01 / Unique ID
A unique, verifiable identity for every governed AI object.
The Compute Passport Identifier (CPID) is persistent, non-secret and globally unique. Credentials proving control of the CPID are signed, scoped, short-lived and continuously revocable.
Cryptographic identity
Persistent identifier. Short-lived proof. Continuous status.
Separate identity from runtime credentials. The identity persists across the lifecycle while execution credentials remain scoped to task, session and approved context.
| Field | Enterprise purpose |
|---|---|
| Issuer ID | Stable identifier for the organization or trust domain controlling issuance. |
| Tenant ID | Opaque isolation boundary without encoding personal information. |
| Object Type | Agent, model, workload, compute, tool, policy or evidence. |
| UUIDv7 | Time-ordered unique value for indexing and collision resistance. |
| Key Thumbprint | Digest of the active public verification key or certificate. |
| Status Endpoint | Resolve active, suspended, expired, retired or compromised state. |
Agent Passport
Bind identity to sponsor, purpose and bounded authority.
IdentityCPID, issuer, sponsor, tenant and aliases.
PurposeBusiness function, approved task classes and environment.
AuthorityOn-behalf-of, delegated, autonomous, ceiling and expiry.
Model bindingProvider, model, version and assurance profile.
Tool scopeAllowlists, action limits, destination limits and rate limits.
LifecycleCommissioned, active, suspended, retired or compromised.