-8 with non-ASCII kept as is, numbers as JSON numbers, null for absent optional fields the format lists. The body hash is the hex SHA-256 of the canonical bytes. The signature is ECDSA P-256 over SHA-256 of the canonical bytes, DER encoded, base64 in signature.value, signature.algorithm = "ecdsa-p256-sha256", signature.key_id naming the issuer's published key.
A token is <prefix> plus base64url without padding of the canonical JSON of {"body", "signature"}. Checkers strip all whitespace before decoding, so tokens survive header folding. Timestamps are ISO 8601 UTC with a Z suffix; a token is valid only inside [not_before, expires_at).
Keys¶
Issuers publish keys at /.well-known/xybern-issuer/<issuer_id> and /v1/enforce/warrants/keys as {key_id, algorithm, public_key_pem, status}. A signature is accepted only from a matching key_id whose status is not revoked; rotation keeps old keys published as retired.
Test vectors and conformance¶
spec/xybern-formats-v1/keys.json holds the test key (never trusted by a real issuer) and vectors/*.json hold the vectors with an expect outcome: valid or invalid for tokens (with the check inputs), well-formed for documents (with required keys and the canonical sha256). Negative vectors cover a tampered body, a tampered signature, an unknown key, an expired window, an action outside the families, an argument above a bound, a child warrant that widens its parent, an artefact substituted after stamping, and a token folded across lines.
python spec/xybern-formats-v1/conformance.py # reference checker, 56 vectors
python spec/xybern-formats-v1/conformance.py --checker my_checker.py
python tools/xybern-verify/verify.py --vectors spec/xybern-formats-v1
An implementation conforms to version 1 when it reaches the expected outcome of every vector. A checker module exposes check_warrant(token, keys, action_type, metadata, parent_token), check_stamp(token, keys, artefact_sha256) and check_attestation(token, keys), and optionally check_invariant(invariant_id, inputs) and check_passport(token, keys) for the draft xao-invariants-v1 and xybern-passport-v1 vectors.
Reference implementations¶
Issuer and checkers in package/xybern_api/ (warrants.py, stamps.py, execution_attestations.py, lineage.py, preflight.py); command line tools/xybern-verify/verify.py (--warrant, --stamp, --attestation, --vectors, proof bundles); Python SDK xybern.warrants, xybern.stamps; JavaScript SDK verifyWarrantOffline, verifyStampOffline; browser <issuer>/check.