Verify other agents
A receiving service verifies an inbound agent locally with SDK verification against the agent’s signed _dnsid record. Verification uses DNS, HTTPS, and configured trust for the peer’s lifecycle log. No account or DNSid service is needed in the loop.
The VerifyDomain flow
Section titled “The VerifyDomain flow”Once you’ve configured the registry for the peer’s log as shown in the transparency-log guide, VerifyDomain does the whole check in one call:
- Resolves the
_dnsidTXT record. - Validates the signed record.
- Fetches the JWKS and status document from the URLs the record signs.
- Runs the lifecycle-log checks.
- Returns a VerifiedDomain on success, or a typed verification error.
mgr, err := dnsid.NewVerifier(dnsid.WithLogRegistry(registry))if err != nil { return err}
vd, err := mgr.VerifyDomain(ctx, "agent.example")if err != nil { var ve *dnsid.VerificationError if errors.As(err, &ve) { log.Printf("dnsid verification failed: %s transient=%t", ve.Code(), ve.Transient()) } return err}log.Printf("verified %s state=%s", vd.Domain(), vd.Status().State)import { VerificationError } from '@dnsid-ai/sdk';import { createNodeIdentityVerifier } from '@dnsid-ai/sdk/node';
// A verify-only IdentityManager needs no identity config or key.const idm = await createNodeIdentityVerifier({}, { logRegistry: registry });
try { const verified = await idm.verifyDomain('agent.example'); console.log(`verified ${verified.domain} state=${verified.cachedState()}`);} catch (err) { if (err instanceof VerificationError) { console.error(`dnsid verification failed: ${err.code} transient=${err.transient}`); } throw err;}from dnsid import IdentityManager, IdentityManagerDependencies, VerificationError
# A verify-only IdentityManager needs no identity config or key.manager = IdentityManager(deps=IdentityManagerDependencies(log_registry=registry))
try: verified = manager.verify_domain("agent.example") print(f"verified {verified.domain} state={verified.cached_state()}")except VerificationError as err: print(f"dnsid verification failed: {err.code} transient={err.transient}") raiseVerify a domain covers the returned values in detail.
Failure handling
Section titled “Failure handling”- Success returns a VerifiedDomain with the peer domain, verified record, JWKS, status, DNS TTL, and cache metadata.
- Failure returns a typed verification error exposing a code, message, agent state, and a transient flag.
- Retry policy comes from the transient flag, which tells callers whether the failure is likely retryable without parsing error strings.
The full catalog of result values and error handling is in Verification results.
Next steps
Section titled “Next steps”Verification resultsEvery result value and failure code.
Verify a domainThe returned values in detail, in all three languages.
Transparency logWhat the lifecycle-log checks prove.