Verification results
Reference for the values returned by SDK verification APIs. The flow itself is covered in Verify other agents and Verify a domain.
Success
Section titled “Success”IdentityManager.VerifyDomain returns a VerifiedDomain when the _dnsid TXT record, record signature, JWKS fetch, status fetch, lifecycle-log checks, and policy checks succeed. Its accessors (Go naming; TypeScript and Python use the same surface in their casing):
Domain()- the verified peer domainRecord()- the parsed, signature-checked identity recordKeySet()- the JWKS fetched from the record’sku=URLStatus()- the live lifecycle status from thesu=URLVerifiedAt()- when verification completedDNSTTL()- the TTL of the resolved TXT recordCachedState()- the cached lifecycle state, honoring freshness metadata
Failure codes
Section titled “Failure codes”Verification failures are typed errors exposing Code(), Message(), AgentState(), and Transient(). The codes are defined by the language-agnostic SDK contract, so they are identical across Go, TypeScript, and Python.
Core verification codes
Section titled “Core verification codes”| Code | Meaning |
|---|---|
dns_resolution | The _dnsid TXT record could not be resolved |
dnssec_failed | DNSSEC validation failed |
record_invalid | The TXT record is missing, malformed, or fails required-field checks |
signature_invalid | The record’s sg= entity signature does not verify |
tls_error | TLS failure fetching the JWKS or status URL |
key_age_exceeded | The operational key exceeds the record’s ka= maximum age |
status_unavailable | The su= status URL could not be fetched |
status_not_active | The status document reports a non-ACTIVE state |
log_error | The lifecycle-log checks could not be completed for the record’s lr= method |
Lifecycle-log codes
Section titled “Lifecycle-log codes”Emitted when strict lifecycle state-machine enforcement rejects the agent’s log evidence (see Transparency log): CHAIN_CONTINUITY, DUPLICATE_ISSUANCE, INVALID_EVIDENCE, INCOMPLETE_STREAM, KEY_CONTINUITY, INVALID_MIGRATION.
Application-profile codes
Section titled “Application-profile codes”The JOSE, HTTP-signature, and OIDC profiles emit additional codes (key_not_found, agent_not_found, token_expired, token_not_yet_valid, malformed_token, invalid_claims, audience_mismatch, issuer_mismatch, lifetime_too_long, policy_not_satisfied). Core VerifyDomain does not emit these.
Branching on failures
Section titled “Branching on failures”var ve *dnsid.VerificationErrorif errors.As(err, &ve) { log.Printf("code=%s transient=%t state=%s", ve.Code(), ve.Transient(), ve.AgentState())}import { VerificationError } from '@dnsid-ai/sdk';
if (err instanceof VerificationError) { console.error(`code=${err.code} transient=${err.transient} state=${err.agentState}`);}from dnsid import VerificationError
try: verified = manager.verify_domain(domain)except VerificationError as err: print(f"code={err.code} transient={err.transient} state={err.agent_state}")The transient flag tells callers whether the failure is likely retryable without parsing error strings. The complete per-language error surface is in the reference: Go errors & enums · TypeScript VerificationError · Python verification results.