Authorisation evidence
Agents sometimes present an authorisation credential at the moment of an action (for example an x401-shaped presentation). PROOFROOM can store that presentation as an attachment on a receipt or a claim. It does not become an identity provider, does not issue credentials, and does not gate any action on one.
Evidence levels remain exactly three: self_reported, system_confirmed and
operator_confirmed. Authorisation credentials are not a fourth rung.
How to attach
Optional field on record_evidence_event, POST /api/events and the claim
flow:
{
"authorization": {
"protocol": "x401",
"presentation": { }
}
}
Omitting the field changes nothing. The scrubbing pipeline applies to
presentation JSON. Claim-level issuer and subject_hint may be stored when
present; full identity documents are never the goal.
x401 example
x401 is an open, issuer-neutral protocol for asking an
agent for cryptographic proof of the verified human behind a request before
proceeding. When a host holds such a presentation, it may pass it to PROOFROOM
as protocol: "x401". PROOFROOM records that a credential was presented. It
does not run the live x401 verifier role for your traffic.
Signature status
Where a cheap offline check against issuer key material referenced in the
presentation is available, PROOFROOM may set signature_status to
signature_valid or signature_invalid. Otherwise it stores not_checked
(or unsupported_format). Current path: presentations are stored as
not_checked because full OpenID4VP / Digital Credentials checks need issuer
trust establishment beyond this product's scope.
Rendering
At Tier 1 a receipt shows one of:
- Authorisation credential presented (x401). Signature checked: valid.
- Authorisation credential presented (x401). Signature checked: invalid.
- Authorisation credential presented (x401). Signature not checked.
The word "verified" is not used for this check. Invalid signatures are shown prominently. Full presentations are never rendered publicly. Reviewer tier may show issuer and claim-level hints.
Honest limitation
An authorisation credential attached to a receipt is evidence that a credential was presented, and where stated, that its signature was checked. PROOFROOM does not confirm the identity behind it, the issuer's trustworthiness, or that the authorisation was appropriate.