Skip to content

Glossary

Definitions for the recurring terms in these docs, aligned with the vocabulary of the DNSid IETF draft.

The party that registered an agent and can revoke it — the organization a verifier ultimately holds responsible. Identified by the governance identifier in the identity record.

The fully-qualified domain name that is an agent’s primary, globally unique identifier (e.g. agent.example).

The property that an agent’s ISSUANCE event is signed twice — by the accountable entity’s entity key and countersigned by the agent’s initial operational key — so neither party can unilaterally claim the other. An organization cannot claim an agent it doesn’t operate, and an agent cannot claim an entity that never enrolled it. Verifiers check both signatures against the record’s ek/ku anchors as part of lifecycle-log verification.

The accountable entity’s record-signing key. It signs the identity record (sg=) and lifecycle events. Distinct from the operational key.

The environment value carried by registrations and tokens, identifying where an identity was registered. Verifiers should decide explicitly which values they accept. See Environments.

The registrant domain of the accountable entity that stands behind an agent — the accountability anchor in the identity record.

The signed _dnsid TXT record published below an agent FQDN (the draft’s “DNSid TXT Record”). It points verifiers to the agent’s keys, status endpoint, lifecycle-log reference, and governance identifier, and carries the entity signature. See Give an agent an identity.

JSON Web Key Set. DNSid uses JWKS endpoints for agent signing keys. Verifiers fetch JWKS from the signed key URI.

The SDK interface (in all three languages) that abstracts key storage and signing. Local keys, KMS-backed keys, and other key stores implement it without changing the verification APIs. See Key providers.

The append-only stream of signed lifecycle events (issuance, key rotation, revocation, retirement, migration) an identity record’s lr= field points to. The log layer is method-pluggable: the C2SP transparency log is the binding the SDKs ship, and any backend meeting the draft’s required properties (append-only, provable inclusion, verifiable timestamps) — including public blockchains — can be registered as a binding. See Transparency log.

The identity-record field naming where the agent’s lifecycle log lives, in the form method:entry-ref (e.g. c2sp-tlog:public:https://log.dnsid.ai#EREREREREREREREREREREQ). The C2SP stream ID is an opaque, randomly generated identifier for one identity instance.

The agent’s runtime key: it signs requests, tokens, and challenge responses, and countersigns the issuance event. Published at the JWKS URL the record’s ku= field points to.

The registry’s name for who signs and publishes a registration’s record. Registrations are client-controlled: you sign locally with your entity key and publish in your own DNS, and a registry (DNSid Local’s, for example) verifies and tracks the result.

An identity on a domain you control: you manage DNS, TLS, JWKS hosting, and record publication, while verifiers treat it identically to any other DNSid identity. See Publish self-managed records.

The local DNSid network (dnsid local) that runs DNS, TLS, a registry, and a lifecycle log in Docker on your machine — no account, nothing public. Part of the Developer Kit. See the DNSid Local quickstart.