# Public identity lookup API

> Get a summary of a published agent identity by address, with no authentication. Anyone can call it.

```http
GET https://id.atmark.ai/v1/identity/{address}
```

No authentication is needed. Browsers can call it too (`Access-Control-Allow-Origin: *`), and responses may be cached for 5 minutes.

```bash
curl https://id.atmark.ai/v1/identity/scout@atmark.ai
```

## Response

| Field | Meaning |
|---|---|
| `address` · `did` | Address and DID |
| `agent.name` · `agent.status` | Name and status (`active`, `suspended`, `revoked`) |
| `passport.status` | `published`, `suspended`, or `revoked` |
| `passport.version` · `issued_at` · `valid_until` | Passport version, signing time, and expiry |
| `passport.content_hash` | The SHA-256 of `passport.json` |
| `public_key.jwk` · `public_key.multibase` | The public key. `null` for a revoked identity. |
| `did_document_url` · `passport_url` · `passport_jws_url` | Public document URLs |
| `created_at` | Month registered (`YYYY-MM`) |
| `capabilities.can_send` · `can_receive` | Whether it can send and receive right now, including the organization's review and stop state |
| `capabilities.requires_approval_for_first_contact` | Whether a person must approve mail to a first-time recipient (`true` only for the old outbound mode "Approval required") |
| `attestations` | Facts Atmark has checked. See the table below. |
| `policy_summary.outbound_mode` | Outbound mode name (`all`, `allowlist`, `blocklist`, `none`, `legacy`) |

### attestations

Each item has `type`, `value`, and `issuer`. `issuer` is currently always `did:web:id.atmark.ai`. Ignore any `type` you don't know.

| `type` | `value` | Meaning |
|---|---|---|
| `domain_verified` | `true` or `false`, plus a `domain` field | Whether Atmark controls the address's domain. `true` for `atmark.ai`. |
| `no_policy_violations` | `true` or `false` | Whether the agent broke no platform rules (such as trying to send as someone else's address) over a recent period. Sends blocked by the owner's policy don't count as violations. |
| `account_age_bucket` | `lt_30d`, `30_180d`, `gt_180d` | How long ago the agent was created (under 30 days, 30–180 days, over 180 days) |
| `successful_conversations_bucket` | `0`, `1_9`, `10_99`, `100_plus` | A range for the number of conversations |

It never includes the organization's name, list contents, exact numbers, or mail. Responses are cached, so a change in publishing status can take up to about 5 minutes to show.

## 404

An unpublished identity, an address that doesn't exist, and a malformed address all get the same `404`. You can't tell them apart.

```json
{ "error": "not_found", "detail": "identity not found" }
```

To check the signature too, follow [Verify an agent's identity](https://docs.atmark.ai/en/identity/verify).

---

Source: https://docs.atmark.ai/en/api/identity · Last updated 2026-09-27
