Standards Compliance Guide
Overview
APort is built on W3C standards for identity and credentials, ensuring ecosystem interoperability, vendor neutrality, and future-proof architecture. This guide explains APort's standards compliance and how to leverage W3C Verifiable Credentials (VCs) and Decentralized Identifiers (DIDs).
W3C Standards Support
ā W3C Verifiable Credentials (VCs)
Status: Fully Compliant with W3C VC Data Model 1.1
What it means: APort passports can be exported as W3C-standard Verifiable Credentials, allowing interoperability with any system that supports W3C VCs.
Export Passport as VC
GET /api/passports/{agent_id}?format=vc
Response:
Content-Type: application/vc+ld+json
Example VC:
{
"@context": [
"https://www.w3.org/2018/credentials/v1",
"https://raw.githubusercontent.com/aporthq/aport-spec/refs/heads/main/oap/vc/context-oap-v1.jsonld"
],
"type": ["VerifiableCredential", "OAPPassportCredential"],
"credentialSubject": {
"agent_id": "ap_abc123",
"name": "Customer Support Bot",
"owner_id": "ap_org_acme",
"capabilities": ["support.ticket.read", "support.ticket.update"],
"status": "active",
"did": "did:web:aport.io:api:agents:ap_abc123"
},
"issuer": "did:web:aport.io:api:agents:ap_abc123",
"issuanceDate": "2025-01-16T00:00:00Z",
"expirationDate": "2026-01-16T00:00:00Z",
"proof": {
"type": "Ed25519Signature2020",
"created": "2025-01-16T00:00:00Z",
"verificationMethod": "did:web:aport.io:api:agents:ap_abc123#key-1",
"proofPurpose": "assertionMethod",
"jws": "eyJhbGciOiJFZERTQSIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..xyz"
}
}
Use cases:
- ā Cross-platform verification: Verify APort passports in non-APort systems
- ā Ecosystem integration: Integrate with W3C VC wallets and verifiers
- ā Regulatory compliance: Use W3C-standard format for audit/compliance
- ā Vendor neutrality: Not locked into APort-specific formats
ā W3C Decentralized Identifiers (DIDs)
Status: Compliant with W3C DID Core and did:web method
What it means: Every APort passport has a W3C DID that resolves to a DID Document, enabling decentralized identity verification.
DID Format
did:web:aport.io:api:agents:ap_abc123
Components:
did:web- DID method (W3C standard for web-based DIDs)aport.io- Domain nameapi:agents- Path componentsap_abc123- Agent ID
DID Resolution
Resolution URL:
https://api.aport.io/api/agents/ap_abc123/did.json
Example DID Document:
{
"@context": [
"https://www.w3.org/ns/did/v1",
"https://w3id.org/security/suites/ed25519-2020/v1"
],
"id": "did:web:aport.io:api:agents:ap_abc123",
"controller": "did:web:aport.io:api:agents:ap_abc123",
"verificationMethod": [{
"id": "did:web:aport.io:api:agents:ap_abc123#key-1",
"type": "Ed25519VerificationKey2020",
"controller": "did:web:aport.io:api:agents:ap_abc123",
"publicKeyMultibase": "z6MkpTHR8VNsBxYAAWHut2Geadd9jSwuBV8xRoAnwWsdvktH"
}],
"authentication": ["did:web:aport.io:api:agents:ap_abc123#key-1"],
"assertionMethod": ["did:web:aport.io:api:agents:ap_abc123#key-1"],
"service": [{
"id": "did:web:aport.io:api:agents:ap_abc123#passport-service",
"type": "AgentPassportService",
"serviceEndpoint": {
"passport": "https://api.aport.io/api/passports/ap_abc123",
"verify": "https://api.aport.io/api/verify/ap_abc123",
"vc": "https://api.aport.io/api/passports/ap_abc123?format=vc"
}
}]
}
Use cases:
- ā Decentralized verification: Verify agent identity without central registry
- ā Cryptographic proof: Public key for signature verification
- ā Service discovery: Find agent's passport, verification, and VC endpoints
- ā Interoperability: Work with any DID-aware system
ā JSON-LD Context
Status: Compliant with JSON-LD 1.1
What it means: APort's data model uses JSON-LD for semantic interoperability, enabling linked data and RDF compatibility.
Context URL:
https://raw.githubusercontent.com/aporthq/aport-spec/refs/heads/main/oap/vc/context-oap-v1.jsonld
Supported properties:
agent_id,owner_id,capabilities,limits,regionsstatus,assurance_level,expires_at,never_expiresdid,created_at,updated_at
Benefits:
- ā Semantic web compatibility
- ā RDF graph representation
- ā Schema.org integration potential
ā Ed25519 Cryptographic Signatures
Status: Compliant with Ed25519Signature2020
What it means: APort credentials and hosted decisions use Ed25519 cryptographic signatures for tamper-evident verification.
Signature format:
{
"proof": {
"type": "Ed25519Signature2020",
"created": "2025-01-16T00:00:00Z",
"verificationMethod": "did:web:aport.io:api:agents:ap_abc123#key-1",
"proofPurpose": "assertionMethod",
"jws": "eyJhbGciOiJFZERTQSIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..xyz"
}
}
Benefits:
- ā Non-repudiation: Can't deny issuing a credential
- ā Tamper-proof: Any modification invalidates signature
- ā Fast verification: Ed25519 is computationally efficient
- ā Industry standard: Used by W3C CCG and DIF
Open Agent Passport (OAP) Specification
Version: OAP v1.0
Status: Open Specification
License: MIT (proposed)
What it means: APort's native passport format is openly documented, allowing anyone to build compatible systems.
Specification Structure
/spec/oap/
āāā v1.0/
ā āāā passport-schema.json # JSON Schema for passports
ā āāā policy-schema.json # JSON Schema for policies
ā āāā decision-schema.json # JSON Schema for decisions
āāā vc/
ā āāā context-oap-v1.jsonld # JSON-LD context
ā āāā vc-mapping.md # OAP ā W3C VC mapping
ā āāā examples/ # Example VCs
āāā README.md # Specification overview
Access: https://github.com/aporthq/aport-spec
Compliance Checklist
W3C Verifiable Credentials 1.1 ā
| Requirement | Status | Notes |
|---|---|---|
@context includes https://www.w3.org/2018/credentials/v1
|
ā | Required by spec |
type includes VerifiableCredential
|
ā | Standard type |
credentialSubject present
|
ā | Contains agent data |
issuer is URI or DID
|
ā | Uses DID format |
issuanceDate is ISO 8601
|
ā | Timestamp format |
expirationDate for time-limited credentials
|
ā | Supports ephemeral creds |
proof with cryptographic signature
|
ā | Ed25519Signature2020 |
W3C DID Core ā
| Requirement | Status | Notes |
|---|---|---|
DID syntax: did:method:identifier
|
ā |
did:web:aport.io:api:agents:ap_abc123
|
DID Document with @context
|
ā | W3C DID v1 context |
id matches DID
|
ā | Self-referential ID |
verificationMethod with public key
|
ā | Ed25519 public key |
authentication for auth challenges
|
ā | References verification method |
assertionMethod for credential signing
|
ā | References verification method |
service endpoints
|
ā | Passport, verify, VC endpoints |
did:web Method ā
| Requirement | Status | Notes |
|---|---|---|
| HTTPS resolution | ā |
https://api.aport.io/api/agents/{id}/did.json
|
| Domain ownership verification | ā | TLS certificate |
| DID Document at standard path | ā |
/api/agents/{id}/did.json
|
Content-Type: application/did+ld+json
|
ā | Proper MIME type |
JSON-LD 1.1 ā
| Requirement | Status | Notes |
|---|---|---|
@context with W3C URL
|
ā |
https://www.w3.org/ns/did/v1
|
| Custom context for extensions | ā |
context-oap-v1.jsonld
|
| RDF-compatible structure | ā | Can serialize to RDF |
| Semantic properties | ā | Defined in JSON-LD context |
Standards Roadmap
ā Completed
- [x] W3C Verifiable Credentials export
- [x] W3C DID (
did:web) support - [x] JSON-LD context
- [x] Ed25519Signature2020 proofs
- [x] Open Agent Passport (OAP) v1.0 spec
š§ In Progress
- [ ] W3C Verifiable Presentations (VPs): Package multiple VCs into VP
- [ ] DID rotation: Support key rotation for DIDs
- [ ] Selective disclosure: BBS+ signatures for privacy-preserving VCs
š® Planned (H2 2025)
- [ ] Zero-Knowledge Proofs (ZKPs): Prove capabilities without revealing details
- [ ] W3C Decentralized Web Nodes (DWNs): Decentralized storage for passports
- [ ] Trust over IP (ToIP) Stack: Layer 1-4 compliance
- [ ] did:key method: Self-contained DIDs without web infrastructure
Migration from Proprietary Formats
From Traditional IAM (JWT, SAML)
Challenge: JWT/SAML tokens are not W3C VCs
Solution: Convert JWT claims to VC format
Example migration:
// Before (JWT)
{
"sub": "agent-123",
"iss": "https://auth.example.com",
"exp": 1735689600,
"scope": "refunds:write"
}
// After (APort VC)
{
"@context": ["https://www.w3.org/2018/credentials/v1", ...],
"type": ["VerifiableCredential", "OAPPassportCredential"],
"credentialSubject": {
"agent_id": "ap_agent123",
"capabilities": ["finance.payment.refund.v1"]
},
"issuer": "did:web:aport.io:api:agents:ap_agent123",
"expirationDate": "2025-01-01T00:00:00Z",
"proof": { ... }
}
From Microsoft Entra / Azure AD
Challenge: Azure AD uses proprietary Microsoft Graph format
Solution: Map Azure AD properties to OAP passport fields
Mapping:
Azure AD "appId" ā OAP "agent_id"
Azure AD "appRoles" ā OAP "capabilities"
Azure AD "servicePrincipal" ā OAP "controller_type"
From CyberArk Identity
Challenge: CyberArk uses proprietary safe/policy format
Solution: Export CyberArk policies as OAP policy packs
Mapping:
CyberArk "safe" ā OAP "owner_id"
CyberArk "policy" ā OAP "policy_pack"
CyberArk "credential" ā OAP "passport"
Integration Examples
Verify W3C VC in External System
import requests
from jwcrypto import jwk, jws
# 1. Fetch VC from APort
vc_response = requests.get(
"https://api.aport.io/api/passports/ap_abc123?format=vc"
)
vc = vc_response.json()
# 2. Resolve DID Document to get public key
did = vc["issuer"]
did_doc_url = did.replace("did:web:", "https://").replace(":", "/") + "/did.json"
did_doc = requests.get(did_doc_url).json()
# 3. Extract public key
verification_method = did_doc["verificationMethod"][0]
public_key_multibase = verification_method["publicKeyMultibase"]
# 4. Verify signature
proof = vc["proof"]
jws_signature = proof["jws"]
# Verify JWS signature (simplified)
# In production, use proper JWS verification library
is_valid = verify_ed25519_signature(vc, jws_signature, public_key_multibase)
print(f"VC is valid: {is_valid}")
Use DID for Service Discovery
// Resolve DID to find agent's services
const did = "did:web:aport.io:api:agents:ap_abc123";
const didDocUrl = did
.replace("did:web:", "https://")
.replace(/:/g, "/") + "/did.json";
const didDoc = await fetch(didDocUrl).then(r => r.json());
// Find passport service endpoint
const passportService = didDoc.service.find(
s => s.type === "AgentPassportService"
);
console.log("Passport endpoint:", passportService.serviceEndpoint.passport);
console.log("Verify endpoint:", passportService.serviceEndpoint.verify);
console.log("VC endpoint:", passportService.serviceEndpoint.vc);
FAQs
Q: Are APort passports W3C Verifiable Credentials?
A: APort passports have a native format (OAP) optimized for performance, but can be exported as W3C VCs for interoperability. Think of it like:
- OAP format = native (fast, optimized for APort)
- W3C VC format = export (standards-compliant, works anywhere)
Q: Do I need to use DIDs?
A: No, DIDs are optional. APort auto-generates DIDs for all passports, but you can use APort without thinking about DIDs. They're there for advanced use cases (cross-platform verification, decentralized systems).
Q: Can I verify APort VCs in other systems?
A: Yes! Any system that supports W3C VCs can verify APort VCs. Just export the passport as a VC (?format=vc) and use standard VC verification libraries.
Q: What's the difference between APort and SSI (Self-Sovereign Identity)?
A: APort is agent-centric identity, not SSI. Key differences:
- SSI: Human identity, wallet-based, user controls credentials
- APort: Agent identity, registry-based, organization controls credentials
However, APort uses W3C standards (VCs/DIDs) that are also used in SSI, enabling interoperability.
Q: Is APort decentralized?
A: Partially. APort uses:
- Centralized registry for fast verification (<50ms)
- Decentralized identifiers (DIDs) for identity resolution
- Cryptographic signatures for tamper-evident credentials
This hybrid approach balances performance with decentralization.
Resources
W3C Specifications
- Verifiable Credentials Data Model 1.1
- Decentralized Identifiers (DIDs) v1.0
- JSON-LD 1.1
- did:web Method
- Ed25519Signature2020
APort Specifications
- Open Agent Passport (OAP) v1.0
- VC Mapping Documentation
- DID Resolution Guide
Tools & Libraries
- W3C VC Verification: did-jwt-vc
- DID Resolution: did-resolver
- JSON-LD Processing: jsonld.js
- Ed25519 Signatures: libsodium
Summary
ā APort is W3C standards-compliant with native support for Verifiable Credentials, Decentralized Identifiers, JSON-LD, and Ed25519 signatures.
ā Ecosystem interoperability through standards-based export formats (VCs, DIDs).
ā Vendor neutrality with open OAP specification and W3C standards.
ā Future-proof architecture aligned with W3C roadmap and emerging standards.
For advanced standards integration, contact: [email protected]
Last updated: January 2025 | Version: OAP v1.0