Skip to content

Agent Passport, format v1 (draft)

Status: draft, XAO version 0.3. Vectors: spec/xybern-formats-v1/vectors/passport.json. Token prefix xpp1., encoding and canonicalisation as for warrants and stamps.

Key Meaning
format "xybern-passport-v1"
passport_id, version pas_ plus 12 hex characters; the version rises on every re-issue; earlier versions are superseded
issuer {workspace_id, key_id, resolver}; the resolver serves <resolver>/<passport_id>
principal {agent_id, name, did, fingerprint, kind, framework}
owner {id, kind}, a pseudonymous accountable id the issuer resolves on lawful request
organisation {workspace_id, name, department_id, external_org}
model {family, version} as declared
system_prompt_hash hex SHA-256 as declared; last_attestation says whether the last session matched it
approved_tools, approved_tools_source the tools the principal may use and where the list came from (declared, access_profile:<id>, tool_schemas)
permitted_models, data_clearance declared
financial_authority {max_single_amount, currency, sources}
delegation_authority {may_delegate, requires_grant, max_depth, grants_received, grants_given}
risk_class, risk_class_source, environment, purpose declared or derived
posture {trust_state, trust_level, warrants_active, missions_active, access_profile, sessions_active, decisions, prompt_drift_count, last_seen_at}
last_attestation {at, session_id, prompt_hash, matches}
trust_history [{at, state, level}], bounded
status, issued_at, expires_at active or revoked; a checker refuses revoked and an expired window

Checks a verifier performs offline: format, signature against a published key that is not revoked, now < expires_at, status != revoked. Version currency and revocation after issue are issuer state: resolve at the issuer. A check_passport(token, keys) in a conformance checker must reach the expect of every vector (valid, tampered authority, expired, revoked, unknown key).