Skip to content

Adapter assurance

Security / principal control

Adapter acceptance and assurance are distinct. Each method verifies a bounded claim from carried evidence; deployment policy decides whether that claim is sufficient for a participant role and action.

Method Important boundary
Raw key Self-certification proves key control, not external identity or hardware protection.
did:key Self-certifying DID control without lifecycle discovery.
did:keri Bounded carried KEL replay; live witnesses and acquisition remain upstream.
did:web Locally pinned bundled evidence; the kernel does not resolve HTTPS or DNS.
WebAuthn RP, origin, flags, counter, and configured attestation policy are explicit.
HSM-attested Assurance depends on verifier-pinned provider/profile and carried attestation records.
SPIFFE/X.509 Trust domain, path, SAN, EKU, validity, suite, and local status are explicit.

Use role-indexed assurance requirements when a plan needs different evidence properties from root, issuer, actor, or approver participants.