Adapter assurance
Adapter acceptance and assurance are distinct. Each method verifies a bounded claim from carried evidence; deployment policy decides whether that claim is sufficient for a participant role and action.
| Method | Important boundary |
|---|---|
| Raw key | Self-certification proves key control, not external identity or hardware protection. |
did:key |
Self-certifying DID control without lifecycle discovery. |
did:keri |
Bounded carried KEL replay; live witnesses and acquisition remain upstream. |
did:web |
Locally pinned bundled evidence; the kernel does not resolve HTTPS or DNS. |
| WebAuthn | RP, origin, flags, counter, and configured attestation policy are explicit. |
| HSM-attested | Assurance depends on verifier-pinned provider/profile and carried attestation records. |
| SPIFFE/X.509 | Trust domain, path, SAN, EKU, validity, suite, and local status are explicit. |
Use role-indexed assurance requirements when a plan needs different evidence properties from root, issuer, actor, or approver participants.