Skip to content
ECZ-IDAPI

Included free · Public proof · ECZ-ID API

Resolver

Public, read-only proof of identity for your API, for anyone who asks.

The Resolver publishes the current record behind an ECZ-ID — who operates the API, what is bound to it, its current state and the evidence that exists — to people and software alike, with no account and no key.

Type
Included free
Price
£0 — included with every free Passport
Acquired and paid in
TrustOps
Operated in · proved by
Dashboard · Resolver

The problem

Why it matters.

Your API is judged by people and programs that cannot see inside your organisation. Without a public record they infer the operator from a hostname, take an API marketplace or gateway entry on trust, or send you another questionnaire.

Built for

  • Customers and partners deciding whether to integrate your API.
  • Security and procurement reviewers who need a record, not a screenshot of a developer portal.
  • Agents and tools that must identify an API before they call it.

What changes

  • A single public place where the identity can be checked.
  • Fewer identity questions answered by hand.
  • A record that says when it was read and how to re-check it.

What you receive

Concrete deliverables, not a vague trust score.

  • A public Resolver page for every published Passport.
  • The same record as machine-readable JSON.
  • Current state, operator, bindings and evidence presence.
  • For each verified binding, its proof method, when it was last verified and when a re-check is due.
  • The guard fields is_proof: false and recheck_before_reliance: true.
A Resolver record
ECZ-ID
ECZ-XX-XXXXXX::API_PASSPORT-XXXXXX
Operator
Your organisation, with its Parent tier
State
Current lifecycle state, as last read
Bindings
Public places where the API appears, each declared or verified
Last verified
YYYY-MM-DD, for each verified binding
Re-check due
YYYY-MM-DD
Guards
is_proof: false · recheck_before_reliance: true

Illustrative structure with placeholder values. The live record is always the Resolver's. Re-check before reliance.

How it works

A short path from need to something usable.

  1. Your Passport is issued in TrustOps and written by ECZ-ID Core.

  2. You consent to publication; nothing is public before that.

  3. The Resolver projects the current record, read-only.

  4. Anyone resolves it — by page, JSON, badge or QR — and re-checks before relying on it.

How it relates to your Passport

Core writes the canonical record; the Resolver projects it. TrustOps and the Dashboard change what you hold and operate; only Core changes what the Resolver shows.

Use cases

  • A customer's security reviewer resolving the API named in a contract before approving the integration.
  • An agent resolving the API's record before its first call, and honouring recheck_before_reliance.
  • A partner following the badge on your developer portal to the current record.

Price

Included free, with every Passport.

£0. It is part of the free API Passport — permanent, not a trial, and no card is required.

After you take it

  1. TrustOps acquires

    Take the free Passport in TrustOps; your organisation's ECZ-ID Business Passport — Declared — FREE is reused or created.

  2. Dashboard operates

    Operate it in the Dashboard: publish, bind and copy your proof links.

  3. Resolver proves

    Anyone resolves the current record on the Resolver.

Privacy, security and evidence

What is collected, published and kept.

  • Publication requires your explicit consent, and you can withdraw it.
  • Only public-safe fields are projected.
  • Absence is neutral: no public record is not a finding.

Boundaries

The claims stop here.

  • The Resolver is public, read-only proof of what is currently declared and verified, with the time it was read. A record is not a verdict — is_proof is false and recheck_before_reliance is true. Re-check before reliance.
  • The Resolver is read-only. It never edits, issues or approves anything.
  • A binding is verified as of its Last verified time, and the record shows its Freshness. ECZ-ID does not renew a bound binding: once its proof method's freshness window has passed, the result is history and a new binding is the fresh proof. Re-check before reliance.

Integrations and questions

Works with what you already run.

  • Machine-readable JSON with no authentication in front of it.
  • Badge, QR and share links that land on the record.
  • The Developer Gateway, for resolving from your own code.
Does a Resolver record prove my claims about the API?
No. The Resolver is public, read-only proof of what is currently declared and verified, with the time it was read. A record is not a verdict, and a DECLARED statement stays your organisation's own. Re-check before reliance.
Does the Resolver sit in my API's call path?
No. Your API never calls it and your callers' requests never pass through it. It is read when someone chooses to check.
Is it really free?
Yes. Every free API Passport gets a public Resolver record, as a page and as JSON.
Can I take a record down?
Publication is your decision, and you can withdraw it.