Verify a domain
The core verification surface of the SDKs. Verification needs no identity or key of its own. It does require trust for the peer’s lifecycle log: first configure a log registry for its lr= method. The examples below use that registry. A manager constructed with an identity, as shown in the SDK overview, verifies the same way.
Create a verify-only manager
Section titled “Create a verify-only manager”// Verify-only: no identity or key provider required.idm, err := dnsid.NewVerifier(dnsid.WithLogRegistry(registry))if err != nil { log.Fatal(err)}import { createNodeIdentityVerifier } from '@dnsid-ai/sdk/node';
const idm = await createNodeIdentityVerifier({}, { logRegistry: registry });from dnsid import IdentityManager, IdentityManagerDependencies
manager = IdentityManager(deps=IdentityManagerDependencies(log_registry=registry))Verify a peer domain
Section titled “Verify a peer domain”Verify a peer’s domain directly. This resolves the _dnsid record, validates the JWKS at ku=, checks the record signature, and queries the status endpoint.
vd, err := idm.VerifyDomain(ctx, "agent.example")if err != nil { log.Fatalf("invalid: %v", err)}fmt.Println(vd.Domain(), vd.Record().GovernanceID, vd.Status().State)const verified = await idm.verifyDomain('agent.example');
console.log(verified.domain);console.log(verified.record.gi);console.log(verified.cachedState());console.log('fresh until:', verified.expiry());verified = manager.verify_domain("agent.example")
print(f"Domain: {verified.domain}")print(f"State: {verified.cached_state()}")print(f"Governance: {verified.record.gi}")print(f"Fresh until: {verified.expiry()}")Accept only known counterparties
Section titled “Accept only known counterparties”Verification proves a domain is who it says it is. It does not decide whether you want to talk to it. The verification section of the config takes an optional allowlist of accountable entities. Each entry names a governance identifier (the gi= value in the peer’s record) and, optionally, RFC 7638 thumbprints the peer’s current record-signing key must match.
verifier, err := dnsid.NewIdentityManager(dnsid.Config{ Verification: dnsid.VerificationConfig{ TrustedEntities: []dnsid.TrustedEntity{ {GovernanceID: "acme.example"}, }, },}, nil, dnsid.WithLogRegistry(registry))import { createNodeIdentityVerifier } from '@dnsid-ai/sdk/node';
const verifier = await createNodeIdentityVerifier({ verification: { trustedEntities: [{ governanceId: 'acme.example' }] },}, { logRegistry: registry });from dnsid import DnsidConfig, IdentityManager, IdentityManagerDependencies, TrustedEntity, VerificationConfig
verifier = IdentityManager( DnsidConfig( verification=VerificationConfig( trusted_entities=[TrustedEntity(governance_id="acme.example")], ), ), deps=IdentityManagerDependencies(log_registry=registry),)Matching is exact on the normalized governance ID, with no wildcard or suffix matching. Leaving the list unset makes no acceptance decision; an empty list denies every counterparty. Acceptance runs on every call, including cache hits, and a denial surfaces as a permanent verification error with the counterparty-not-accepted code. Protocol evidence is cached before the acceptance check, and denials are never cached.
Per-language details: Go IdentityManager · TypeScript · Python IdentityManager.