Authorisation Stamps¶
Until now the proof that an agent's action was authorised lived in your Provenance Vault and in the receipts you export. An Authorisation Stamp is that proof travelling with the action itself. When an agent sends an email, posts to an API, submits a payment instruction or produces a document, the artefact carries a compact signed stamp. Whoever receives it, a bank, a supplier, a counterparty's agent, a regulator, checks it in one call or fully offline against your published key, with no account and no trust in Xybern's database, and sees: authorised, under which Charter version, on the authority of an accountable human, within which bounds, by which agent, when, and not substituted since.
Receivers create the demand. A bank that says "we refuse agent-initiated instructions without a valid authorisation stamp" makes every organisation sending agents at it an issuer. The checker is free and universal; the issuer is the product.
Sender: in one minute¶
Turn stamps on for the workspace (Stamps view, "Stamps enabled", or POST /v1/enforce/stamps/settings {"enabled": true}). From then on every authorised outbound action (send_*, pay*, payment*, transfer*, publish*, post_*, external_*, email*, notify*, submit*, issue_*) returns a stamp with the decision:
from xybern import Xybern
from xybern.stamps import http_headers, attach_email, payment_reference
client = Xybern(api_key="xb_live_...")
d = client.intercept("send_payment", "Refund 120 to #4411", agent_id="agt_payments", metadata={"amount": 120})
if d["decision"] == "allow":
token = d["stamp"]["token"] # xst1.…
requests.post(bank_url, json=payload, headers=http_headers(token))
Bind the stamp to the exact artefact when you have it, so a substituted artefact fails the check:
body = render_email(...)
d = client.intercept("send_email", body, agent_id="agt_support", stamp=True,
artefact_sha256=hashlib.sha256(body.encode()).hexdigest())
attach_email(msg, d["stamp"]["token"], footer=True) # X-Xybern-Authorisation header + one-line footer
Or stamp later: client.stamp_decision(decision_id, artefact_sha256=...). Ask for a stamp on any authorised action with stamp=True; suppress one with stamp=False. A per-agent override is delegation_policy.stamp.
Where a rail cannot carry the token (ISO 20022 remittance information is 140 characters), send payment_reference(token), the resolver URL of the stamp; the receiver resolves it and gets the full stamp back.
Receiver: in one minute¶
Anyone, no account:
- Browser: paste the stamp at
https://xybern.com/check(or the issuer's own host). The signature is checked in the browser against the issuer's published key; the resolver reports whether the stamp still stands. - One call:
GET <resolver>/<stamp_id>(the resolver is named inside the stamp), JSON or HTML. - Fully offline: fetch the issuer record once (
<host>/.well-known/xybern-issuer/<issuer_id>), cache the keys, then
from xybern.stamps import verify_offline, verify
res = verify_offline(token, keys, artefact_sha256=sha256_of_what_you_received)
res["valid"], res["body"]["decision"]["outcome"], res["body"]["charter_hash"], res["body"]["accountable"]
verify(token) # keys from the issuer record, then the resolver for revocation state
python -m xybern.stamps "$TOKEN" --artefact received.pdf
python tools/xybern-verify/verify.py --stamp "$TOKEN" --keys keys.json --artefact received.pdf
If the receiver also runs Xybern, its own Charter can require stamps on what it receives: declare "refuse any received payment instruction that does not carry a valid authorisation stamp from a trusted issuer" and the compiler emits an inbound_stamp rule; or add the rule directly. Trusted issuers are set in the Stamps view (* for any issuer). When the sender's issuer is on the same install, the receiver's decision is sealed in the sender's vault too (stamp_honoured), so both sides hold the record.
What a stamp reveals, and what it does not¶
It reveals the outcome, the action type, when it was decided, the issuer, the Charter version hash, a pseudonymous accountable-party id, the agent id, the bounds the agent was under, and the artefact hash. It never carries the action content, the metadata, a name or an email. The issuer resolves the accountable id to the human on lawful request (Stamps view, or GET /enforcement/stamps/accountable/<id>).
Revocation¶
Revoking a stamp (Stamps view, POST /v1/enforce/stamps/<id>/revoke) tells receivers to stop honouring it; Revoke everywhere on an agent revokes its outstanding stamps. The receipt remains the historical proof that the action was authorised at the time. Every issue, check and revocation is sealed to the Provenance Vault, and the resolver counts checks and honours.
Issuer identity¶
Your issuer id is your workspace id; your display name and trusted issuers are set in the Stamps view. Your issuer record is served at /.well-known/xybern-issuer/<id> on your host (a Sovereign install serves its own, so receivers can pin it directly), and you can opt into the public mirror at /.well-known/xybern-issuers. Keys are the Provenance Vault's published signing keys; retired keys stay published so older stamps still verify.
API¶
| Method | Path | Purpose |
|---|---|---|
| POST | /v1/enforce/stamps |
Issue for a decision: {decision_id, artefact_sha256?} |
| GET | /v1/enforce/stamps |
List (agent_id, status, decision_id) |
| GET | /v1/enforce/stamps/<id> |
One stamp, with its token while active |
| POST | /v1/enforce/stamps/<id>/revoke |
Revoke |
| POST | /v1/enforce/stamps/verify |
Issuer-side check of a token |
| GET, POST | /v1/enforce/stamps/settings |
enabled, public_issuer, trusted_issuers, display_name |
| GET | /proof/stamp/<id> |
Public resolver (no auth) |
| POST | /check/verify, GET /check |
Public check endpoint and page |
| GET | /.well-known/xybern-issuer/<id>, /.well-known/xybern-issuers |
Issuer record and public mirror |
SDK 2.6.0: intercept(stamp=, artefact_sha256=), stamp_decision, list_stamps, get_stamp, revoke_stamp, verify_stamp, stamp_settings, and xybern.stamps. JavaScript 1.20.0: stampDecision, listStamps, getStamp, revokeStamp, verifyStamp, verifyStampOffline, stampHeaders, paymentReference. Format: Authorisation Stamp v1.