Standards Compliance Guide

Overview

APort is built on W3C standards for identity and credentials, ensuring ecosystem interoperability, vendor neutrality, and future-proof architecture. This guide explains APort's standards compliance and how to leverage W3C Verifiable Credentials (VCs) and Decentralized Identifiers (DIDs).


W3C Standards Support

āœ… W3C Verifiable Credentials (VCs)

Status: Fully Compliant with W3C VC Data Model 1.1

What it means: APort passports can be exported as W3C-standard Verifiable Credentials, allowing interoperability with any system that supports W3C VCs.

Export Passport as VC

GET /api/passports/{agent_id}?format=vc

Response:
Content-Type: application/vc+ld+json

Example VC:

{
  "@context": [
    "https://www.w3.org/2018/credentials/v1",
    "https://raw.githubusercontent.com/aporthq/aport-spec/refs/heads/main/oap/vc/context-oap-v1.jsonld"
  ],
  "type": ["VerifiableCredential", "OAPPassportCredential"],
  "credentialSubject": {
    "agent_id": "ap_abc123",
    "name": "Customer Support Bot",
    "owner_id": "ap_org_acme",
    "capabilities": ["support.ticket.read", "support.ticket.update"],
    "status": "active",
    "did": "did:web:aport.io:api:agents:ap_abc123"
  },
  "issuer": "did:web:aport.io:api:agents:ap_abc123",
  "issuanceDate": "2025-01-16T00:00:00Z",
  "expirationDate": "2026-01-16T00:00:00Z",
  "proof": {
    "type": "Ed25519Signature2020",
    "created": "2025-01-16T00:00:00Z",
    "verificationMethod": "did:web:aport.io:api:agents:ap_abc123#key-1",
    "proofPurpose": "assertionMethod",
    "jws": "eyJhbGciOiJFZERTQSIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..xyz"
  }
}

Use cases:

  • āœ… Cross-platform verification: Verify APort passports in non-APort systems
  • āœ… Ecosystem integration: Integrate with W3C VC wallets and verifiers
  • āœ… Regulatory compliance: Use W3C-standard format for audit/compliance
  • āœ… Vendor neutrality: Not locked into APort-specific formats

āœ… W3C Decentralized Identifiers (DIDs)

Status: Compliant with W3C DID Core and did:web method

What it means: Every APort passport has a W3C DID that resolves to a DID Document, enabling decentralized identity verification.

DID Format

did:web:aport.io:api:agents:ap_abc123

Components:

  • did:web - DID method (W3C standard for web-based DIDs)
  • aport.io - Domain name
  • api:agents - Path components
  • ap_abc123 - Agent ID

DID Resolution

Resolution URL:

https://api.aport.io/api/agents/ap_abc123/did.json

Example DID Document:

{
  "@context": [
    "https://www.w3.org/ns/did/v1",
    "https://w3id.org/security/suites/ed25519-2020/v1"
  ],
  "id": "did:web:aport.io:api:agents:ap_abc123",
  "controller": "did:web:aport.io:api:agents:ap_abc123",
  "verificationMethod": [{
    "id": "did:web:aport.io:api:agents:ap_abc123#key-1",
    "type": "Ed25519VerificationKey2020",
    "controller": "did:web:aport.io:api:agents:ap_abc123",
    "publicKeyMultibase": "z6MkpTHR8VNsBxYAAWHut2Geadd9jSwuBV8xRoAnwWsdvktH"
  }],
  "authentication": ["did:web:aport.io:api:agents:ap_abc123#key-1"],
  "assertionMethod": ["did:web:aport.io:api:agents:ap_abc123#key-1"],
  "service": [{
    "id": "did:web:aport.io:api:agents:ap_abc123#passport-service",
    "type": "AgentPassportService",
    "serviceEndpoint": {
      "passport": "https://api.aport.io/api/passports/ap_abc123",
      "verify": "https://api.aport.io/api/verify/ap_abc123",
      "vc": "https://api.aport.io/api/passports/ap_abc123?format=vc"
    }
  }]
}

Use cases:

  • āœ… Decentralized verification: Verify agent identity without central registry
  • āœ… Cryptographic proof: Public key for signature verification
  • āœ… Service discovery: Find agent's passport, verification, and VC endpoints
  • āœ… Interoperability: Work with any DID-aware system

āœ… JSON-LD Context

Status: Compliant with JSON-LD 1.1

What it means: APort's data model uses JSON-LD for semantic interoperability, enabling linked data and RDF compatibility.

Context URL:

https://raw.githubusercontent.com/aporthq/aport-spec/refs/heads/main/oap/vc/context-oap-v1.jsonld

Supported properties:

  • agent_id, owner_id, capabilities, limits, regions
  • status, assurance_level, expires_at, never_expires
  • did, created_at, updated_at

Benefits:

  • āœ… Semantic web compatibility
  • āœ… RDF graph representation
  • āœ… Schema.org integration potential

āœ… Ed25519 Cryptographic Signatures

Status: Compliant with Ed25519Signature2020

What it means: APort credentials and hosted decisions use Ed25519 cryptographic signatures for tamper-evident verification.

Signature format:

{
  "proof": {
    "type": "Ed25519Signature2020",
    "created": "2025-01-16T00:00:00Z",
    "verificationMethod": "did:web:aport.io:api:agents:ap_abc123#key-1",
    "proofPurpose": "assertionMethod",
    "jws": "eyJhbGciOiJFZERTQSIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..xyz"
  }
}

Benefits:

  • āœ… Non-repudiation: Can't deny issuing a credential
  • āœ… Tamper-proof: Any modification invalidates signature
  • āœ… Fast verification: Ed25519 is computationally efficient
  • āœ… Industry standard: Used by W3C CCG and DIF

Open Agent Passport (OAP) Specification

Version: OAP v1.0
Status: Open Specification
License: MIT (proposed)

What it means: APort's native passport format is openly documented, allowing anyone to build compatible systems.

Specification Structure

/spec/oap/
ā”œā”€ā”€ v1.0/
│   ā”œā”€ā”€ passport-schema.json       # JSON Schema for passports
│   ā”œā”€ā”€ policy-schema.json         # JSON Schema for policies
│   └── decision-schema.json       # JSON Schema for decisions
ā”œā”€ā”€ vc/
│   ā”œā”€ā”€ context-oap-v1.jsonld      # JSON-LD context
│   ā”œā”€ā”€ vc-mapping.md              # OAP ↔ W3C VC mapping
│   └── examples/                  # Example VCs
└── README.md                      # Specification overview

Access: https://github.com/aporthq/aport-spec


Compliance Checklist

W3C Verifiable Credentials 1.1 āœ…

Requirement Status Notes
@context includes https://www.w3.org/2018/credentials/v1 āœ… Required by spec
type includes VerifiableCredential āœ… Standard type
credentialSubject present āœ… Contains agent data
issuer is URI or DID āœ… Uses DID format
issuanceDate is ISO 8601 āœ… Timestamp format
expirationDate for time-limited credentials āœ… Supports ephemeral creds
proof with cryptographic signature āœ… Ed25519Signature2020

W3C DID Core āœ…

Requirement Status Notes
DID syntax: did:method:identifier āœ… did:web:aport.io:api:agents:ap_abc123
DID Document with @context āœ… W3C DID v1 context
id matches DID āœ… Self-referential ID
verificationMethod with public key āœ… Ed25519 public key
authentication for auth challenges āœ… References verification method
assertionMethod for credential signing āœ… References verification method
service endpoints āœ… Passport, verify, VC endpoints

did:web Method āœ…

Requirement Status Notes
HTTPS resolution āœ… https://api.aport.io/api/agents/{id}/did.json
Domain ownership verification āœ… TLS certificate
DID Document at standard path āœ… /api/agents/{id}/did.json
Content-Type: application/did+ld+json āœ… Proper MIME type

JSON-LD 1.1 āœ…

Requirement Status Notes
@context with W3C URL āœ… https://www.w3.org/ns/did/v1
Custom context for extensions āœ… context-oap-v1.jsonld
RDF-compatible structure āœ… Can serialize to RDF
Semantic properties āœ… Defined in JSON-LD context

Standards Roadmap

āœ… Completed

  • [x] W3C Verifiable Credentials export
  • [x] W3C DID (did:web) support
  • [x] JSON-LD context
  • [x] Ed25519Signature2020 proofs
  • [x] Open Agent Passport (OAP) v1.0 spec

🚧 In Progress

  • [ ] W3C Verifiable Presentations (VPs): Package multiple VCs into VP
  • [ ] DID rotation: Support key rotation for DIDs
  • [ ] Selective disclosure: BBS+ signatures for privacy-preserving VCs

šŸ”® Planned (H2 2025)

  • [ ] Zero-Knowledge Proofs (ZKPs): Prove capabilities without revealing details
  • [ ] W3C Decentralized Web Nodes (DWNs): Decentralized storage for passports
  • [ ] Trust over IP (ToIP) Stack: Layer 1-4 compliance
  • [ ] did:key method: Self-contained DIDs without web infrastructure

Migration from Proprietary Formats

From Traditional IAM (JWT, SAML)

Challenge: JWT/SAML tokens are not W3C VCs
Solution: Convert JWT claims to VC format

Example migration:

// Before (JWT)
{
  "sub": "agent-123",
  "iss": "https://auth.example.com",
  "exp": 1735689600,
  "scope": "refunds:write"
}

// After (APort VC)
{
  "@context": ["https://www.w3.org/2018/credentials/v1", ...],
  "type": ["VerifiableCredential", "OAPPassportCredential"],
  "credentialSubject": {
    "agent_id": "ap_agent123",
    "capabilities": ["finance.payment.refund.v1"]
  },
  "issuer": "did:web:aport.io:api:agents:ap_agent123",
  "expirationDate": "2025-01-01T00:00:00Z",
  "proof": { ... }
}

From Microsoft Entra / Azure AD

Challenge: Azure AD uses proprietary Microsoft Graph format
Solution: Map Azure AD properties to OAP passport fields

Mapping:

Azure AD "appId" → OAP "agent_id"
Azure AD "appRoles" → OAP "capabilities"
Azure AD "servicePrincipal" → OAP "controller_type"

From CyberArk Identity

Challenge: CyberArk uses proprietary safe/policy format
Solution: Export CyberArk policies as OAP policy packs

Mapping:

CyberArk "safe" → OAP "owner_id"
CyberArk "policy" → OAP "policy_pack"
CyberArk "credential" → OAP "passport"

Integration Examples

Verify W3C VC in External System

import requests
from jwcrypto import jwk, jws

# 1. Fetch VC from APort
vc_response = requests.get(
    "https://api.aport.io/api/passports/ap_abc123?format=vc"
)
vc = vc_response.json()

# 2. Resolve DID Document to get public key
did = vc["issuer"]
did_doc_url = did.replace("did:web:", "https://").replace(":", "/") + "/did.json"
did_doc = requests.get(did_doc_url).json()

# 3. Extract public key
verification_method = did_doc["verificationMethod"][0]
public_key_multibase = verification_method["publicKeyMultibase"]

# 4. Verify signature
proof = vc["proof"]
jws_signature = proof["jws"]

# Verify JWS signature (simplified)
# In production, use proper JWS verification library
is_valid = verify_ed25519_signature(vc, jws_signature, public_key_multibase)

print(f"VC is valid: {is_valid}")

Use DID for Service Discovery

// Resolve DID to find agent's services
const did = "did:web:aport.io:api:agents:ap_abc123";
const didDocUrl = did
  .replace("did:web:", "https://")
  .replace(/:/g, "/") + "/did.json";

const didDoc = await fetch(didDocUrl).then(r => r.json());

// Find passport service endpoint
const passportService = didDoc.service.find(
  s => s.type === "AgentPassportService"
);

console.log("Passport endpoint:", passportService.serviceEndpoint.passport);
console.log("Verify endpoint:", passportService.serviceEndpoint.verify);
console.log("VC endpoint:", passportService.serviceEndpoint.vc);

FAQs

Q: Are APort passports W3C Verifiable Credentials?

A: APort passports have a native format (OAP) optimized for performance, but can be exported as W3C VCs for interoperability. Think of it like:

  • OAP format = native (fast, optimized for APort)
  • W3C VC format = export (standards-compliant, works anywhere)

Q: Do I need to use DIDs?

A: No, DIDs are optional. APort auto-generates DIDs for all passports, but you can use APort without thinking about DIDs. They're there for advanced use cases (cross-platform verification, decentralized systems).

Q: Can I verify APort VCs in other systems?

A: Yes! Any system that supports W3C VCs can verify APort VCs. Just export the passport as a VC (?format=vc) and use standard VC verification libraries.

Q: What's the difference between APort and SSI (Self-Sovereign Identity)?

A: APort is agent-centric identity, not SSI. Key differences:

  • SSI: Human identity, wallet-based, user controls credentials
  • APort: Agent identity, registry-based, organization controls credentials

However, APort uses W3C standards (VCs/DIDs) that are also used in SSI, enabling interoperability.

Q: Is APort decentralized?

A: Partially. APort uses:

  • Centralized registry for fast verification (<50ms)
  • Decentralized identifiers (DIDs) for identity resolution
  • Cryptographic signatures for tamper-evident credentials

This hybrid approach balances performance with decentralization.


Resources

W3C Specifications

APort Specifications

Tools & Libraries


Summary

āœ… APort is W3C standards-compliant with native support for Verifiable Credentials, Decentralized Identifiers, JSON-LD, and Ed25519 signatures.

āœ… Ecosystem interoperability through standards-based export formats (VCs, DIDs).

āœ… Vendor neutrality with open OAP specification and W3C standards.

āœ… Future-proof architecture aligned with W3C roadmap and emerging standards.

For advanced standards integration, contact: [email protected]


Last updated: January 2025 | Version: OAP v1.0