ECZ-ID Agent Trust
Make AI agents, APIs, MCP servers, and tool surfaces resolver-verifiable. Developer Gateway explains the model, documents the discovery surfaces, and routes acquisition to TrustOps and proof to Resolver. It does not write truth. It does not host checkout. It does not replace Resolver.
ECZ-ID Agent Credential™
A resolver-verifiable reference for one logical agent, bound to an accountable operator. One Agent Credential equals one logical agent. Acquisition and lifecycle live in TrustOps. Current proof lives in Resolver.
ECZ-ID API Passport™
A resolver-verifiable reference for one authorised API surface. One API Passport equals one authorised API surface. Required when the agent exposes or depends on authorised API surfaces under ECZ-ID rules.
How the model works
Manifests are discovery only
Manifest, JSON, and header signals help relying parties find the credential reference. They are not proof.
Copied JSON does not copy trust
A manifest moved to another origin or frozen in time does not transfer the underlying credential.
Resolver is proof
Current state — including authorised origins and lifecycle status — is confirmed in Resolver.
TrustOps owns lifecycle
Acquisition, activation, billing, suspension, and lifecycle control happen in TrustOps.
Developer Gateway documents and routes
No checkout here. No proof clone here. No truth writing here. No marketplace approval claims here.
One credential = one logical thing
One Agent Credential per logical agent. One API Passport per authorised API surface.
Supported Agent Trust surfaces
Each surface is discovery, local check, education, or routing. None of them write truth. None of them replace Resolver.
Documentation
Public reference for the discovery surfaces, the API Passport rules, the TrustOps handoff, the Resolver proof model, the forbidden-claims governance, and the abuse-report path.
Developer Gateway does
- Explain the Agent Trust model
- Document the discovery surfaces and schema
- Guide developers and operators through setup choices
- Route acquisition and lifecycle actions to TrustOps
- Route proof checks to Resolver
- Document the abuse-report path
Developer Gateway does not
- Write truth or issue credentials
- Host acquisition, billing, or lifecycle control
- Replace Resolver as the proof surface
- Operate as a marketplace checkout
- Certify safety, security, lawfulness, or platform approval
- Make partnership claims that are not proven
Next steps
Use the guided Agent Trust flow to identify which passports your situation needs. Use TrustOps to set up. Use Resolver to confirm current proof.
