Skip to content

Public verification

Verify an agent before you rely on it.

Paste an ECZ-ID. You will get a link to the live public record: who operates the agent, what state is published, and what that record explicitly does not establish.

Public Resolver reads and public machine-readable records are never metered, never authenticated and never counted against any allowance.

A parent looks like ECZ-GB-XXXXXX. An agent looks like ECZ-GB-XXXXXX::AGENT_PASSPORT-YYYYYY.

The identifier you type stays in your browser. This page checks its shape locally and then sends you to the Resolver; it does not look the record up on your behalf, and it keeps no list of what was checked.

How to read a record

What each field supports — and what it does not.

The second column is the one that matters. Most bad conclusions come from reading a field as stronger evidence than it is.
Resolver fields, what each one establishes and what it does not
FieldWhat it tells youWhat it does not
parentWhich organisation operates this agent, and whether that organisation has been independently verified.It does not mean the agent was checked. A verified organisation can operate an unexamined agent.
lifecycle_stateThe state published for this identity right now, with the time it was read.ACTIVE describes the record, not the agent's behaviour, its permissions, or whether it is running.
public_bindingsWhere this agent is declared to run, and how each declaration was established.A declared binding is a statement by the operator unless its provenance says otherwise. Declared is not control-proven.
do_not_inferThe list of things this record explicitly does not establish.Skipping it is how people invent claims the record never made. It is the most useful field on the page.
is_proofAlways false.The Resolver never presents itself as a verdict. It publishes evidence for you to weigh.

Reading it correctly

Four rules that stop a record being over-read.

An absent record is not a finding

No public ECZ-ID Passport found is not a safety finding. It means this identifier resolves to no published record — nothing more. Most software has no ECZ-ID yet.

A record is not a verdict

The record is not proof. It publishes what is currently declared and what evidence exists, with the time it was read. Re-check the live record before you rely on it.

Organisation verified, machine not

A VERIFIED or ASSURED Parent does not verify the agent. The parent organisation's identity is verified. The machine is not. An agent linked to a VERIFIED Parent is described exactly that way — linked to a VERIFIED Parent — never as a verified agent.

Declared is a statement, not a check

DECLARED does not mean independently verified. It records what an organisation says about itself, with the date it said it — not the outcome of a check.

A badge, a QR code, a screenshot or a card is a pointer to a record, not the record. Only the live Resolver is current. Re-check before reliance. State can change between the moment a badge is drawn and the moment an agent acts.

ECZ-ID tells you what is published and by whom. What that is worth in your context is your policy's decision, not ours.

The other side of the check

Someone is going to look yours up too.

If you operate an agent, publishing a record is what makes this check possible in the other direction.