Authorisation evidence

Agents sometimes present an authorisation credential at the moment of an action (for example an x401-shaped presentation). PROOFROOM can store that presentation as an attachment on a receipt or a claim. It does not become an identity provider, does not issue credentials, and does not gate any action on one.

Evidence levels remain exactly three: self_reported, system_confirmed and operator_confirmed. Authorisation credentials are not a fourth rung.

How to attach

Optional field on record_evidence_event, POST /api/events and the claim flow:

{
  "authorization": {
    "protocol": "x401",
    "presentation": { }
  }
}

Omitting the field changes nothing. The scrubbing pipeline applies to presentation JSON. Claim-level issuer and subject_hint may be stored when present; full identity documents are never the goal.

x401 example

x401 is an open, issuer-neutral protocol for asking an agent for cryptographic proof of the verified human behind a request before proceeding. When a host holds such a presentation, it may pass it to PROOFROOM as protocol: "x401". PROOFROOM records that a credential was presented. It does not run the live x401 verifier role for your traffic.

Signature status

Where a cheap offline check against issuer key material referenced in the presentation is available, PROOFROOM may set signature_status to signature_valid or signature_invalid. Otherwise it stores not_checked (or unsupported_format). Current path: presentations are stored as not_checked because full OpenID4VP / Digital Credentials checks need issuer trust establishment beyond this product's scope.

Rendering

At Tier 1 a receipt shows one of:

  • Authorisation credential presented (x401). Signature checked: valid.
  • Authorisation credential presented (x401). Signature checked: invalid.
  • Authorisation credential presented (x401). Signature not checked.

The word "verified" is not used for this check. Invalid signatures are shown prominently. Full presentations are never rendered publicly. Reviewer tier may show issuer and claim-level hints.

Honest limitation

An authorisation credential attached to a receipt is evidence that a credential was presented, and where stated, that its signature was checked. PROOFROOM does not confirm the identity behind it, the issuer's trustworthiness, or that the authorisation was appropriate.

Related