STACK
MENU

Accept requests from authorised agents

A STACK Passport lets your service verify which agent is calling, which customer or organisation is responsible for it, and what the agent has permission to do.

How requests are checked

Agent request arrives at your service
AgentWhich agent is calling.VerifiedAgent identity and signature are valid.
Operator / customerWhich organisation owns the agent and is accountable.IdentifiedThe responsible operator is named.
DelegationWhere this call sits in a chain of up to 4 narrowing hops.VerifiedThe delegation chain is valid.
Identity evidenceProof of the human behind the agent, never their PII.VerifiedThe required identity claim is present.
Service scopeWhat the agent may do, bound to specific actions and resources.In scopeThe requested action and resource are allowed.
ExpiryHow long the permission lasts.ValidThe permission has not expired.
Request accepted

Your service can act with confidence. The agent is authorised for this action, on behalf of this customer, right now.

  • Proceed with the authorised action
  • Log the decision and evidence
  • Continue the workflow
Out-of-scope requestInvalid signature, unexpected operator, invalid delegation, expired permission or an action outside the approved scope.
DeniedThe request is rejected. No action is taken.
Request denied

The agent is not authorised for this action, on behalf of this customer, right now.

Building the receiving end? Talk to us.

Passport verification is public and can run inside your service. If you are building one of these workflows, we would like to hear from you.

stack | Accept agents: verify STACK passports offline