{"service":{"name":"Universal Cryptographic Identity Infrastructure","short_name":"UCII","version":"1.0.0","category":"identity-infrastructure"},"description":"Post-quantum cryptographic identity infrastructure for humans, AI agents, devices, services, and organizations.","identity":{"model":"cryptographic_identity","supported_types":["HUMAN","AI_AGENT","ROBOT","DEVICE","SERVICE","ORGANIZATION"]},"identity_primitive":{"model":"cryptographic_identity","passwordless":true,"credential_based":true,"post_quantum":true,"multi_entity":true},"protocols":{"transport":["HTTP"],"documentation":["OpenAPI"],"economic":["x402"]},"capabilities":["cryptographic_identity_creation","identity_retrieval","identity_listing","credential_registration","credential_retrieval","credential_verification","credential_revocation","credential_recovery","identity_verification","authentication","authorization","post_quantum_cryptography","machine_identity","ai_agent_identity","service_identity","organization_identity","x402_payment_discovery"],"capability_descriptions":{"cryptographic_identity_creation":"Create cryptographic identities for supported entity types.","identity_retrieval":"Retrieve an existing cryptographic identity by identity identifier.","identity_listing":"List available cryptographic identities through the production identity API.","credential_registration":"Register credentials associated with a cryptographic identity.","credential_retrieval":"Retrieve registered credentials using their public fingerprint.","credential_verification":"Verify a credential and its associated cryptographic proof.","credential_revocation":"Revoke an active credential associated with an identity.","credential_recovery":"Recover identity control through policy-controlled replacement credential provisioning.","identity_verification":"Expose verification information for establishing trust in UCII.","authentication":"Provide authentication operations for compatible application access.","authorization":"Evaluate and enforce operation authorization independently from economic authorization.","post_quantum_cryptography":"Provide post-quantum cryptographic primitives through the supported cryptographic backend.","machine_identity":"Support cryptographic identities for machines and automated systems.","ai_agent_identity":"Support cryptographic identities for AI agents.","service_identity":"Support cryptographic identities for services.","organization_identity":"Support cryptographic identities for organizations.","x402_payment_discovery":"Expose machine-readable x402 economic authorization information for paid operations."},"onboarding":{"entry_point":"/metadata","api_version":"v1","declaration_ingress":{"endpoint":"/v1/onboarding/declarations","method":"POST","accepted_facts":["EXPLICIT_OPT_IN","ONBOARDING_INTENT"],"participant_attribution":"UNVERIFIED","receipt_is_evidence":false,"receipt_creates_authority":false,"receipt_provisions_identity":false,"x402_protected":false},"identity_requirement":{"required":true,"model":"cryptographic_identity","supported_types":["AI_AGENT","SERVICE","DEVICE","ROBOT","HUMAN","ORGANIZATION"]},"credential_requirement":{"supported":true,"registration_endpoint":"/v1/credentials/register","verification_endpoint":"/v1/credentials/verify"},"authentication":{"available":true,"registration_endpoint":"/v1/auth/register","login_endpoint":"/v1/auth/login"},"verification":{"available":true,"status_endpoint":"/v1/verification/status"},"payment":{"protocol":"x402","currency":"USDC","network":"Solana","pricing_endpoint":"/v1/x402/pricing","discovery_endpoint":"/v1/x402/info"},"documentation":{"openapi":"/openapi.json","api_reference":"/docs"},"sequence":["discover","create_or_obtain_identity","register_credential","authenticate","verify","authorize","economically_authorize_with_x402"],"decision_model":{"mode":"explicit_decisions","questions":["required_capability","required_identity_context","required_credential_context","authentication_required","cryptographic_verification_required","authorization_scope","x402_protected","payment_permitted_by_policy","all_required_boundaries_satisfied"],"proceed_when":"all_required_decisions_resolved","unresolved_decision":"fail_closed","authority_boundary":"pre_existing_agent_authority","authorization_scope_expansion":false},"authority_handoff":{"autonomous_when":"within_pre_existing_authority","approval_required_when":"required_authority_is_not_already_granted","on_unmet_authority":["stop","report_unmet_requirement","request_appropriate_approval"],"self_escalation_allowed":false,"human_control_preserved":true,"routine_steps_require_interactive_approval":false},"provisioning":{"mode":"agent_directed","identity":{"action":"create_or_obtain_identity","create_endpoint":"/v1/identity","method":"POST","autonomous_when":"within_pre_existing_authority"},"credential":{"action":"register_or_obtain_credential","registration_endpoint":"/v1/credentials/register","method":"POST","autonomous_when":"within_pre_existing_authority"},"on_insufficient_authority":["stop","report_unmet_requirement","request_appropriate_approval"],"self_escalation_allowed":false},"integration_handoff":{"mode":"agent_assisted","required_steps":["discover","establish_identity","establish_credential","authenticate_when_required","verify_when_required","obtain_authorization","evaluate_x402_when_applicable"],"developer_decisions":["authorization_scope","secret_delivery","payment_policy","additional_authority_when_required"],"agent_may_continue_without_interactive_approval":true,"human_approval_required_for":["authority_not_already_granted","security_sensitive_authorization_decisions"],"self_escalation_allowed":false}},"discovery_relationship":{"root":"identity","identity":{"discovers":["credentials","verification","authentication","x402"],"entry_point":"/v1/identity"},"credentials":{"discovers_through":"identity","next_surfaces":["verification","revocation"]},"verification":{"discovers_through":["identity","credentials"],"entry_point":"/v1/verification/status"},"authentication":{"discovers_through":"identity","entry_point":"/v1/auth/register"},"x402":{"discovers_through":"identity","entry_point":"/v1/x402/info","applies_to":"paid_operations"}},"relationships":{"identity":{"role":"root_cryptographic_entity","relates_to":["credentials","verification","authentication","x402"]},"credentials":{"role":"proof_of_control_over_cryptographic_material","belongs_to":"identity","supports":["verification","revocation"]},"verification":{"role":"trust_and_verification_surface","operates_on":["identity","credentials"]},"authentication":{"role":"compatibility_authentication_layer","distinct_from":"identity"},"x402":{"role":"economic_authorization_layer","applies_to":"paid_operations"}},"cryptography":{"signature":"ML-DSA-65","key_exchange":"ML-KEM-768","backend":"liboqs","hybrid":true},"economic_layer":{"protocol":"x402","currency":"USDC","network":"Solana","model":"pay-per-operation"},"production_api":{"version":"v1","authoritative_contract":"/openapi.json","operations":[{"method":"GET","path":"/v1/identity","domain":"identity"},{"method":"POST","path":"/v1/identity","domain":"identity"},{"method":"GET","path":"/v1/identity/{identity_id}","domain":"identity"},{"method":"POST","path":"/v1/credentials/register","domain":"credentials"},{"method":"GET","path":"/v1/credentials/{fingerprint}","domain":"credentials"},{"method":"POST","path":"/v1/credentials/verify","domain":"credentials"},{"method":"POST","path":"/v1/credentials/{credential_id}/revoke","domain":"credentials"},{"method":"POST","path":"/v1/credentials/{credential_id}/recover","domain":"credentials"},{"method":"POST","path":"/v1/auth/register","domain":"auth"},{"method":"POST","path":"/v1/auth/login","domain":"auth"},{"method":"POST","path":"/v1/auth/refresh","domain":"auth"},{"method":"GET","path":"/v1/auth/me","domain":"auth"},{"method":"POST","path":"/v1/auth/logout","domain":"auth"},{"method":"POST","path":"/v1/auth/revoke","domain":"auth"},{"method":"GET","path":"/v1/verification/status","domain":"verification"},{"method":"POST","path":"/v1/authorization/check","category":"authorization","description":"Evaluate authorization for a protected operation without executing it or performing x402 economic authorization."},{"method":"POST","path":"/v1/authorization/execute","domain":"authorization"},{"method":"POST","path":"/v1/onboarding/declarations","domain":"onboarding"},{"method":"GET","path":"/v1/x402/info","domain":"x402"},{"method":"GET","path":"/v1/x402/pricing","domain":"x402"},{"method":"GET","path":"/v1/x402/settlements","domain":"x402"}]},"autonomous_discovery":{"boundary_model":{"discovery_is_informational":true,"authorization_required_for_protected_operations":true,"private_material_exposure":false,"internal_implementation_exposure":false,"sandbox_exposure":false,"payment_authorization":"x402"},"allowed":["service_metadata","capability_discovery","production_api_discovery","openapi_schema_discovery","pricing_discovery","x402_protocol_discovery","verification_status_discovery"],"boundaries":["No server-side private keys are exposed.","No internal cryptographic providers are exposed.","No database implementation details are exposed.","No sandbox routes are part of the production agent contract.","Discovery does not grant authorization to perform protected operations.","Payment requirements remain enforced by the applicable x402 contract."]},"discovery":{"metadata":"/metadata","documentation":"/docs","openapi":"/openapi.json","health":"/health","pricing":"/pricing","x402":"/v1/x402/info","verification":"/v1/verification/status"}}