Skip to content

Core concepts

The concepts that show up throughout DNSid. Each links to the page that covers it in depth; the glossary has one-line definitions for everything else.

Concept map of an agent identity: domain, keypair, JWKS, identity record, claims, and verification all anchor to the agent identity.Concept map of an agent identity: domain, keypair, JWKS, identity record, claims, and verification all anchor to the agent identity.

The core concepts and how they hang off a single agent identity.

An agent identity is anchored to a fully-qualified domain name that the accountable entity owns and operates—the self-managed model. During development, DNSid Local stands in for your DNS and hosting with a disposable local zone. Give an agent an identity covers the model and the record lifecycle.

Each agent involves two keys with different jobs:

Public keys are published at JWKS endpoints; private keys stay with their owners, managed through a key provider.

The identity record is the signed _dnsid TXT record published below the agent’s domain—a set of pointers to the agent’s keys, status endpoint, and lifecycle log, plus the entity signature that makes it trustworthy. The record in public DNS is authoritative. The DNSid Local quickstart walks a record field by field; Publish self-managed records covers publishing your own.

Identity history—issuance, key rotation, revocation, retirement—is a stream of signed lifecycle events the record’s lr= field points to. Verifiers replay it to prove the current key chains back to a bilateral issuance signed by both the entity and the agent. The transparency log guide covers the C2SP binding the SDKs ship.

SDK verification (VerifyDomain) resolves the record, checks the signature, fetches the JWKS and the signed status URL, and runs the lifecycle-log checks. Failures carry a typed code and a transient flag—see Verification results. Revocation is terminal and propagates through the status URL and the lifecycle log.