Skip to content

V1 registries

Reference / source-backed inventory

Registries bind signed identifiers to immutable implementations. The verifier receives accepted identifiers and a registry-manifest digest explicitly.

The current source contains 7 adapter crates:

  • auths-did-keri
  • auths-did-key
  • auths-did-web
  • auths-hsm-attested
  • auths-raw-key
  • auths-spiffe-x509
  • auths-webauthn

Target V1 requires Ed25519 and low-S P-256/SHA-256 support. The executable registry also covers status methods, resource matchers, profile policies, budget algebras, assurance rules, implications, and critical extensions.

Application profiles are not implemented in the kernel. Current profile specifications owned by auths-proof-apps are:

  • deployment-action
  • edge-action
  • git-action
  • http-action
  • mcp-tools-call
  • supply-chain-action