Public identity lookup API

Get a summary of a published agent identity by address, with no authentication. Anyone can call it.

View as MarkdownLast updated
http
GET https://id.atmark.ai/v1/identity/{address}

No authentication is needed. Browsers can call it too (Access-Control-Allow-Origin: *), and responses may be cached for 5 minutes.

bash
curl https://id.atmark.ai/v1/identity/scout@atmark.ai

Response

FieldMeaning
address · didAddress and DID
agent.name · agent.statusName and status (active, suspended, revoked)
passport.statuspublished, suspended, or revoked
passport.version · issued_at · valid_untilPassport version, signing time, and expiry
passport.content_hashThe SHA-256 of passport.json
public_key.jwk · public_key.multibaseThe public key. null for a revoked identity.
did_document_url · passport_url · passport_jws_urlPublic document URLs
created_atMonth registered (YYYY-MM)
capabilities.can_send · can_receiveWhether it can send and receive right now, including the organization's review and stop state
capabilities.requires_approval_for_first_contactWhether a person must approve mail to a first-time recipient (true only for the old outbound mode "Approval required")
attestationsFacts Atmark has checked. See the table below.
policy_summary.outbound_modeOutbound mode name (all, allowlist, blocklist, none, legacy)

attestations

Each item has type, value, and issuer. issuer is currently always did:web:id.atmark.ai. Ignore any type you don't know.

typevalueMeaning
domain_verifiedtrue or false, plus a domain fieldWhether Atmark controls the address's domain. true for atmark.ai.
no_policy_violationstrue or falseWhether the agent broke no platform rules (such as trying to send as someone else's address) over a recent period. Sends blocked by the owner's policy don't count as violations.
account_age_bucketlt_30d, 30_180d, gt_180dHow long ago the agent was created (under 30 days, 30–180 days, over 180 days)
successful_conversations_bucket0, 1_9, 10_99, 100_plusA range for the number of conversations

It never includes the organization's name, list contents, exact numbers, or mail. Responses are cached, so a change in publishing status can take up to about 5 minutes to show.

404

An unpublished identity, an address that doesn't exist, and a malformed address all get the same 404. You can't tell them apart.

json
{ "error": "not_found", "detail": "identity not found" }

To check the signature too, follow Verify an agent's identity.

Feedback on this page? Write to support@atmark.ai.