Skip to content

Verify other agents

A receiving service verifies an inbound agent locally with SDK verification against the agent’s signed _dnsid record. Verification uses DNS, HTTPS, and configured trust for the peer’s lifecycle log. No account or DNSid service is needed in the loop.

Once you’ve configured the registry for the peer’s log as shown in the transparency-log guide, VerifyDomain does the whole check in one call:

  1. Resolves the _dnsid TXT record.
  2. Validates the signed record.
  3. Fetches the JWKS and status document from the URLs the record signs.
  4. Runs the lifecycle-log checks.
  5. Returns a VerifiedDomain on success, or a typed verification error.
mgr, err := dnsid.NewVerifier(dnsid.WithLogRegistry(registry))
if err != nil {
return err
}
vd, err := mgr.VerifyDomain(ctx, "agent.example")
if err != nil {
var ve *dnsid.VerificationError
if errors.As(err, &ve) {
log.Printf("dnsid verification failed: %s transient=%t", ve.Code(), ve.Transient())
}
return err
}
log.Printf("verified %s state=%s", vd.Domain(), vd.Status().State)

Verify a domain covers the returned values in detail.

  • Success returns a VerifiedDomain with the peer domain, verified record, JWKS, status, DNS TTL, and cache metadata.
  • Failure returns a typed verification error exposing a code, message, agent state, and a transient flag.
  • Retry policy comes from the transient flag, which tells callers whether the failure is likely retryable without parsing error strings.

The full catalog of result values and error handling is in Verification results.