Identity
Hosted · caller-held keysKeep a resolvable identifier and prove control of its keys.
Scope & usage
- Purpose
- Associate records with an application identity and verify control of a signing key.
- Source status
- Implemented in source. Caller-held roots and legacy identities have different authority rules.
- Scope
- Project access, identity control, and consent are separate.
- Read
- Identity and authority; key custody and recovery.
- Action
- Explicit registration creates records and returns a bearer once. Recovery and protected changes require their own proofs; browsing does neither.
- Auth
- The seed-registration flow uses caller-held keys and its mode-specific admission checks. Protected rooted changes additionally require an identity signature.
- Output
- Identity and key records, signed-request results, or a typed refusal. An identity record does not assign the reader a persona.