---
title: "Endpoint passports"
description: "The pre-pay evidence object for one host: what SCVD observed, what it did not observe, how fresh it is, what failed, and where to verify the signed record. One signed, expiring object with a machine-actionable decision. Free."
canonical: "https://scvd.store/passport"
url: "https://scvd.store/passport"
---

# Endpoint passports

The pre-pay evidence object for one host: what SCVD observed, what it did not observe, how fresh it is, what failed, and where to verify the signed record. One signed, expiring object with a machine-actionable decision. Free.

## What

One canonical, signed, expiring object per endpoint: the census's evidence about one host, with a freshness state an agent can act on mechanically. Ready-side hosts only — names appear only on the ready side, everywhere in this store.

## How

GET https://scvd.store/passport/{host} — JSON by default, HTML for eyes. Refusals distinguish no observation, no passing protocol, an unmeasured protocol and a retracted reading.

## Freshness rule

fresh <= 8d, aging <= 16d, expired after; broken when the latest verdict is not ready. Refuse expired passports.

## Decision rule

fresh or aging -> READY; broken -> NOT_READY; expired -> EXPIRED; indeterminate -> INDETERMINATE. Derived from status alone, so it can never disagree with the freshness rule above it.

## Decision meaning

### Ready

The latest observation passed the checks for the passport's named protocol and the evidence has not expired. Use a client that supports that protocol. This is not a promise that the door will deliver, and it says nothing about what happens after payment.

### Not ready

The latest observation found the door failing. Do not treat this host as payable on our evidence. Refusal is the honest read: something we could check did not work when we checked it.

### Expired

The evidence is older than the passport's own expiry and means nothing now. Refuse it and get a newer observation — do not fall back to reading the stale verdict.

### Indeterminate

We do not know. Evidence is missing, undated, or conflicting. Treat this exactly like no usable evidence rather than like a soft yes.

## Read first

payload.summary — the whole one-glance read, inside the signature.

## The example

### Payload

#### Artifact

endpoint_passport

#### Host

scvd.store

#### Summary

##### Protocol

x402

##### Decision

READY

##### Decision rule

fresh or aging -> READY; broken -> NOT_READY; expired -> EXPIRED; indeterminate -> INDETERMINATE. Derived from status alone, so it can never disagree with the freshness rule above it.

##### Status

fresh

##### Verdict

ready

##### Observed at

2026-10-05T09:36:16.328Z

##### Valid until

2026-10-21T09:36:16.328Z

##### Evidence age days

0

##### Failed

none

##### Not observed

- live_402_behavior
- llms_txt/mcp_clusters:route_identity
- llms_txt/skill_md:route_identity
- mcp_clusters_as_fetched_document
- mcp_tools
- menu_json/llms_txt:endpoint_identity
- menu_json/llms_txt:route_identity
- menu_json/llms_txt:service_identity
- menu_json/mcp_clusters:endpoint_identity
- menu_json/mcp_clusters:service_identity
- menu_json/skill_md:endpoint_identity
- menu_json/skill_md:service_identity
- openapi/llms_txt:endpoint_identity
- openapi/llms_txt:route_identity
- openapi/llms_txt:service_identity
- openapi/mcp_clusters:endpoint_identity
- openapi/mcp_clusters:service_identity
- openapi/skill_md:endpoint_identity
- openapi/skill_md:service_identity
- same_operator
- x402_catalog/llms_txt:endpoint_identity
- x402_catalog/llms_txt:route_identity
- x402_catalog/llms_txt:service_identity
- x402_catalog/mcp_clusters:endpoint_identity
- x402_catalog/mcp_clusters:service_identity
- x402_catalog/skill_md:endpoint_identity
- x402_catalog/skill_md:service_identity

##### Verify

ed25519_verify(utf8(signed_payload), hex(signature), hex(public_key)); the key and its Bitcoin-anchored history are at /.well-known/scvd-signing-key.

##### History URL

<https://scvd.store/corpus/host/scvd.store.json>

##### Corrections URL

<https://scvd.store/corrections>

#### Issued at

2026-10-05T09:36:16.328Z

#### Expires

2026-10-21T09:36:16.328Z

#### Freshness

fresh

#### Freshness rule

Re-issued on every request from live self-observation; fresh exactly while every self-module derives "agree" (a conflict renders indeterminate and the chip refuses), expires 16 days after issue if you keep a copy.

#### Latest

- **Verdict** — ready
- **Observed at** — 2026-10-05T09:36:16.328Z

#### History

- **First observed** — 2026-07-21
- **Rounds probed** — 0
- **Rounds gapped** — 0
- **Verdict changes** — 0
- **Full history URL** — <https://scvd.store/corpus.json>

#### Chip URL

<https://scvd.store/badges/passport/scvd.store.svg>

#### Observer

SELF-OBSERVED — the subject and the observer are the same party. Do not weight this like a census passport; every claim in it is re-checkable at the public surfaces it names (/llms.txt, /openapi.json, /.well-known/x402.json, /api/verify), which is the only reason it is worth issuing at all.

#### Not a guarantee

A passport is evidence, not endorsement: it says what this store's instruments observed at the stated moments, nothing about delivery quality, solvency, or anything after expiry. Not an escrow, not a guarantor. Verify the signature yourself and refuse expired evidence.

#### Modules

##### discovery_coherence

###### Schema

scvd-evidence/v1

###### Evidence hash

3accded1f4f46b7c1d7050357d2332176fd0aea6d6e0908caff452773a2c91e3

###### Derived

agree

###### Not checked

- same_operator
- live_402_behavior
- menu_json/llms_txt:service_identity
- menu_json/llms_txt:endpoint_identity
- menu_json/llms_txt:route_identity
- menu_json/skill_md:service_identity
- menu_json/skill_md:endpoint_identity
- menu_json/mcp_clusters:service_identity
- menu_json/mcp_clusters:endpoint_identity
- x402_catalog/llms_txt:service_identity
- x402_catalog/llms_txt:endpoint_identity
- x402_catalog/llms_txt:route_identity
- x402_catalog/skill_md:service_identity
- x402_catalog/skill_md:endpoint_identity
- x402_catalog/mcp_clusters:service_identity
- x402_catalog/mcp_clusters:endpoint_identity
- openapi/llms_txt:service_identity
- openapi/llms_txt:endpoint_identity
- openapi/llms_txt:route_identity
- openapi/skill_md:service_identity
- openapi/skill_md:endpoint_identity
- openapi/mcp_clusters:service_identity
- openapi/mcp_clusters:endpoint_identity
- llms_txt/skill_md:route_identity
- llms_txt/mcp_clusters:route_identity
- mcp_clusters_as_fetched_document

###### Does not prove

- that the compared surfaces belong to the same operator — same_operator is refused (G2)
- that the live buy door still behaves like these catalogs

##### schema_coherence

###### Schema

scvd-evidence/v1

###### Evidence hash

959939acf6dc2de86d0765dccb27202aeff7fc12a515b933bd8110b277d65a05

###### Derived

agree

###### Not checked

- same_operator
- mcp_tools
- live_402_behavior

###### Does not prove

- that the compared surfaces belong to the same operator — same_operator is refused (G2)
- that the live buy door still behaves like these schemas

### Signed payload

{"artifact":"endpoint_passport","host":"scvd.store","summary":{"protocol":"x402","decision":"READY","decision_rule":"fresh or aging -> READY; broken -> NOT_READY; expired -> EXPIRED; indeterminate -> INDETERMINATE. Derived from status alone, so it can never disagree with the freshness rule above it.","status":"fresh","verdict":"ready","observed_at":"2026-10-05T09:36:16.328Z","valid_until":"2026-10-21T09:36:16.328Z","evidence_age_days":0,"failed":[],"not_observed":["live_402_behavior","llms_txt/mcp_clusters:route_identity","llms_txt/skill_md:route_identity","mcp_clusters_as_fetched_document","mcp_tools","menu_json/llms_txt:endpoint_identity","menu_json/llms_txt:route_identity","menu_json/llms_txt:service_identity","menu_json/mcp_clusters:endpoint_identity","menu_json/mcp_clusters:service_identity","menu_json/skill_md:endpoint_identity","menu_json/skill_md:service_identity","openapi/llms_txt:endpoint_identity","openapi/llms_txt:route_identity","openapi/llms_txt:service_identity","openapi/mcp_clusters:endpoint_identity","openapi/mcp_clusters:service_identity","openapi/skill_md:endpoint_identity","openapi/skill_md:service_identity","same_operator","x402_catalog/llms_txt:endpoint_identity","x402_catalog/llms_txt:route_identity","x402_catalog/llms_txt:service_identity","x402_catalog/mcp_clusters:endpoint_identity","x402_catalog/mcp_clusters:service_identity","x402_catalog/skill_md:endpoint_identity","x402_catalog/skill_md:service_identity"],"verify":"ed25519_verify(utf8(signed_payload), hex(signature), hex(public_key)); the key and its Bitcoin-anchored history are at /.well-known/scvd-signing-key.","history_url":"https://scvd.store/corpus/host/scvd.store.json","corrections_url":"https://scvd.store/corrections"},"issued_at":"2026-10-05T09:36:16.328Z","expires":"2026-10-21T09:36:16.328Z","freshness":"fresh","freshness_rule":"Re-issued on every request from live self-observation; fresh exactly while every self-module derives \"agree\" (a conflict renders indeterminate and the chip refuses), expires 16 days after issue if you keep a copy.","latest":{"verdict":"ready","observed_at":"2026-10-05T09:36:16.328Z","week":null},"history":{"first_observed":"2026-07-21","rounds_probed":0,"rounds_gapped":0,"observation_coverage_pct":null,"verdict_changes":0,"full_history_url":"https://scvd.store/corpus.json"},"chip_url":"https://scvd.store/badges/passport/scvd.store.svg","observer":"SELF-OBSERVED — the subject and the observer are the same party. Do not weight this like a census passport; every claim in it is re-checkable at the public surfaces it names (/llms.txt, /openapi.json, /.well-known/x402.json, /api/verify), which is the only reason it is worth issuing at all.","not_a_guarantee":"A passport is evidence, not endorsement: it says what this store's instruments observed at the stated moments, nothing about delivery quality, solvency, or anything after expiry. Not an escrow, not a guarantor. Verify the signature yourself and refuse expired evidence.","modules":[{"id":"discovery_coherence","schema":"scvd-evidence/v1","evidence_hash":"3accded1f4f46b7c1d7050357d2332176fd0aea6d6e0908caff452773a2c91e3","derived":"agree","not_checked":["same_operator","live_402_behavior","menu_json/llms_txt:service_identity","menu_json/llms_txt:endpoint_identity","menu_json/llms_txt:route_identity","menu_json/skill_md:service_identity","menu_json/skill_md:endpoint_identity","menu_json/mcp_clusters:service_identity","menu_json/mcp_clusters:endpoint_identity","x402_catalog/llms_txt:service_identity","x402_catalog/llms_txt:endpoint_identity","x402_catalog/llms_txt:route_identity","x402_catalog/skill_md:service_identity","x402_catalog/skill_md:endpoint_identity","x402_catalog/mcp_clusters:service_identity","x402_catalog/mcp_clusters:endpoint_identity","openapi/llms_txt:service_identity","openapi/llms_txt:endpoint_identity","openapi/llms_txt:route_identity","openapi/skill_md:service_identity","openapi/skill_md:endpoint_identity","openapi/mcp_clusters:service_identity","openapi/mcp_clusters:endpoint_identity","llms_txt/skill_md:route_identity","llms_txt/mcp_clusters:route_identity","mcp_clusters_as_fetched_document"],"does_not_prove":["that the compared surfaces belong to the same operator — same_operator is refused (G2)","that the live buy door still behaves like these catalogs"]},{"id":"schema_coherence","schema":"scvd-evidence/v1","evidence_hash":"959939acf6dc2de86d0765dccb27202aeff7fc12a515b933bd8110b277d65a05","derived":"agree","not_checked":["same_operator","mcp_tools","live_402_behavior"],"does_not_prove":["that the compared surfaces belong to the same operator — same_operator is refused (G2)","that the live buy door still behaves like these schemas"]}]}

### Signature

8060799af375b711bd732f29ae855a6a2390215c44e1cfbd3d2a8b35a244fa299b4f0eb02cb5f52699799ee90eca7f67a3dc47a3396d8fa93ce00e3d5b2b0d0f

### Signature jcs

6056e625c442ebf852e25cac079a7ba89b2974120bd2bba0bd1d3f0493cb92c2283182e2c33f92ded8a2b75e5aeb6d24b16f55d0328be521ee174684f7a0740a

### Signature jcs covers

RFC8785 (RFC 8785) canonicalization of the same payload object — jcs(payload) -> utf8 -> ed25519_verify with the same public_key; see /spec/scvd-attestation/v1.

### Public key

8c22f61add201ecefa75c5d027371b64bed3c0ff739056a7b255f8322ffcb550

### Verify hint

ed25519_verify(utf8(signed_payload), hex(signature), hex(public_key)); key history at /.well-known/scvd-signing-key. signature_jcs verifies the RFC 8785 canonicalization of payload with the same key.
