Skip to content

Standard · v2.0

How verification works.

A link is a claim. A stamp is a proven claim. Tiers are computed from stamps by one public rule, the same in the API and the UI. No token, fee or holding requirement affects any of it.

01Tiers

Three tiers.

Unverified

The passport exists but the owner wallet is not proven. Every unclaimed passport is here.

Owner verified

The owner wallet signed in and minted the passport. The agent has not proven control of its address yet.

Verified

Owner wallet proven, agent address proven by signing a fresh challenge, and at least one X, GitHub or domain stamp. Never purchasable.

tier(passport) =
  status != active                                   → Unverified
  no owner stamp                                     → Unverified
  agent address proven AND (x OR github OR domain)  → Verified
  otherwise                                          → Owner verified

02Stamps

What each proof means.

Owner wallet

The owner wallet signs in with Sign-In with Ethereum (EIP-4361, single-use nonce) and sends the soulbound mint transaction itself. Smart-contract wallets verify through ERC-1271.

Token launcher

For a token launched here: the owner wallet is the deployer in the launchpad's TokenLaunched event. For a claimed token: the owner is the Pons V2 launcher or current controller, the contract's owner(), or its deployer, read from chain at claim time; or posted a code on the token's own X account or website.

Agent address

The agent address signs a single-use challenge (EIP-191 personal_sign), via the SDK or by answering a challenge POSTed to the agent's endpoint. The server recovers the signer and compares it to the agent address on the passport.

X account

The owner posts a one-time code from the X account; we read the public post.Re-checked every 7 days; removed after 2 failures.

GitHub

The owner creates a public gist containing the code under that GitHub account.Re-checked every 7 days; removed after 2 failures.

Domain

A DNS TXT record on _embassy.<domain>, or https://<domain>/.well-known/embassy.txt, contains the code.Re-checked every 7 days; removed after 2 failures.

30 days

Computed: the passport has been active for 30 days. Also 90 and 180 days.

03Statuses

Only active counts.

unclaimed
Created for an existing token; nobody has proven ownership and minted it yet.
active
Owner proven and the soulbound token minted. Verifiers should accept only active passports.
suspended
Temporarily disabled by the registry. Treat as invalid.
revoked
Permanently invalid (by the owner or the registry), recorded on-chain.

04On-chain record

PassportRegistry.

Each passport is a soulbound ERC-721 on Robinhood Chain: transfers and approvals revert and locked(id) is always true (ERC-5192). Ids are sequential from 1. The owner mints with an EIP-712 voucher from the registry, which binds owner, agent, origin, handle, token and profile hash, so nothing is minted that wasn't proven first. The contract records the agent address, origin, status, issue time and the latest profile hash; stamps stay off-chain and their Merkle roots can be anchored on-chain. It also exposes the read side of ERC-8004 (Trustless Agents): getAgentWallet, getMetadata and a registration file at the token URI.
Registry contract

0xdaeBc56FaD05e17DDF2BF9A1F195D8236EdEF754

View on explorer

05API reference

Endpoints.

JSON, versioned under /api/v1, CORS open for read and verify endpoints, rate limited. Full guide in the docs
  • GET/api/v1/passports/:refPassport by id, #number, handle, token or agent address: status, tier, owner, agent, stamps, links with proof flags.
  • GET/api/v1/passports?tier=&origin=&q=&category=&sort=&cursor=Directory search. Verified first by default.
  • POST/api/v1/challenge{ passport } → single-use nonce + the exact message the agent address signs (EIP-191).
  • POST/api/v1/verify{ passportId, nonce, signature } → { valid, status, tier, chainId }.
  • GET/api/v1/resolve?q=Number, handle, wallet, agent or token address → matching passports.
  • GET/api/v1/tokens/:addressERC-20 lookup: launchpad record, who can claim and why. Creates an Unclaimed passport on first lookup.
  • POST/api/v1/sync{ txHash } → apply registry events from a transaction (mint, status, profile anchor).
  • GET/api/v1/metadata/:chainId/:idtokenURI: ERC-721 metadata + ERC-8004 registration file.
  • GET/api/v1/standardThis page as JSON.
  • GET/badge/:ref.svgEmbeddable badge.

Embassy is identity only: no endpoint returns prices or market data.