Agent Passport, format v1 (draft)¶
Status: draft, XAO version 0.3. Vectors: spec/xybern-formats-v1/vectors/passport.json. Token prefix xpp1., encoding and canonicalisation as for warrants and stamps.
| Key | Meaning |
|---|---|
format |
"xybern-passport-v1" |
passport_id, version |
pas_ plus 12 hex characters; the version rises on every re-issue; earlier versions are superseded |
issuer |
{workspace_id, key_id, resolver}; the resolver serves <resolver>/<passport_id> |
principal |
{agent_id, name, did, fingerprint, kind, framework} |
owner |
{id, kind}, a pseudonymous accountable id the issuer resolves on lawful request |
organisation |
{workspace_id, name, department_id, external_org} |
model |
{family, version} as declared |
system_prompt_hash |
hex SHA-256 as declared; last_attestation says whether the last session matched it |
approved_tools, approved_tools_source |
the tools the principal may use and where the list came from (declared, access_profile:<id>, tool_schemas) |
permitted_models, data_clearance |
declared |
financial_authority |
{max_single_amount, currency, sources} |
delegation_authority |
{may_delegate, requires_grant, max_depth, grants_received, grants_given} |
risk_class, risk_class_source, environment, purpose |
declared or derived |
posture |
{trust_state, trust_level, warrants_active, missions_active, access_profile, sessions_active, decisions, prompt_drift_count, last_seen_at} |
last_attestation |
{at, session_id, prompt_hash, matches} |
trust_history |
[{at, state, level}], bounded |
status, issued_at, expires_at |
active or revoked; a checker refuses revoked and an expired window |
Checks a verifier performs offline: format, signature against a published key that is not revoked, now < expires_at, status != revoked. Version currency and revocation after issue are issuer state: resolve at the issuer. A check_passport(token, keys) in a conformance checker must reach the expect of every vector (valid, tampered authority, expired, revoked, unknown key).