{"contract_version":"ecz.free_passport_acquisition.v1","lane":"FREE","law":{"payment_required":false,"payment_calls":0,"parent_tier_required":"DECLARED","parent_is_created_if_absent":true,"authentications_required":1,"one_subject_one_ecz_id":true,"a_passport_is_not_proof":true,"recheck_before_reliance":true,"declared_meaning":"Self-declared organisation identity. Not independently verified.","never_claims":["that the machine is safe","that the machine is secure","that the machine behaves correctly","that ECZ-ID has tested or approved the machine","that the operating organisation has been independently verified"]},"request_vs_claim":{"claim":"An authorised operator gets a free Passport for a machine they operate.","request":"Anyone else may ask the operator for one. A request creates no identity.","absence_result":"NO_PUBLIC_ECZ_ID_FOUND","absence_is_not":["UNSAFE","UNTRUSTED","FAILED_TRUST_CHECK"]},"forwardable_context":["campaign","correlation_id","display_name","identifier","identifier_kind","locale","operator_mode","origin_surface","referral","requested_passport_type","requested_product","return_to","return_url","source_provider","source_surface"],"families":[{"token":"agent","type_code":"AGENT_PASSPORT","display_name":"ECZ-ID Agent Passport™","family_display":"Agent","available":true,"availability":"LIVE","pending":[],"start_path":"/start/agent","subject_law":"one logical AI agent operated by the Parent","singleton_law":"one agent -> one Passport; many agents -> many Passports","not_new_passports":["version","deployment","replica","region","platform"],"identifier_kinds":[{"kind":"a2a_card_url","normaliser":"URL","hash_only":false,"description":"the agent's A2A card URL"},{"kind":"well_known_origin","normaliser":"URL","hash_only":false,"description":"the origin publishing the agent's .well-known manifest"},{"kind":"repository","normaliser":"REPOSITORY","hash_only":false,"description":"host/owner/repo of the source repository"},{"kind":"package","normaliser":"PACKAGE","hash_only":false,"description":"ecosystem:name of the published package (no version)"}],"binding_classes":["deployment_binding","well_known_manifest","a2a_card","provider_registration"],"minimum_parent_tier":"DECLARED","publication_consent_required":true,"projects_identifier":true,"publish_kit":{"share_path":"/p/{ecz_id}","machine_json_path":"/api/p/{ecz_id}.json","badge_route":"/api/passports/child/{ecz_id}/badge.svg","qr_route":"/api/passports/child/{ecz_id}/qr.png","embed":".well-known/ecz-agent.json pointer; ecz_id + resolver_backlink in the agent card"},"adjacent":["MCP_PASSPORT","API_PASSPORT","SERVICE_WORKLOAD_PASSPORT","SDK_PASSPORT"],"managed_slot":"active managed deployment/platform binding"},{"token":"mcp","type_code":"MCP_PASSPORT","display_name":"ECZ-ID MCP Passport™","family_display":"MCP","available":true,"availability":"LIVE","pending":[],"start_path":"/start/mcp","subject_law":"one logical MCP server operated by the Parent","singleton_law":"one server -> one Passport; tools inside a server are never Passports","not_new_passports":["tool","endpoint","deployment","replica"],"identifier_kinds":[{"kind":"mcp_endpoint","normaliser":"URL","hash_only":false,"description":"the MCP server endpoint URL"},{"kind":"registry_server_name","normaliser":"NAME","hash_only":false,"description":"the MCP Registry server name, e.g. com.ecocitizenz/trust-mcp"},{"kind":"repository","normaliser":"REPOSITORY","hash_only":false,"description":"host/owner/repo of the source repository"},{"kind":"package","normaliser":"PACKAGE","hash_only":false,"description":"ecosystem:name of the published package (no version)"}],"binding_classes":["mcp_registry_entry","mcpb_desktop_bundle","mcp_remote_http","mcp_local_stdio"],"minimum_parent_tier":"DECLARED","publication_consent_required":true,"projects_identifier":true,"publish_kit":{"share_path":"/p/{ecz_id}","machine_json_path":"/api/p/{ecz_id}.json","badge_route":"/api/passports/child/{ecz_id}/badge.svg","qr_route":"/api/passports/child/{ecz_id}/qr.png","embed":".well-known/ecz-mcp.json; MCP Registry pointer; A2A publication (C12)"},"adjacent":["API_PASSPORT","SERVICE_WORKLOAD_PASSPORT","SDK_PASSPORT","AGENT_PASSPORT"],"managed_slot":"active managed server/deployment endpoint"},{"token":"plugin","type_code":"PLUGIN_PASSPORT","display_name":"ECZ-ID Plugin Passport™","family_display":"Plugin","available":false,"availability":"NOT_YET_LIVE","pending":["ACQUISITION_NOT_RELEASED","HELD_BY_OPERATOR"],"start_path":"/start/plugin","subject_law":"one logical plugin / extension / integration artefact published by the Parent, independent of the marketplace it is listed on","singleton_law":"one plugin -> one Passport across every marketplace; versions, releases, installs and executions are bindings/evidence/events","not_new_passports":["version","release","install","execution","store_listing","skill_component","action_run","workflow_reference"],"identifier_kinds":[{"kind":"plugin_name","normaliser":"NAME","hash_only":false,"description":"publisher-namespace/plugin-name as declared in the manifest"},{"kind":"plugin_manifest_url","normaliser":"URL","hash_only":false,"description":"the URL of the plugin manifest"},{"kind":"repository","normaliser":"REPOSITORY","hash_only":false,"description":"host/owner/repo of the source repository"},{"kind":"package","normaliser":"PACKAGE","hash_only":false,"description":"ecosystem:name of the published package (no version)"}],"binding_classes":["marketplace_listing","openai_gpt_actions","shopify_app_surface","microsoft_app_registration","github_action_reference"],"minimum_parent_tier":"DECLARED","publication_consent_required":true,"projects_identifier":true,"publish_kit":{"share_path":"/p/{ecz_id}","machine_json_path":"/api/p/{ecz_id}.json","badge_route":"/api/passports/child/{ecz_id}/badge.svg","qr_route":"/api/passports/child/{ecz_id}/qr.png","embed":"ecz_id + resolver_backlink in the plugin manifest (.claude-plugin, .cursor-plugin, .codex-plugin, package.json, action.yml)"},"adjacent":["API_PASSPORT","SDK_PASSPORT","AGENT_PASSPORT"],"managed_slot":"active marketplace/store distribution binding"},{"token":"api","type_code":"API_PASSPORT","display_name":"ECZ-ID API Passport™","family_display":"API","available":false,"availability":"NOT_YET_LIVE","pending":["ACQUISITION_NOT_RELEASED","HELD_BY_OPERATOR"],"start_path":"/start/api","subject_law":"one authorised API surface operated by the Parent","singleton_law":"one logical API -> one Passport; versions, environments, regional aliases and gateways are bindings; a second distinct API surface is a second Passport","not_new_passports":["version","environment","regional_alias","gateway"],"identifier_kinds":[{"kind":"api_base_url","normaliser":"URL_VERSIONLESS","hash_only":false,"description":"the API base URL; a trailing /vN version segment is a binding, not the subject"},{"kind":"openapi_url","normaliser":"URL","hash_only":false,"description":"the URL of the OpenAPI document"},{"kind":"repository","normaliser":"REPOSITORY","hash_only":false,"description":"host/owner/repo of the source repository"}],"binding_classes":["API_ORIGIN","OPENAPI_SPEC","WEBHOOK_ENDPOINT","DOMAIN_DNS_TXT","jwks_uri"],"minimum_parent_tier":"DECLARED","publication_consent_required":true,"projects_identifier":true,"publish_kit":{"share_path":"/p/{ecz_id}","machine_json_path":"/api/p/{ecz_id}.json","badge_route":"/api/passports/child/{ecz_id}/badge.svg","qr_route":"/api/passports/child/{ecz_id}/qr.png","embed":"OpenAPI info: x-ecz-id + x-ecz-resolver-backlink"},"adjacent":["SERVICE_WORKLOAD_PASSPORT","SDK_PASSPORT","MCP_PASSPORT"],"managed_slot":"managed endpoint/environment binding"},{"token":"iot","type_code":"IOT_DEVICE","display_name":"ECZ-ID IoT Device Passport™","family_display":"IoT/Device","available":false,"availability":"NOT_YET_LIVE","pending":["ACQUISITION_NOT_RELEASED","HELD_BY_OPERATOR"],"start_path":"/start/iot","subject_law":"one physical device (or one device identity module) operated by the Parent","singleton_law":"one device -> one Passport; a fleet -> many Passports (the meter counts MANAGED devices, never Passports)","not_new_passports":["mac_address","ip_address","firmware_version","gateway","hub_registration"],"identifier_kinds":[{"kind":"device_serial","normaliser":"PLAIN","hash_only":true,"description":"PLAIN over the composite manufacturer:model:serial"},{"kind":"device_attestation_ref","normaliser":"PLAIN","hash_only":true,"description":"SoC identity / attestation reference where the platform provides one"}],"binding_classes":["SERIAL_NUMBER","MAC_ADDRESS","FIRMWARE","GATEWAY","HUB_REGISTRATION"],"minimum_parent_tier":"DECLARED","publication_consent_required":true,"projects_identifier":false,"publish_kit":{"share_path":"/p/{ecz_id}","machine_json_path":"/api/p/{ecz_id}.json","badge_route":"/api/passports/child/{ecz_id}/badge.svg","qr_route":"/api/passports/child/{ecz_id}/qr.png","embed":"device label QR -> /p/{ecz_id}; fleet manifest field"},"adjacent":["API_PASSPORT","SERVICE_WORKLOAD_PASSPORT","SDK_PASSPORT"],"managed_slot":"active managed device (fleet slot)"},{"token":"sdk","type_code":"SDK_PASSPORT","display_name":"ECZ-ID SDK Passport™","family_display":"SDK","available":false,"availability":"NOT_YET_LIVE","pending":["ACQUISITION_NOT_RELEASED","HELD_BY_OPERATOR"],"start_path":"/start/sdk","subject_law":"one logical library/SDK published by the Parent, across languages and registries","singleton_law":"one SDK -> one Passport; npm/PyPI/Maven/NuGet/Go/OCI channels are bindings; versions/releases are history; a different library is a second Passport","not_new_passports":["version","release","registry_channel","package_artefact"],"identifier_kinds":[{"kind":"repository","normaliser":"REPOSITORY","hash_only":false,"description":"host/owner/repo of the source repository"},{"kind":"package","normaliser":"PACKAGE","hash_only":false,"description":"ecosystem:name of the published package (no version)"},{"kind":"sdk_name","normaliser":"NAME","hash_only":false,"description":"publisher-scoped logical name when neither repository nor package is public"}],"binding_classes":["PACKAGE_REGISTRY","REPO","GITHUB_OIDC","GITLAB_OIDC","OCI_IMAGE"],"minimum_parent_tier":"DECLARED","publication_consent_required":true,"projects_identifier":true,"publish_kit":{"share_path":"/p/{ecz_id}","machine_json_path":"/api/p/{ecz_id}.json","badge_route":"/api/passports/child/{ecz_id}/badge.svg","qr_route":"/api/passports/child/{ecz_id}/qr.png","embed":"package.json ecz_id/resolver_backlink; pyproject.toml [tool.ecz_id]; README badge"},"adjacent":["API_PASSPORT","AGENT_PASSPORT","MCP_PASSPORT","PLUGIN_PASSPORT","SERVICE_WORKLOAD_PASSPORT"],"managed_slot":"managed release/distribution channel"},{"token":"svc","type_code":"SERVICE_WORKLOAD_PASSPORT","display_name":"ECZ-ID Service & Workload Passport™","family_display":"Service & Workload","available":false,"availability":"NOT_YET_LIVE","pending":["ACQUISITION_NOT_RELEASED","HELD_BY_OPERATOR"],"start_path":"/start/svc","subject_law":"one ENDURING logical service or workload operated by the Parent; never a pod, replica, instance, process or region; provider-neutral continuity","singleton_law":"one logical workload -> one Passport; ephemeral pods/replicas/processes -> nothing; environments/regions/clusters -> bindings","not_new_passports":["pod","replica","instance","process","deployment_instance","region","cluster","runtime_credential"],"identifier_kinds":[{"kind":"workload_name","normaliser":"NAME","hash_only":false,"description":"stable publisher-scoped logical name, e.g. payments/ledger-writer"},{"kind":"service_origin","normaliser":"URL","hash_only":false,"description":"the workload's primary origin where one exists"},{"kind":"repository","normaliser":"REPOSITORY","hash_only":false,"description":"host/owner/repo of the source repository"}],"binding_classes":["aws_iam_role","gcp_workload_identity","entra_workload_identity","spiffe_id","kubernetes_service_account","oidc_issuer","nvidia_nemo_workflow"],"minimum_parent_tier":"DECLARED","publication_consent_required":true,"projects_identifier":true,"publish_kit":{"share_path":"/p/{ecz_id}","machine_json_path":"/api/p/{ecz_id}.json","badge_route":"/api/passports/child/{ecz_id}/badge.svg","qr_route":"/api/passports/child/{ecz_id}/qr.png","embed":"workload manifest / deployment annotation ecz_id + resolver_backlink; trust-graph node workload"},"adjacent":["AGENT_PASSPORT","API_PASSPORT","MCP_PASSPORT","SDK_PASSPORT"],"managed_slot":"active managed logical workload"}],"counts":{"total":7,"available_now":2}}