Reference
Parafé keeps records of three kinds of party: user accounts, organizations and AI agents. Those records say who someone is, and they change rarely. For each interaction between two agents, Parafé also issues a pass (a consent token). A pass says what that one interaction may do, and it lasts a few minutes.
Two words that are easy to mix up: email_verified is a verification tier: how well Parafé knows the person or company behind an agent. verified is an authorization level on a pass: the person approved this exact purchase. An agent can be email_verified and still act with an attested pass.
Parafé-registered user account
A person who signed up at platform.parafe.ai.
| Field | Value | What it means |
|---|---|---|
| Verification tier | unverified | The person hasn't confirmed their email yet. |
email_verified | The person clicked the link in their verification email. Agents that act for them carry this tier. | |
| Status | active | Normal. |
suspended | Parafé stopped the account. Its agents are suspended too. | |
| Role in an organization | owner | Created the organization. |
admin | Manages the organization with the owner. | |
developer | Builds with the organization's API keys and agents. |
Parafé-registered organization
A company or team. Its agents act for it.
| Field | Value | What it means |
|---|---|---|
Verification tierverification_tier | unverified | Parafé knows nothing about who this is. |
email_verified | The owner's email is confirmed. | |
domain_verified | The organization proved it controls its website's domain. | |
org_verified | Parafé reviewed the business itself. |
Parafé-registered AI agent
A piece of software with its own Parafé identity and key. Public record: GET https://api.parafe.ai/registry/agents/{agent_id}. The public list (GET https://api.parafe.ai/registry/agents) shows an agent that signed itself up only once a person or organization has claimed it; before that, anyone with its ID can still look it up.
| Field | Value | What it means |
|---|---|---|
Identifieragent_id, did | prf_agent_… | Its permanent Parafé ID. |
did:web:api.parafe.ai:agents:… | The same ID in the W3C DID format other systems understand. | |
Operatoroperator_type | personal | Run by a person's Parafé account. |
org | Run by an organization. | |
| none | Registered itself; Parafé doesn't know who runs it. | |
Principalprincipal_type | personal | Acts for a person with a Parafé account. |
org | Acts for an organization. | |
external | Acts for a user of another platform, who hasn't claimed it on Parafé. | |
| none | Nobody has claimed it yet. | |
Identity assuranceidentity_assurance | self_registered | Signed itself up; nobody stands behind it yet. |
registered | Signed up by a signed-in Parafé account (its operator). | |
claimed | Signed itself up (or a platform registered it for one of its users), then a person or organization signed in to Parafé approved it with a claim link. Ranks equal to registered. | |
Verification tierverification_tier | same four values as an organization | Taken from its principal: how well Parafé knows the person or organization it acts for. An unclaimed agent is unverified. |
Statusstatus | active | Normal. |
suspended | Stopped because its account was suspended. | |
revoked | Permanently retired. Its passes stop working. | |
| Key | P-256 | The default kind of signing key. |
Ed25519 | Also accepted. | |
Scope policiesscope_policies | one per scope, e.g. place-order | What this agent requires from agents that come to it. See below. |
Reputationreputation_signals | six numbers | Its history: tenure, session completion rate, unique counterparties, handshake success rate, denied scope requests, action volume. No single score. |
Parafé pass (consent token)
Issued by Parafé for one interaction between two agents. Lasts a few minutes.
| Field | Value | What it means |
|---|---|---|
Scopescope | set by the receiving agent, e.g. place-order | The kind of interaction this pass is for. |
Permissionspermissions | e.g. create_order | What the pass lets the agent do. |
Exclusionsexclusions | e.g. issue_refund | What is never allowed under this pass, even if asked. |
Authorizationauthorization_modality | autonomous | The agent is acting on its own. |
attested | The agent says its person asked for this. Parafé records the claim; it can't check it. | |
delegated | The person signed a standing permission in advance (an AP2 mandate), and Parafé checked it. | |
verified | The person approved this exact purchase on an approval screen the receiving agent trusts (a signed AP2 mandate), and Parafé checked it. | |
Key proofinitiator_proof | pop | The agent proved it holds its key when the pass was issued. |
credential | The agent only showed its credential. | |
Partiesinitiator_parties, target_parties | operator and principal of each agent | Who runs each agent and who it acts for. Never a person's name or ID. |
Which rule checks which field
A receiving agent's scope policy sets the minimum for each scope. Parafé refuses the pass if the calling agent falls short.
| Scope policy field | Checks | Example |
|---|---|---|
minimum_authorization_modality | the pass's authorization | attested: the person must at least have asked |
minimum_initiator_proof | the pass's key proof | pop |
minimum_verification_tier | the agent's verification tier | email_verified: the person behind the agent confirmed their email |
minimum_identity_assurance | the agent's identity assurance | claimed |
minimum_tenure_days and the other reputation floors | the agent's reputation | 30 |
ap2_trusted_issuers | who may sign the AP2 mandate behind a delegated or verified pass | an approval screen's public key |