Proofroom Passport (Spec v1)

A Passport is a short-lived signed snapshot an agent presents: Proofroom Agent ID, identity grade, sponsor alias (accountability by inquiry), capabilities at current scope version, evidence state (chain head, receipt counts, three trust signals, incidents), issued/expires, and a live verify URL.

  • Asserts, never authorises. Embedded does_not_verify caveats travel with the artifact.
  • Format: W3C Verifiable Credential profile (ProofroomPassport).
  • Audience binding: M2M presentations bind audience + nonce; replayed or stolen passports fail elsewhere.
  • Grades: Enrolled (Sponsored) passports are bearer artifacts and labelled as such; sensitive contexts should require Verified grade.
  • Young agents: trajectory (age_days, receipts, incidents) so thin passports read as honest youth.

Verifier-first surfaces

Surface Path
Issue (audience-bound) GET /api/passport/{pag_…}?audience=…&nonce=…
Live check POST /api/passport/check with { claims, signature, audience, nonce }
Offline node scripts/verify-passport.mjs passport.json key.json
Signing key /.well-known/proofroom-signing-key.json

Offline check proves genuine and unexpired. The live URL confirms current state and revocation.

Auto-issued at agent enrollment (§17). Buyer requirement kit may require Passport presentation alongside receipts.