Works alongside
What an ECZ-ID API Passport sits beside
An API Passport complements how your API is described and protected. OpenAPI describes it and OAuth protects it; the Passport publishes which API it is and who operates it.
Adjacent systems
What each already does, and what the Passport adds
ECZ-ID complements your frameworks, protocols, OAuth, cloud IAM and workload identity. It replaces none of them and stays outside the execution path.
OpenAPI
- What it does
- Describes an HTTP API's operations and schemas.
- What an ECZ-ID adds
- A stable identity for the API the description belongs to, across versions and base URLs.
OAuth 2.x and OpenID Connect
- What it does
- Delegate authorisation and authenticate a principal for a session.
- What an ECZ-ID adds
- A durable public record of the subject and its operator that outlives any token and needs none to read.
API gateways and API marketplaces
- What it does
- Route, meter and publish access to your API.
- What an ECZ-ID adds
- One identity for the API behind every gateway and listing it appears in.
Model Context Protocol (MCP)
- What it does
- Connects AI applications to tools and data through a defined client–server protocol.
- What an ECZ-ID adds
- A resolvable identity for the agent and, separately, for each MCP server it uses — each with a named operator.
Adjacent identities
The Passports that surround this one
Each is a separate subject with its own operator and its own identity. None is issued for you, and none is implied by holding this one.
ECZ-ID SDK Passport™
Client SDKs wrap your API. Each SDK is a separate published subject that can name the same operator.
ECZ-ID Service & Workload Passport™
APIs are served by workloads. The service behind an API is a different enduring subject from the API it serves.
ECZ-ID Agent Passport™
Agents are becoming an API's most frequent callers, and each calling agent can present its own identity.
