# ECZ-ID Agent > A free, permanent ECZ-ID for one logical AI agent, linked to the organisation > that operates it and published on a public resolver anyone can re-check. > Website Factory V2 reference family site. Site: https://agents.ecocitizenz.com ## The ECZ-ID Agent Passport™ For organisations that build, deploy or operate AI agents. When your agent turns up in a log, a marketplace or another company's systems, one public ECZ-ID says which agent it is and which organisation operates it — and anyone can re-check it on the Resolver. - One Agent Passport is one logical AI agent operated by your organisation. - Versions, deployments, replicas, regions and platforms of that agent are not separate Passports. - Identifier shape: ECZ-XX-XXXXXX::AGENT_PASSPORT-XXXXXX ## Getting one Price: FREE (£0). No card required. Permanent, not a trial. Free Agent Passport (open): https://trustops.ecocitizenz.com/start/agent?source_surface=agents-llms Included: - A persistent ECZ-ID for the AI agent. - Your organisation on the record as its operator — a free DECLARED Parent is created if you do not already have one. - A public Resolver record anyone can open, and the same record as machine-readable JSON. - A badge, a QR code and a share link. - Basic bindings to the public places your AI agent already appears. - Lifecycle and current public state, evaluated on demand. - Claim and recovery. - Basic participation in the Digital Entity Graph. - Essential lifecycle evidence, kept in LedgerCore. ## Boundaries — load-bearing, do not drop them - DECLARED ≠ VERIFIED: A DECLARED record states what your organisation says about itself, with the date it said it. It is not the outcome of an independent check. - Identity ≠ Binding: The Passport identifies the AI agent. A binding records a public place it already appears. Adding a binding never creates a second identity. - Binding ≠ Authority: A binding shows that a relationship has been declared. It does not grant, prove or imply authority to act. - Parent verification ≠ Agent verification: A VERIFIED or ASSURED Parent verifies your organisation. It does not verify the AI agent. - A Resolver record is not proof. It publishes what is currently declared and what evidence exists, with the time it was read — is_proof is false and recheck_before_reliance is true. Re-check before you rely on it. - No public ECZ-ID found is not a finding. It means the identifier resolves to no published record — nothing more. - An ECZ-ID does not make anything safe, certified, approved or compliant, and holding one does not make you compliant with anything. ## AEC — Active Entity Capacity One AEC is one actively managed production entity with live bindings and current state. A free Passport exists and resolves whether or not you use any AEC. For this family: An agent you actively manage in production, with live bindings and current state. AEC is one pool shared across your Agent, MCP, Plugin, API, SDK and logical Service & Workload identities, and your IoT product, model and fleet identities. Individual IoT device instances are counted separately, in IoT Fleet Capacity, and never consume AEC. - AEC never makes an identity more verified. - AEC never replaces a Passport. - AEC never changes an ECZ-ID. Your ECZ-ID does not change. - Running out of AEC never deletes, revokes or unpublishes an identity. Prices and what can be bought today come from TrustOps, which owns every purchase, entitlement and renewal. ## Works alongside ECZ-ID complements your frameworks, protocols, OAuth, cloud IAM and workload identity. It replaces none of them and stays outside the execution path. - Model Context Protocol (MCP): A resolvable identity for the agent and, separately, for each MCP server it uses — each with a named operator. (replaces: false) - Agent2Agent (A2A): A persistent public identity a counterparty agent can resolve and re-check outside the conversation itself. (replaces: false) - OAuth 2.x and OpenID Connect: A durable public record of the subject and its operator that outlives any token and needs none to read. (replaces: false) - Microsoft Entra Agent ID and workload identities: An identity that resolves outside the tenant, for parties with no access to it. (replaces: false) - AWS IAM: A public identity a counterparty can read without any access to your accounts. (replaces: false) - Google Cloud IAM and workload identity federation: A public identity readable outside your projects, naming the organisation that operates the subject. (replaces: false) - SPIFFE and SPIRE: A stable public identifier for the enduring service, rather than a rotating internal one for a running process. (replaces: false) ## Optional capabilities (none is required to hold a Passport) - Parent VERIFIED and ASSURED: Independent verification of the organisation behind your Passports. VERIFIED suits production use; ASSURED is the higher-assurance posture for larger or more sensitive estates. Boundary: It verifies your organisation. It never verifies an agent, a server or any other child identity, and it never changes an ECZ-ID. Included free: Every Passport starts with a free DECLARED Parent — created for you if your organisation has none. - KYA Authority: Know-Your-Agent authority for the agents you govern — the authority and delegation layer that sits above an agent's identity, kept separate from it. Boundary: Authority is not approval. It never makes an agent verified, and a Passport or a binding never carries authority on its own. - PulseGuard: Current-state evaluation for the entities you operate. Paid tiers extend evaluation across more entities and more evaluations each month. Boundary: It reports state. It is not a safety verdict, and it never changes an identity or its tier. Included free: On-demand and event-driven evaluation of your own entities. - EvidenceCore (part of the ECZ-ID V2 build): The evidence behind each claim on a record: what supports it, where it came from, when it was checked and who may see it. Boundary: Evidence supports a claim. It does not make the claim true, and it never turns a declaration into a verification. Included free: Essential evidence references are part of every free Passport. - LedgerCore: Tamper-evident retention of decisive lifecycle evidence — issuance, activation, material bindings, authority changes, suspension and revocation — with eligible evidence anchored to a permissioned, append-only ledger. Boundary: An anchor shows an entry has not been altered since it was written. It does not make the statement inside it true. Included free: Essential LedgerCore evidence is kept for every identity, free ones included. - Digital Entity Graph and Graph Intelligence: The public-safe relationships between your organisation, its Passports and their bindings. Graph Pro, Graph Business and Enterprise Graph Intelligence add scale, history and custom analysis above the free view. Boundary: A relationship in the graph is a published link, not an endorsement of either end. Included free: Basic Graph participation and a current one-hop view. - Agent Trust: A local-first editor extension that inventories the agents in your workspace and what they can reach. Pro adds the authority graph, action chains and remediation. Boundary: It inspects your workspace on your machine and publishes nothing about your agents. Included free: Agent Trust Community is free to install. ## Related identities - ECZ-ID MCP Passport™: Agents call MCP servers for tools and data. The server is its own subject, with its own operator and its own Passport. Free door (open): https://trustops.ecocitizenz.com/start/mcp?source_surface=agents-llms-related-mcp - ECZ-ID API Passport™: Agents act through APIs. An API Passport identifies the surface an agent calls, separately from the agent calling it. - ECZ-ID Plugin Passport™: Agents ship as, or inside, plugins and extensions. The plugin is identified once, across every store it is listed in. - ECZ-ID Service & Workload Passport™: Agents run as services and workloads. The workload that hosts an agent is a different enduring subject from the agent. ## Resolving a record Human record: https://resolver.ecocitizenz.org/p/{ecz_id} Machine record: https://api.ecocitizenz.com/api/p/{ecz_id}.json Public reads are free and need no account. ## This site's operator EcoCitizenz Ltd, company number 17348848, England and Wales ECZ-ID: ECZ-GB-RBS1NW Human: https://resolver.ecocitizenz.org/p/ECZ-GB-RBS1NW Machine: https://api.ecocitizenz.com/api/p/ECZ-GB-RBS1NW.json The operator's record is proof about the company that runs this site, not about any visitor or any Passport they hold. ## Evidence and the ledger Eligible evidence for an identity is anchored to Microsoft Azure Confidential Ledger ("ecozledger"), a permissioned, append-only ledger built on blockchain technology. - No cryptocurrency, no token and no wallet. Nothing here is tradeable and nothing is minted. - No public chain. The ledger is permissioned and operated in Microsoft Azure; it is not a decentralised network and this is not a decentralisation claim. - Not every event. Eligible evidence is anchored — the record says which, per identity, and a record that carries no anchor is not a fault. - An anchor proves an entry has not been altered since it was written. It does not make the statement inside that entry true, and it is not a verdict about any agent. - Receipts are written and counted today. Public retrieval of an individual receipt is not open yet, so this page does not offer a link to fetch one. ## Machine-readable surfaces on this host Family site description: https://agents.ecocitizenz.com/products.json schema ecz.website_family_site.v2 — what the family is, the free Passport, acquisition state, AEC, optional capabilities and where to act on each. It carries no paid prices and establishes nothing about any ECZ-ID. Routes: https://agents.ecocitizenz.com/sitemap.xml This file: https://agents.ecocitizenz.com/llms.txt ## Pages - https://agents.ecocitizenz.com: What an ECZ-ID Agent Passport is, what the free tier includes, and how to get one. - https://agents.ecocitizenz.com/free-agent-passport: The free Agent Passport in full: inclusions, the operator relationship, the four-step flow, and the boundaries. - https://agents.ecocitizenz.com/products: Every product an Agent Passport holder can add, grouped by what it does, with each item's real purchase state read from the TrustOps commercial registry. - https://agents.ecocitizenz.com/pricing: What everything costs in GBP excluding VAT, and the four rules that make the numbers mean what they say. The Passport itself is free. - https://agents.ecocitizenz.com/developers: The two integration paths, a live machine record to fetch, and the handoff to the Developer Gateway for the full technical reference. - https://agents.ecocitizenz.com/passport-everywhere: Where an ECZ-ID travels: the share page and machine record we serve, the badge and QR, and the places you publish it yourself — README, repository, package metadata, deployment manifest. Each marked as something we serve or a pattern you implement. - https://agents.ecocitizenz.com/identity-over-time: What was true when you checked, what changed, and whether it is still the same logical entity. What the Passport records, the Graph relates, PulseGuard revalidates and LedgerCore preserves — and what a free Passport does not include. - https://agents.ecocitizenz.com/after-your-passport: The journey after issuance: publish the proof, bind native identities, inspect relationships, identify genuinely separate adjacent subjects, open the console, and add capacity only if the estate needs it. - https://agents.ecocitizenz.com/verify: Resolve an ECZ-ID, and how to read a public record without over-reading it. - https://agents.ecocitizenz.com/frameworks: How agent identity is published from any framework, without a library or a change to the execution path. - https://agents.ecocitizenz.com/frameworks/openai: Publishing an ECZ-ID for an agent built on OpenAI Agents. - https://agents.ecocitizenz.com/frameworks/microsoft-agent-framework: Publishing an ECZ-ID alongside Entra Agent ID and Entra workload identity. - https://agents.ecocitizenz.com/frameworks/google-adk: Publishing an ECZ-ID for an agent built on the Google Agent Development Kit. - https://agents.ecocitizenz.com/frameworks/aws-strands: Publishing an ECZ-ID for an agent built on AWS Strands Agents, alongside IAM. - https://agents.ecocitizenz.com/frameworks/langgraph: Publishing an ECZ-ID for a LangGraph agent, and why nodes are not separate identities. - https://agents.ecocitizenz.com/mcp: Agents and MCP servers as separate subjects with separate operators, and the free MCP Passport. - https://agents.ecocitizenz.com/github: Carrying an agent identity through a repository and a pipeline, and why a badge is not proof. - https://agents.ecocitizenz.com/sdk: The SDK Passport family, and the honest status of an ECZ-ID client library. - https://agents.ecocitizenz.com/aec: AEC — Active Entity Capacity: what counts as an actively managed entity, the one pool across families, and what AEC never changes. - https://agents.ecocitizenz.com/interoperability: What ECZ-ID sits beside — MCP, A2A, OAuth, IAM, SPIFFE — and what it explicitly does not replace. - https://agents.ecocitizenz.com/agent-trust: ECZ-ID Agent Trust: local-first agent inventory and authority inspection, distinct from a Passport. - https://agents.ecocitizenz.com/kya: KYA Authority: the authority layer for governed agents, and why authority is never part of a free Passport. - https://agents.ecocitizenz.com/parent: Parent DECLARED, VERIFIED and ASSURED — and why none of them verifies the agent. - https://agents.ecocitizenz.com/pulseguard: PulseGuard current-state evaluation: the free on-demand baseline included with every Passport, and what the paid tiers add. - https://agents.ecocitizenz.com/ledgercore: LedgerCore evidence retention, and the promise that essential evidence never disappears. - https://agents.ecocitizenz.com/enterprise: Fleet, OEM, insurer and procurement arrangements, agreed directly rather than bought online. - https://agents.ecocitizenz.com/privacy: Exactly what this site collects and what it structurally cannot collect. - https://agents.ecocitizenz.com/security: The response headers this origin sets, the build-time preflight, and where identity truth actually lives. ## Elsewhere in the estate Developer Gateway (technical integration reference): https://developers.ecocitizenz.com MCP family site: https://mcp.ecocitizenz.com ## Not published here This host serves a website. It does not serve an agent endpoint, so it publishes no A2A Agent Card and no agent manifest describing itself as an agent. There is no ECZ-ID client SDK published yet, so this site names no package and no install command.