跳转到内容

ak.profile.agent_signer_evidence.v1

← Profiles

ak.profile.agent_signer_evidence.v1

description

"Portable ordinary-Realm Agent signer authorization evidence. Producers publish one reusable Agent authority state attestation and independent privacy-minimal controller gate. Their maximum 300 second windows constrain direct current-query consumption only; verified ordinary publication evidence remains reusable without periodic refresh and is fenced by known revocation. Historical evidence freezes the original producer proof and authorization evidence, or a distinct receiver receipt. Server and peer consumers verify complete identity/method/history dependencies and reuse unchanged material. Ordinary clients consume authenticated own-Station signing-key results and independently verify message signature/MLS/replay; later terminal transitions do not invalidate previously accepted history."

enforcement_phases

[
  "conformance",
  "peer_eligibility"
]

operation_requirements

[
  {
    "direction": "provide",
    "operation_id": "ak.self.signer_keys.read.resolve.v1",
    "binding_kind": "http_json"
  }
]

required_event_kinds

[
  "ak.agent.key.authorize",
  "ak.agent.key.revoke"
]

rejected_event_kinds

[]

required_schemas

[
  "ak.schema.signer_key_query_request.v1",
  "ak.schema.signer_key_query_outcome.v1"
]

required_fixtures

[]

optional_extensions

[
  "ak.profile.key_transparency.v1"
]

feature_discovery

{
  "required": [
    "agent_signer_evidence",
    "agent_signer_evidence_historical_receipt",
    "agent_mls_authorization_cross_binding"
  ],
  "unsupported_optional": "Do not mark ordinary Agent Events Verified. Preserve ciphertext or quarantined plaintext with verification_pending and never fall back to keys/query or ordinary MLS leaf-only trust."
}

profile_set

"extension_profile_implementation"

Source