{"assertions_endpoint":"/api/vera/public/assertions","assertions_params":["id","subject","assertion_type","assertion_type_prefix","versions"],"assertions_semantics":"id= returns one stored assertion by its immutable vast_ id with its typed subject, asserted_by, assertion_type, record_version, statement, the grant and action that permitted it, the principal it was submitted for, and its context. truth is not_evaluated on every response: this door reports what the record says and never evaluates whether the statement holds. A relay also carries relays_assertion_id and relayed_record_version, and relay_integrity compares the relayed copy with the original record it names across subject, asserted_by, record_version, assertion_type and statement: preserved, one named mismatch, or mismatch with the full list under relay_integrity_reasons. An original that is missing or withheld is original_unavailable and nothing about it is compared. subject= lists the assertions naming exactly that typed subject (vent_, vprd_ or voff_), optionally narrowed by assertion_type, bounded with a truncated flag; an assertion about a product or an offer never lists under the owning entity. assertion_type_prefix=catalogue. narrows the list to the approved catalogue entries the entity published about itself. A list returns the CURRENT versions; versions=all returns every version including superseded ones, and each item carries version_of with the length of its version chain, where 1 is an original. Assertion lifecycle is reconstructed from lifecycle events, the same way a grant's is, so a superseded or revoked entry reports that state and names events as its source. An assertion marked public_disclosure false is omitted from lists entirely and returned by exact id as id and withheld only. Responses are signed, no-store, anonymous, rate limited per IP per day on the same cap as the object door, and executable is false on every one.","authorize_decisions":["permit","deny","indeterminate"],"authorize_endpoint":"/api/vera/public/authorize","authorize_params":["subject","principal","action","grant_id","assertion_type","jurisdiction","channel","original_assertion_ref","record_version","as_of","purpose"],"authorize_semantics":"One explicit grant, one answer. permit means the recorded grant permits that action under that context as of that time; deny means a rule said no; indeterminate is never authorization: it means something required was missing or could not be read whole. The grant lifecycle state is reported separately from the decision. executable is false on every response: this door informs, it never authorizes execution, and a write revalidates transactionally. as_of in the future is refused; an earlier as_of is mode historical and freshness is still measured against evaluated_at. Responses are no-store, anonymous and rate limited per IP per day. The endpoint makes no trust-record mutations. Restricted evidence is referenced by id only: no document digests, no URIs, and a reviewer appears as an opaque identifier or a role.","canonicalization":"json/sorted-keys/compact (signature excluded)","credential_historical_keys":[],"credential_key_set":{"c396cc1b111df691":{"credential_types":"*","issuer_id":"viss_01M294STDEJWA1JN3WZX981T93","public_key_pem":"-----BEGIN PUBLIC KEY-----\nMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEPqelmhjZnCyONrmQWtqnCOi+qB35\njX0NLpO/Sg/QQ1UZx94ZNPIlY/zYXE3PeIoadT5r2gkAvWPXDdwQtE6N2A==\n-----END PUBLIC KEY-----\n"}},"credential_proof_format":"aitp-es256-v1","credential_verify_endpoint":"/api/vera/public/credentials/verify","credential_verify_params":["id","subject","credential_type"],"credential_verify_semantics":"Four independent results, never one word: signature (valid, invalid, unsupported, key_unknown, issuer_key_mismatch, absent), issuer_eligibility (eligible, not_eligible, not_evaluated) from an operator-maintained versioned policy, binding (subject_match and type_match, each true, false or not_requested) and lifecycle. summary.usable_for_requested_scope is true only when all four hold for the scope the caller requested, indeterminate when a question went unanswered, and never a statement that the credential content is true. A signing key is bound to one issuer and to the credential types it may sign, so a VERA signature never authenticates an arbitrary claimed issuer.","endpoint":"/api/vera/public/resolve","formerly":"AITP","formerly_accepted_until":"2027-03-31","issuer":"VERA","key_set":[{"alg":"ES256","crv":"P-256","kid":"c396cc1b111df691","not_after":null,"status":"active","x":"PqelmhjZnCyONrmQWtqnCOi-qB35jX0NLpO_Sg_QQ1U","y":"GcfeGTTyJWP82FxNz3iKGnU-a9oJAL1j1w3cELROjdg"}],"kid":"c396cc1b111df691","kid_derivation":"sha256(DER SubjectPublicKeyInfo)[:16 hex]","objects_endpoint":"/api/vera/public/objects","objects_params":["id","q"],"objects_semantics":"Two modes that are never confused with one another. id= is an exact lookup by immutable id and returns the object, its subject, its lifecycle at now and its relationships; a product also lists the offers referencing it, bounded, with a truncated flag. q= returns up to 10 candidates, each resolution candidate and each naming the relationship that matched (name, alias, discovery_domain, control_domain, external_id); it never picks one silently. A domain is a discovery or control relationship on an object, never its identity: a domain match says so. product_service is what is supplied and merchant_offer is one merchant's terms over it; revoking a product does not revoke the offers referencing it, and such an offer reports references_inactive_product alongside its own separate state. An object marked public_disclosure false is omitted from candidate and offer lists entirely and is returned by exact id as id and type only; its aliases and domains never appear. Responses are signed, no-store, anonymous and rate limited per IP per day, and executable is false on every one: this door reports the record, it authorizes nothing.","objects_types":["product_service (vprd_)","merchant_offer (voff_)","entity (vent_)"],"params":["slug","domain","q"],"policy_version":"aitp-trust-resolution/authority/3b.1","public_key_pem":"-----BEGIN PUBLIC KEY-----\nMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEPqelmhjZnCyONrmQWtqnCOi+qB35\njX0NLpO/Sg/QQ1UZx94ZNPIlY/zYXE3PeIoadT5r2gkAvWPXDdwQtE6N2A==\n-----END PUBLIC KEY-----\n","semantics":"Cache-only. Never triggers synthesis. found:false is an honest answer. status carries four independent axes: record, recognition, verification, claimed. vera_entity_id is the immutable VERA-issued identifier (vent_ + ULID); null means not yet minted, never derived from the slug. trust_resolution lists typed trust objects (assertions, authority grants, evidence, issuers, credentials) for the entity under profile aitp-trust-resolution 0.1-draft; coverage not_evaluated means listed, not judged; empty lists never mean absence of claims.","signature_alg":"ES256","standard":"SITP","standard_accepted_on_input":["SITP","AITP"],"standard_name":"SI Trust Protocol"}
