{
  "_what": "One worked, first-party ECZ-ID interoperability example: a real operator record, a real native binding, the public destinations that serve it, and the shape that relates it to a machine somebody else operates.",
  "_why": "Every other example in this estate uses example.com. This one uses the operator of this site, so a reader can run every URL in it and get a real answer instead of a shape. It is the reference instance for the ECZ-ID acquisition websites and the hyperscaler integration workstream: copy it, replace the counterparty half, keep the boundaries.",
  "_measured_at": "2026-09-22",
  "_measurement_method": "Every URL in this document was requested with GET from a clean environment with no account and no credential. The statuses recorded below are what came back.",
  "schema_version": "ecz.first_party_interoperability_example.v1",
  "is_proof": false,
  "recheck_before_reliance": true,
  "operator": {
    "_role": "The accountable party. One legal entity, one parent ECZ-ID.",
    "ecz_id": "ECZ-GB-RBS1NW",
    "legal_name": "ECOCITIZENZ LTD",
    "trading_name": "EcoCitizenz",
    "jurisdiction": "UNITED KINGDOM",
    "company_registration_number": "17348848",
    "_publication_basis": "The record's own business_profile.publication_consent marks company_registration_number, registered_address and incorporation_date as consented to publication. Nothing is republished here that the record does not consent to.",
    "record_type": "ECZ_ID_PARENT",
    "parent_tier": "VERIFIED",
    "_parent_tier_meaning": "The parent organisation's identity is verified. No machine operated by it is verified by that fact.",
    "measured_state_2026_09_22": {
      "lifecycle_state": "ACTIVE",
      "reliance_level": "PARENT_IDENTITY_ONLY",
      "binding_state": "NO_PUBLIC_PROOF",
      "binding_reason_code": "NO_PUBLIC_BINDING_PROOF_AVAILABLE",
      "children_count": 0,
      "_note": "A snapshot, recorded so a reader can tell whether this document has gone stale. It is not the current state and must never be used as one. Read the machine record."
    }
  },
  "public_destinations": {
    "_role": "Where the record is read. Two different hosts, deliberately.",
    "machine_record": {
      "url": "https://api.ecocitizenz.com/api/p/ECZ-GB-RBS1NW.json",
      "method": "GET",
      "auth": "none",
      "measured_status": 200,
      "media_type": "application/json",
      "_use": "Automate against this one.",
      "status_meaning": {
        "200": "the public record; still not proof",
        "404": "NO_PUBLIC_ECZ_ID_FOUND — absence of a record, never a verdict on the machine",
        "410": "treat exactly as 404",
        "429": "RESOLVER_RATE_LIMITED — retryable",
        "503": "RESOLVER_UNREADABLE — retryable; unreadable is not absent and not unsafe"
      },
      "caching": "NEVER cache the record. Read it live whenever state matters.",
      "cors": "Access-Control-Allow-Origin: * (measured 2026-09-22)"
    },
    "human_record": {
      "url": "https://resolver.ecocitizenz.org/p/ECZ-GB-RBS1NW",
      "method": "GET",
      "auth": "none",
      "measured_status": 200,
      "_use": "Link people here. Do not scrape it.",
      "_warning": "This host does not serve the machine record. Pointing automation at it returns a page, not JSON."
    },
    "share_badge": {
      "url": "https://api.ecocitizenz.com/api/badge/ECZ-GB-RBS1NW/BP.svg",
      "measured_status": 200,
      "is_proof": false,
      "_note": "An image that routes to the Resolver. The image is never the proof."
    }
  },
  "native_binding": {
    "_role": "How the ECZ-ID attaches to a machine, in a format the machine's own ecosystem already reads. ECZ-ID does not invent a new place to put identity.",
    "subject": "com.ecocitizenz/trust-mcp",
    "subject_kind": "registry_server_name",
    "family": "MCP",
    "declared_by_operator_at": {
      "url": "https://developers.ecocitizenz.com/.well-known/ecz-mcp.json",
      "measured_status": 200,
      "carries": [
        "operator_ecz_id",
        "resolver_url",
        "machine_proof_url",
        "mcp_server.name",
        "mcp_server.endpoint",
        "mcp_server.registry"
      ]
    },
    "ecosystem_registration": {
      "registry": "Official MCP Registry",
      "url": "https://registry.modelcontextprotocol.io/v0.1/servers/com.ecocitizenz%2Ftrust-mcp/versions",
      "measured_status": 200,
      "registry_status": "active",
      "version": "0.2.0",
      "transport": "streamable-http",
      "endpoint": "https://trust-mcp.ecocitizenz.com/mcp"
    },
    "_honest_scope": "The server is bound to the operator by declaration at the operator's own origin and is listed in the Official MCP Registry. It does NOT hold a child Passport of its own: that is a separate acquisition an operator runs, and none has been run for this subject. This document will not invent one to look complete.",
    "_known_gap": "https://trust-mcp.ecocitizenz.com/.well-known/ecz-mcp.json answers 404. The binding is declared at the operator origin only, not at the server's own origin. Recorded rather than hidden."
  },
  "verifier_result": {
    "_role": "The same record, read by the published read-only verifier rather than by hand, so the two can be compared.",
    "produced_by": "npx -y @ecocitizenz/ecz-id-mcp-verifier check --target ECZ-GB-RBS1NW",
    "verifier_version": "0.9.0",
    "measured_at": "2026-09-22",
    "result_state": "RESOLVER_VERIFIABLE",
    "reason_codes": [],
    "policy_mode": "OPEN",
    "exit_code": 0,
    "primary_action": "VIEW_RESOLVER_PROOF",
    "secondary_actions": [
      "RECHECK_BEFORE_RELIANCE"
    ],
    "verifier_writes_truth": false,
    "verifier_activates_proof": false,
    "verifier_marks_bound": false,
    "no_source_uploaded": true,
    "no_secrets_uploaded": true,
    "no_telemetry": true
  },
  "digital_entity_graph": {
    "_role": "The Digital Entity Graph for this subject: four lanes, and deliberately no fifth lane for authority. This is the estate model used by the ECZ-ID acquisition websites (website-factory/graph/entity-graph.ts), expressed here against the live acquisition contract so the two cannot drift.",
    "_derivation": "Every lane below is read from https://trustops.ecocitizenz.com/api/v1/acquisition/families. A relationship cannot exist in a rendering without existing in the record first, and there is no second list of what connects to what.",
    "lanes": [
      {
        "lane": "operator",
        "edge_label": "operates",
        "node": "ECOCITIZENZ LTD",
        "ecz_id": "ECZ-GB-RBS1NW",
        "detail": "One ECZ-ID Business Passport. Every Passport hangs from it, and it never changes."
      },
      {
        "lane": "subject",
        "edge_label": "is",
        "node": "ECZ-ID MCP Passport",
        "source_field": "families[mcp].subject_law",
        "detail": "one logical MCP server operated by the Parent",
        "singleton_law": "one server -> one Passport; tools inside a server are never Passports",
        "never_a_second_passport": [
          "tool",
          "endpoint",
          "deployment",
          "replica"
        ]
      },
      {
        "lane": "binding",
        "edge_label": "is represented by",
        "source_field": "families[mcp].binding_classes",
        "nodes": [
          "mcp_registry_entry",
          "mcpb_desktop_bundle",
          "mcp_remote_http",
          "mcp_local_stdio"
        ],
        "detail": "A representation of the same subject. It never becomes a second Passport.",
        "this_subject_uses": [
          "mcp_registry_entry",
          "mcp_remote_http"
        ]
      },
      {
        "lane": "relationship",
        "edge_label": "relates to",
        "source_field": "families[mcp].adjacent",
        "nodes": [
          "API_PASSPORT",
          "SERVICE_WORKLOAD_PASSPORT",
          "SDK_PASSPORT",
          "AGENT_PASSPORT"
        ],
        "detail": "Semantically valid links to other ECZ-ID families. A link is not an instance: it says this kind of subject can relate to that kind, not that any such relationship is live."
      }
    ],
    "authority": {
      "heading": "A relationship is not permission",
      "statement": "Every line above says two things are connected. None of them says one is allowed to act for the other. Authority is granted in your own systems, and ECZ-ID does not grant it, infer it or enforce it.",
      "_why_no_authority_lane": "A line between two boxes reads as permission unless the picture says otherwise. There is no authority EDGE, only this statement. If delegated authority is ever published on the public record it becomes a fourth lane, with evidence, and not before.",
      "established": [
        "Which organisation operates this entity, named on the public record.",
        "The organisation’s own tier, and exactly what that tier covers.",
        "Which representations the operator has bound to this one identity.",
        "What the record said at the moment you resolved it."
      ],
      "not_established": [
        "That the entity is safe, correct, approved or certified.",
        "That a connected entity may act on this one’s behalf.",
        "That any permission, scope or credential has been delegated.",
        "That a relationship shown here is currently active in production."
      ]
    },
    "illustrative_note": "Illustrative. This is the shape a record of this kind can take, not a live estate — a new Passport starts with no bindings and no relationships, and shows only what its operator chooses to publish."
  },
  "adjacent_entity_relationship": {
    "_role": "How two machines nobody jointly owns relate to each other. Each side resolves the other and records what it found. Neither side can vouch for the other.",
    "_how_to_use_this_block": "The mcp_subject half is real and was measured. The agent_subject half is a slot: put your own subject in it, resolve it yourself, and write down what you actually got. Do not copy a posture you did not measure.",
    "type": "ecz.reciprocal_reliance_envelope",
    "version": "1.0",
    "conforms_to": "https://developers.ecocitizenz.com/schemas/action-envelopes/reciprocal-reliance-envelope.schema.json",
    "agent_subject": null,
    "_agent_subject_note": "null means not measured, which is an honest value. It does not mean no agent, and it does not mean the agent is unknown to ECZ-ID.",
    "mcp_subject": {
      "target": "com.ecocitizenz/trust-mcp",
      "target_type": "mcp_server",
      "operator_ecz_id": "ECZ-GB-RBS1NW",
      "posture": "OPERATOR_RECORD_RESOLVER_VERIFIABLE",
      "_posture_note": "The OPERATOR's record is resolver-verifiable. The server itself holds no child Passport, so this is deliberately not the bare RESOLVER_VERIFIABLE the schema uses for a subject with its own record."
    },
    "policy_hint": "OPEN",
    "recommended_posture_paths": [
      "mcp: view_resolver_proof",
      "agent: resolve the peer yourself before recording a posture",
      "recheck_before_reliance"
    ],
    "external_authorisation": "not_determined_by_eczid",
    "authority_boundary": "ECZ-ID Core systems control canonical state. TrustOps handles setup. Resolver shows public proof. Re-check before reliance.",
    "local_policy_decides": true,
    "recheck_before_reliance": true,
    "no_safety_or_approval_inference": true,
    "verifier_writes_truth": false,
    "verifier_activates_proof": false,
    "verifier_marks_bound": false,
    "_relationship_to_the_graph": "The graph above is the SHAPE: which kinds of subject may relate. This block is the RUNTIME ARTEFACT: what was actually found when both sides were resolved. A lane in the graph never implies a posture here, and a posture here never adds a lane there."
  },
  "free_acquisition": {
    "_role": "Where a reader gets one of these for a machine they operate. No payment, one sign-in.",
    "contract_url": "https://trustops.ecocitizenz.com/api/v1/acquisition/families",
    "contract_version": "ecz.free_passport_acquisition.v1",
    "measured_status": 200,
    "lane": "FREE",
    "law": {
      "payment_required": false,
      "payment_calls": 0,
      "authentications_required": 1,
      "parent_tier_required": "DECLARED",
      "parent_is_created_if_absent": true,
      "one_subject_one_ecz_id": true,
      "a_passport_is_not_proof": true
    },
    "_availability_rule": "Read families[].available from the contract at run time. This document does NOT list which families are open, because that changes with no release on either side and a copied list is the commonest way a surface starts lying. Render a call to action only where available is true; render NOT_YET_LIVE as 'not open yet', never as an error.",
    "forwardable_context_keys": [
      "source_surface",
      "origin_surface",
      "requested_passport_type",
      "identifier",
      "identifier_kind",
      "return_to",
      "return_url",
      "campaign",
      "referral",
      "correlation_id",
      "locale",
      "operator_mode",
      "display_name",
      "requested_product",
      "source_provider"
    ],
    "refused_context_keys": [
      "tier",
      "verified",
      "ecz_id",
      "assured",
      "independently_verified",
      "parent_tier",
      "lifecycle_state"
    ],
    "_refused_reason": "A surface cannot assert identity or tier by URL. These are refused loudly by the far end; do not build them.",
    "_cors_note": "Measured 2026-09-22: no TrustOps public surface returns an Access-Control-Allow-Origin header, so a cross-origin browser read of this contract is blocked. Read it from a server or a CLI. The public machine record at api.ecocitizenz.com does send Access-Control-Allow-Origin: * and is browser-readable."
  },
  "boundaries": {
    "_role": "The claims this document does not make, stated once so a reader does not have to infer them.",
    "a_record_is_not_proof": true,
    "absence_result": "NO_PUBLIC_ECZ_ID_FOUND",
    "absence_is_not": [
      "UNSAFE",
      "UNTRUSTED",
      "FAILED_TRUST_CHECK"
    ],
    "unreadable_is_not_absent": true,
    "never_claims": [
      "that the machine is safe",
      "that the machine is secure",
      "that the machine behaves correctly",
      "that ECZ-ID has tested or approved the machine",
      "that the operating organisation has been independently verified",
      "certification, compliance, insurance or platform endorsement"
    ],
    "authority_split": {
      "ecz_id_core": "writes canonical truth and issues identity",
      "trustops": "acquisition, setup and lifecycle",
      "resolver": "the public record",
      "developer_gateway": "documents and routes; issues nothing"
    }
  },
  "reuse": {
    "_role": "How the acquisition websites and the hyperscaler workstream take this.",
    "replace": [
      "adjacent_entity_relationship.agent_subject — with a subject you measured yourself",
      "native_binding.subject — with the machine you operate",
      "free_acquisition — nothing; read the contract live instead of copying it",
      "digital_entity_graph.lanes — re-read them from the contract for YOUR family; do not copy the MCP lanes"
    ],
    "keep_verbatim": [
      "boundaries",
      "public_destinations.machine_record.status_meaning",
      "free_acquisition._availability_rule",
      "free_acquisition.refused_context_keys",
      "digital_entity_graph.authority",
      "digital_entity_graph.illustrative_note"
    ],
    "canonical_url": "https://developers.ecocitizenz.com/examples/first-party-interoperability.json",
    "human_walkthrough": "https://developers.ecocitizenz.com/quickstart/"
  }
}
