Included free · Public proof · ECZ-ID API
Resolver
Public, read-only proof of identity for your API, for anyone who asks.
The Resolver publishes the current record behind an ECZ-ID — who operates the API, what is bound to it, its current state and the evidence that exists — to people and software alike, with no account and no key.
- Type
- Included free
- Price
- £0 — included with every free Passport
- Acquired and paid in
- TrustOps
- Operated in · proved by
- Dashboard · Resolver
The problem
Why it matters.
Your API is judged by people and programs that cannot see inside your organisation. Without a public record they infer the operator from a hostname, take an API marketplace or gateway entry on trust, or send you another questionnaire.
Built for
- Customers and partners deciding whether to integrate your API.
- Security and procurement reviewers who need a record, not a screenshot of a developer portal.
- Agents and tools that must identify an API before they call it.
What changes
- A single public place where the identity can be checked.
- Fewer identity questions answered by hand.
- A record that says when it was read and how to re-check it.
What you receive
Concrete deliverables, not a vague trust score.
- A public Resolver page for every published Passport.
- The same record as machine-readable JSON.
- Current state, operator, bindings and evidence presence.
- For each verified binding, its proof method, when it was last verified and when a re-check is due.
- The guard fields is_proof: false and recheck_before_reliance: true.
- ECZ-ID
- ECZ-XX-XXXXXX::
API_PASSPORT-XXXXXX - Operator
- Your organisation, with its Parent tier
- State
- Current lifecycle state, as last read
- Bindings
- Public places where the API appears, each declared or verified
- Last verified
- YYYY-MM-DD, for each verified binding
- Re-check due
- YYYY-MM-DD
- Guards
- is_proof: false · recheck_before_reliance: true
Illustrative structure with placeholder values. The live record is always the Resolver's. Re-check before reliance.
How it works
A short path from need to something usable.
Your Passport is issued in TrustOps and written by ECZ-ID Core.
You consent to publication; nothing is public before that.
The Resolver projects the current record, read-only.
Anyone resolves it — by page, JSON, badge or QR — and re-checks before relying on it.
How it relates to your Passport
Core writes the canonical record; the Resolver projects it. TrustOps and the Dashboard change what you hold and operate; only Core changes what the Resolver shows.
Use cases
- A customer's security reviewer resolving the API named in a contract before approving the integration.
- An agent resolving the API's record before its first call, and honouring recheck_before_reliance.
- A partner following the badge on your developer portal to the current record.
Price
Included free, with every Passport.
£0. It is part of the free API Passport — permanent, not a trial, and no card is required.
After you take it
TrustOps acquires
Take the free Passport in TrustOps; your organisation's ECZ-ID Business Passport — Declared — FREE is reused or created.
Dashboard operates
Operate it in the Dashboard: publish, bind and copy your proof links.
Resolver proves
Anyone resolves the current record on the Resolver.
Privacy, security and evidence
What is collected, published and kept.
- Publication requires your explicit consent, and you can withdraw it.
- Only public-safe fields are projected.
- Absence is neutral: no public record is not a finding.
Boundaries
The claims stop here.
- The Resolver is public, read-only proof of what is currently declared and verified, with the time it was read. A record is not a verdict — is_proof is false and recheck_before_reliance is true. Re-check before reliance.
- The Resolver is read-only. It never edits, issues or approves anything.
- A binding is verified as of its Last verified time, and the record shows its Freshness. ECZ-ID does not renew a bound binding: once its proof method's freshness window has passed, the result is history and a new binding is the fresh proof. Re-check before reliance.
Integrations and questions
Works with what you already run.
- Machine-readable JSON with no authentication in front of it.
- Badge, QR and share links that land on the record.
- The Developer Gateway, for resolving from your own code.
- Does a Resolver record prove my claims about the API?
- No. The Resolver is public, read-only proof of what is currently declared and verified, with the time it was read. A record is not a verdict, and a DECLARED statement stays your organisation's own. Re-check before reliance.
- Does the Resolver sit in my API's call path?
- No. Your API never calls it and your callers' requests never pass through it. It is read when someone chooses to check.
- Is it really free?
- Yes. Every free API Passport gets a public Resolver record, as a page and as JSON.
- Can I take a record down?
- Publication is your decision, and you can withdraw it.
Related
- Included free · Share proofBadge, QR and share proofPut a route to current proof wherever people already meet you.Read more
- Included free · For softwareMachine-readable identityThe same record, as JSON any program can read.Read more
- Included free · One identity, many placesBindingsEvery place your API appears, tied to one identity.Read more
Start with a free API Passport.
£0 · No card required · Permanent, not a trial.
