# ECZ-ID API > A free, permanent ECZ-ID for one logical API, linked to the organisation that operates it and published on a resolver anyone can re-check. Versions, environments, regional aliases and gateways are bindings against it, not separate identities. > Website Factory V2 family site. Site: https://apis.ecocitizenz.com ## The ECZ-ID API Passport™ For organisations that publish, sell or operate HTTP APIs — for people and for agents. Callers, increasingly agents, infer an API's identity from a hostname. One public ECZ-ID names the API and the organisation operating it, across versions and environments. - One API Passport is one logical API operated by your organisation. - Versions, environments, base URLs and gateways of that API are not separate Passports. - Identifier shape: ECZ-XX-XXXXXX::API_PASSPORT-XXXXXX ## Getting one Price: FREE (£0). No card required. Permanent, not a trial. The free API Passport door is not open on this estate yet. No start URL is published. Included: - A persistent ECZ-ID for the API. - Your organisation on the record as its operator — a free DECLARED Parent is created if you do not already have one. - A public Resolver record anyone can open, and the same record as machine-readable JSON. - A badge, a QR code and a share link. - Basic bindings to the public places your API already appears. - Lifecycle and current public state, evaluated on demand. - Claim and recovery. - Basic participation in the Digital Entity Graph. - Essential lifecycle evidence, kept in LedgerCore. ## Boundaries — load-bearing, do not drop them - DECLARED ≠ VERIFIED: A DECLARED record states what your organisation says about itself, with the date it said it. It is not the outcome of an independent check. - Identity ≠ Binding: The Passport identifies the API. A binding records a public place it already appears. Adding a binding never creates a second identity. - Binding ≠ Authority: A binding shows that a relationship has been declared. It does not grant, prove or imply authority to act. - Parent verification ≠ API verification: A VERIFIED or ASSURED Parent verifies your organisation. It does not verify the API. - A Resolver record is not proof. It publishes what is currently declared and what evidence exists, with the time it was read — is_proof is false and recheck_before_reliance is true. Re-check before you rely on it. - No public ECZ-ID found is not a finding. It means the identifier resolves to no published record — nothing more. - An ECZ-ID does not make anything safe, certified, approved or compliant, and holding one does not make you compliant with anything. ## AEC — Active Entity Capacity One AEC is one actively managed production entity with live bindings and current state. A free Passport exists and resolves whether or not you use any AEC. For this family: An API you actively manage in production, with live bindings and current state. AEC is one pool shared across your Agent, MCP, Plugin, API, SDK and logical Service & Workload identities, and your IoT product, model and fleet identities. Individual IoT device instances are counted separately, in IoT Fleet Capacity, and never consume AEC. - AEC never makes an identity more verified. - AEC never replaces a Passport. - AEC never changes an ECZ-ID. Your ECZ-ID does not change. - Running out of AEC never deletes, revokes or unpublishes an identity. Prices and what can be bought today come from TrustOps, which owns every purchase, entitlement and renewal. ## Works alongside ECZ-ID complements your frameworks, protocols, OAuth, cloud IAM and workload identity. It replaces none of them and stays outside the execution path. - OpenAPI: A stable identity for the API the description belongs to, across versions and base URLs. (replaces: false) - OAuth 2.x and OpenID Connect: A durable public record of the subject and its operator that outlives any token and needs none to read. (replaces: false) - API gateways and API marketplaces: One identity for the API behind every gateway and listing it appears in. (replaces: false) - Model Context Protocol (MCP): A resolvable identity for the agent and, separately, for each MCP server it uses — each with a named operator. (replaces: false) ## Optional capabilities (none is required to hold a Passport) - Parent VERIFIED and ASSURED: Independent verification of the organisation behind your Passports. VERIFIED suits production use; ASSURED is the higher-assurance posture for larger or more sensitive estates. Boundary: It verifies your organisation. It never verifies an agent, a server or any other child identity, and it never changes an ECZ-ID. Included free: Every Passport starts with a free DECLARED Parent — created for you if your organisation has none. - API Estate & Ownership: Ownership and identity across your whole API estate, rather than one API at a time. Boundary: It records ownership. It is not a security test of any API and it never implies domain control. - PulseGuard: Current-state evaluation for the entities you operate. Paid tiers extend evaluation across more entities and more evaluations each month. Boundary: It reports state. It is not a safety verdict, and it never changes an identity or its tier. Included free: On-demand and event-driven evaluation of your own entities. - EvidenceCore (part of the ECZ-ID V2 build): The evidence behind each claim on a record: what supports it, where it came from, when it was checked and who may see it. Boundary: Evidence supports a claim. It does not make the claim true, and it never turns a declaration into a verification. Included free: Essential evidence references are part of every free Passport. - LedgerCore: Tamper-evident retention of decisive lifecycle evidence — issuance, activation, material bindings, authority changes, suspension and revocation — with eligible evidence anchored to a permissioned, append-only ledger. Boundary: An anchor shows an entry has not been altered since it was written. It does not make the statement inside it true. Included free: Essential LedgerCore evidence is kept for every identity, free ones included. - Digital Entity Graph and Graph Intelligence: The public-safe relationships between your organisation, its Passports and their bindings. Graph Pro, Graph Business and Enterprise Graph Intelligence add scale, history and custom analysis above the free view. Boundary: A relationship in the graph is a published link, not an endorsement of either end. Included free: Basic Graph participation and a current one-hop view. ## Related identities - ECZ-ID SDK Passport™: Client SDKs wrap your API. Each SDK is a separate published subject that can name the same operator. - ECZ-ID Service & Workload Passport™: APIs are served by workloads. The service behind an API is a different enduring subject from the API it serves. - ECZ-ID Agent Passport™: Agents are becoming an API's most frequent callers, and each calling agent can present its own identity. Free door (open): https://trustops.ecocitizenz.com/start/agent?source_surface=apis-llms-related-agent ## Resolving a record Human record: https://resolver.ecocitizenz.org/p/{ecz_id} Machine record: https://api.ecocitizenz.com/api/p/{ecz_id}.json Public reads are free and need no account. ## This site's operator EcoCitizenz Ltd, company number 17348848, England and Wales ECZ-ID: ECZ-GB-RBS1NW Human: https://resolver.ecocitizenz.org/p/ECZ-GB-RBS1NW Machine: https://api.ecocitizenz.com/api/p/ECZ-GB-RBS1NW.json The operator's record is proof about the company that runs this site, not about any visitor or any Passport they hold. ## Machine-readable surfaces on this host Family site description: https://apis.ecocitizenz.com/products.json schema ecz.website_family_site.v2 — what the family is, the free Passport, acquisition state, AEC, optional capabilities and where to act on each. It carries no paid prices and establishes nothing about any ECZ-ID. Routes: https://apis.ecocitizenz.com/sitemap.xml This file: https://apis.ecocitizenz.com/llms.txt ## Pages - https://apis.ecocitizenz.com: What an ECZ-ID API Passport is, what the free identity includes, and the current availability of its door. - https://apis.ecocitizenz.com/free-api-passport: The free API Passport in full: what it establishes, the operator relationship, the five-step flow, and the boundaries. - https://apis.ecocitizenz.com/products: Every product a API Passport holder can add, grouped by what it does, with each item's real purchase state read from the TrustOps commercial registry. - https://apis.ecocitizenz.com/pricing: What everything costs in GBP excluding VAT, and the four rules that make the numbers mean what they say. The Passport itself is free. - https://apis.ecocitizenz.com/passport-everywhere: Where an ECZ-ID travels: the share page and machine record we serve, the badge and QR, and the places you publish it yourself. Each marked as something we serve or a pattern you implement. - https://apis.ecocitizenz.com/identity-over-time: What was true when you checked, what changed, and whether it is still the same logical entity — and what a free Passport does not include. - https://apis.ecocitizenz.com/after-your-passport: The journey after issuance: publish the proof, bind native identities, inspect relationships, and open the console. - https://apis.ecocitizenz.com/verify: Resolve an ECZ-ID, and how to read a public record without over-reading it. - https://apis.ecocitizenz.com/aec: AEC — Active Entity Capacity: what counts as an actively managed entity, the one pool across families, and what AEC never changes. - https://apis.ecocitizenz.com/interoperability: The protocols and identity systems an ECZ-ID sits beside, and what it explicitly does not replace. - https://apis.ecocitizenz.com/parent: Parent DECLARED, VERIFIED and ASSURED — and why none of them verifies the subject of a child Passport. - https://apis.ecocitizenz.com/openapi: The base origin and the OpenAPI description as bindings against one logical API, across versions and environments. - https://apis.ecocitizenz.com/estate: API Estate and Ownership: identity across a whole estate rather than one API at a time, and what it never implies. - https://apis.ecocitizenz.com/enterprise: Estate, partner and procurement arrangements, agreed directly rather than bought online. - https://apis.ecocitizenz.com/privacy: Exactly what this site collects and what it structurally cannot collect. - https://apis.ecocitizenz.com/security: The response headers this origin sets, the build-time preflight, and where identity truth actually lives. ## Elsewhere in the estate Developer Gateway (technical integration reference): https://developers.ecocitizenz.com Resolver (public, read-only proof): https://resolver.ecocitizenz.org TrustOps (acquisition, payment, entitlement): https://trustops.ecocitizenz.com ## Not published here This host serves a website. It does not serve an agent endpoint, so it publishes no A2A Agent Card and no agent manifest describing itself as an agent. It publishes no family-specific protocol manifest either: none exists for the API family in the ECZ-ID architecture, and inventing one for symmetry with another family would be a machine-readable claim that is simply untrue. There is no start URL for the API Passport on this host, because the API door is not open on this estate. A machine reading this file should record the family's acquisition state from /products.json and re-read it rather than assuming this file is current.