Skip to content

Verification results

Reference for the values returned by SDK verification APIs. The flow itself is covered in Verify other agents and Verify a domain.

IdentityManager.VerifyDomain returns a VerifiedDomain when the _dnsid TXT record, record signature, JWKS fetch, status fetch, lifecycle-log checks, and policy checks succeed. Its accessors (Go naming; TypeScript and Python use the same surface in their casing):

  • Domain() - the verified peer domain
  • Record() - the parsed, signature-checked identity record
  • KeySet() - the JWKS fetched from the record’s ku= URL
  • Status() - the live lifecycle status from the su= URL
  • VerifiedAt() - when verification completed
  • DNSTTL() - the TTL of the resolved TXT record
  • CachedState() - the cached lifecycle state, honoring freshness metadata

Verification failures are typed errors exposing Code(), Message(), AgentState(), and Transient(). The codes are defined by the language-agnostic SDK contract, so they are identical across Go, TypeScript, and Python.

CodeMeaning
dns_resolutionThe _dnsid TXT record could not be resolved
dnssec_failedDNSSEC validation failed
record_invalidThe TXT record is missing, malformed, or fails required-field checks
signature_invalidThe record’s sg= entity signature does not verify
tls_errorTLS failure fetching the JWKS or status URL
key_age_exceededThe operational key exceeds the record’s ka= maximum age
status_unavailableThe su= status URL could not be fetched
status_not_activeThe status document reports a non-ACTIVE state
log_errorThe lifecycle-log checks could not be completed for the record’s lr= method

Emitted when strict lifecycle state-machine enforcement rejects the agent’s log evidence (see Transparency log): CHAIN_CONTINUITY, DUPLICATE_ISSUANCE, INVALID_EVIDENCE, INCOMPLETE_STREAM, KEY_CONTINUITY, INVALID_MIGRATION.

The JOSE, HTTP-signature, and OIDC profiles emit additional codes (key_not_found, agent_not_found, token_expired, token_not_yet_valid, malformed_token, invalid_claims, audience_mismatch, issuer_mismatch, lifetime_too_long, policy_not_satisfied). Core VerifyDomain does not emit these.

var ve *dnsid.VerificationError
if errors.As(err, &ve) {
log.Printf("code=%s transient=%t state=%s", ve.Code(), ve.Transient(), ve.AgentState())
}

The transient flag tells callers whether the failure is likely retryable without parsing error strings. The complete per-language error surface is in the reference: Go errors & enums · TypeScript VerificationError · Python verification results.