Proposal: a shared, “informal protocol” for identity confidence

This is a proposal on a small standard: a record shape for identity confidence — rank, score, type, issuer signature — anyone can write and any AppView can display and validate the same way.

My background is Digital Rights — I invented the first App Store, in 1993. I focus on human safety, harm reduction, and data sovereignty; I have four small children, this future isn’t abstract to me.

ATProto was designed with identity as a separate, portable thing — the DID stands apart and this is a tremendous opportunity to help secure our future world. That separation is critical to privacy, but the public lexicon is still the natural place to store the resulting measure of confidence.

In the same way an article is tamper-proofed, a pseudonymous post or account must be able to carry credibility — and a publisher must be able to validate it without ever holding PII.

An “informal protocol” would standardize this increasingly common requirement. Bluesky’s badge is on-protocol but authority-gated — hand-picked.

For everyone else, a signature inside the record, proving who issued it, checkable by anyone, forever, with no live callback, is possible based on what we’ve done a few times now.

What we built

When verify completes, we putRecord into the subject’s own repo at our NSID. The record is the result of validation, never the evidence.


{

  "$type": "app.truanon.label",

  "rank": "credible",

  "score": "3",

  "confidenceType": "social",

  "verifiedAt": "2026-07-21T00:00:00Z"

}

Then the AppView getRecords it off the PDS. It travels with the DID and renders instantly like any other lexicon data - a lovely badge of trust.

A repo record is signed by the owner’s key. That’s gorgeous tamper evidence. Here, we have something where nothing stops writing { “rank”: “genuine”, “score”: “5” } by hand.

Where trust lives today is not complete

  • Issuer’s repo unspoofable, but only those who are hand-picked get to use it.

  • Labeler: unspoofable, graded if you like, but the claim lives with the service, not the account.

  • Subject’s repo (ours): travels with the DID — but self-signed, so unverifiable

Keep the record in the subject’s repo and embed the issuer’s signature inside it — a signature over the record’s fields, made with a key published in the issuer’s DID document. Any reader verifies offline, against the issuer’s key, forever, with no live service in the loop. This community already specified the primitive: community.lexicon.attestations.signature, as used in community.lexicon.badge.award.

{
  "$type": "app.truanon.label",
  "rank": "credible",
  "score": "3",
  "confidenceType": "social",
  "verifiedAt": "2026-07-21T00:00:00Z"
}

Any verifier writes the same shape under its own key, and each AppView decides which issuer keys it trusts and at what threshold. The trust list stops being one company’s list; credibility thresholds become a per-community choice over one shared record shape.

The international regulatory and legal world really demands a variety of ever-evolving solutions and the results should be verified, protected and shared easily.

We’ve implemented the mechanism a few times over. What we want to close down, together, is the tamper loop — because everyone who touches identity confidence on this protocol will need to close it the same way.

I’d love your thoughts. Does subject-repo-plus-issuer-signature feel like the right corner to you, or would you place trust elsewhere? Any fields missing from the minimal set? And does a community NSID make more sense than ours for the published schema? Would you like to work on implementations people can use and adopt? I’m here to help.

2 Likes

Nice idea, thx for the writeup @jtayler.bsky.social!

rank /score: those two quietly turn a confidence signal into a grade. Plenty of apps will probably happily render a number, not because it’s the right thing to do but because it’s the easy thing and it looks great on the surface :sweat_smile:.

But: a signal that one issuer made for one context (your child-safety case, or a “yes, really a journalist” vouch) travels with the DID and renders everywhere, so another app in a totally different context reads it as generic “trustworthy”. Context collapse, basically, and a bare score makes it worse because the number survives the trip but the meaning doesn’t.

Ran into the same thing designing reputation for Barazo, a “helpful” reaction in a programming community shouldn’t weigh the same as one in a manga community, or a car mechanics community. I ended up computing it AppView-side per community instead of storing a number on the record.

Your confidenceType is clearly reaching for this, I’d just want to see how far it can carry. Might be worth asking whether the score belongs in the standard record at all, or whether each community derives its own from the raw attestations?

anyway, happy to see initiatives in this direction!

1 Like

Totally agree — interpretation of a validation is the crux, and law/regulation often forces that in ways you can’t predict (a clean driving record means nothing on a dog-walking site).

Here, we see attestations like being a journalist can sometimes be separately validated — proving an @mit.edu or @ibm.com email address is easy for the owner, but not readily available to a fraudster. Those accounts are curated.

Same pattern: a site needed to identify a “developer” via GitHub or BitBucket, you validate, grant visibility and let the platform’s API gate the privileged section.

Same for kids — binding to a school platform proves an age range other platforms can trust, without exposing anything else so validations are not exclusive and don’t even interfere.

Laws and regulations change, communities grow and this identity layer evolves along with any of that.

Would love to dig into Braso with you — mind if I poke around and see where I can help?

1 Like

Go ahead :flexed_biceps: the MVP/POC environment is at https://staging.barazo.forum/, docs at https://docs.barazo.forum/ and the code is on github: Singi Labs · GitHub

@gui.do I’m into the staging site. Nice – do you want to look into this together?

1 Like

Jesse,

Excuse me for this, but your comment about children and the future, and the app store, rung a large bell. You might be aware of Digital Sovereignty being a major social movement in Europe presently. European Commission Director Generals are all making it plain.

A few decades before you were selling your genius to Mr.Jobs, I was inventing financial products which enabled computer companies to lock in their customers. So we both have a few sins to forgive.

So, we know that app stores are one key to taking back a developer’s sovereignty from the gatekeepers. That’s going to come to a head shortly as 24 European countries issue Wallets.

Would you consider helping the EC to set up a public app store?

1 Like

@simonfj.eurosky.social I’d be happy to help any way I can, of course - I think you can message me? or just use my public email jtayler@truanon.com and remind me of our discussion here.

Jesse.

Thanks so much. Look, i hope you don’t mind. This is a very different approach I know. But at my age (the memory is going) one thing I’ve learnt is that example is that the best leader, and together (if we keep this conversation here & above the radar) we can assist to influence a younger generation.

We find ourselves at this time in history after coming up with concepts that we’re meant to institute some real social progress. They just got taken to extremes by private companies. Yours; where computer and media companies now gatekeep/rip off developers. Mine; where they turned a capital expense/one off license fee into a (locked in) price per month by playing IT managers off against their Finance director.

You might have seen the latest attempt by the EC to regulate what the major players have been doing. And the orange man’s response.

We are at the point in time, if you follow these things over the decades as I have, where the European Communities are looking to offer public alternatives to the US companies instead of trying to regulate them. Not sure how this proposal might look yet. But you’ve got the history, so one doesn’t need to sell the idea of a public developer’s (app) store to the EC too hard.

Slowly, slowly. Please! In your own time. You’ve seen the obvious stated by the Waag guys. And you may have seen the first eurosky conference. The primary session for me was the one that addressed the convergence between the old public broadcasters and the new (so called) social media.

Gotta say. I can see where you’re coming from with the “informal protocol” for identity confidence. There’s a definite truth in that approach. I have to throw this session, from the guys who run the R&E networks across Europe at you. The second presentation from Christoph - who runs the eduID product at SWITCH (the swiss uni network) - offers a perspective to at-protocol’s developers (from every global uni’s network manager). NREN.

OK Enough. I’ll mention this conference where I was hoping someone from the AT community would be attending this year conference in September (to meet Christoph and Co).

is that ATmosphereConf?