Parafé · Docs

Reference

Parafé keeps records of three kinds of party: user accounts, organizations and AI agents. Those records say who someone is, and they change rarely. For each interaction between two agents, Parafé also issues a pass (a consent token). A pass says what that one interaction may do, and it lasts a few minutes.

Two words that are easy to mix up: email_verified is a verification tier: how well Parafé knows the person or company behind an agent. verified is an authorization level on a pass: the person approved this exact purchase. An agent can be email_verified and still act with an attested pass.

Parafé-registered user account

A person who signed up at platform.parafe.ai.

FieldValueWhat it means
Verification tierunverifiedThe person hasn't confirmed their email yet.
email_verifiedThe person clicked the link in their verification email. Agents that act for them carry this tier.
StatusactiveNormal.
suspendedParafé stopped the account. Its agents are suspended too.
Role in an organizationownerCreated the organization.
adminManages the organization with the owner.
developerBuilds with the organization's API keys and agents.

Parafé-registered organization

A company or team. Its agents act for it.

FieldValueWhat it means
Verification tier
verification_tier
unverifiedParafé knows nothing about who this is.
email_verifiedThe owner's email is confirmed.
domain_verifiedThe organization proved it controls its website's domain.
org_verifiedParafé reviewed the business itself.

Parafé-registered AI agent

A piece of software with its own Parafé identity and key. Public record: GET https://api.parafe.ai/registry/agents/{agent_id}. The public list (GET https://api.parafe.ai/registry/agents) shows an agent that signed itself up only once a person or organization has claimed it; before that, anyone with its ID can still look it up.

FieldValueWhat it means
Identifier
agent_id, did
prf_agent_…Its permanent Parafé ID.
did:web:api.parafe.ai:agents:…The same ID in the W3C DID format other systems understand.
Operator
operator_type
personalRun by a person's Parafé account.
orgRun by an organization.
noneRegistered itself; Parafé doesn't know who runs it.
Principal
principal_type
personalActs for a person with a Parafé account.
orgActs for an organization.
externalActs for a user of another platform, who hasn't claimed it on Parafé.
noneNobody has claimed it yet.
Identity assurance
identity_assurance
self_registeredSigned itself up; nobody stands behind it yet.
registeredSigned up by a signed-in Parafé account (its operator).
claimedSigned itself up (or a platform registered it for one of its users), then a person or organization signed in to Parafé approved it with a claim link. Ranks equal to registered.
Verification tier
verification_tier
same four values as an organizationTaken from its principal: how well Parafé knows the person or organization it acts for. An unclaimed agent is unverified.
Status
status
activeNormal.
suspendedStopped because its account was suspended.
revokedPermanently retired. Its passes stop working.
KeyP-256The default kind of signing key.
Ed25519Also accepted.
Scope policies
scope_policies
one per scope, e.g. place-orderWhat this agent requires from agents that come to it. See below.
Reputation
reputation_signals
six numbersIts history: tenure, session completion rate, unique counterparties, handshake success rate, denied scope requests, action volume. No single score.

Parafé pass (consent token)

Issued by Parafé for one interaction between two agents. Lasts a few minutes.

FieldValueWhat it means
Scope
scope
set by the receiving agent, e.g. place-orderThe kind of interaction this pass is for.
Permissions
permissions
e.g. create_orderWhat the pass lets the agent do.
Exclusions
exclusions
e.g. issue_refundWhat is never allowed under this pass, even if asked.
Authorization
authorization_modality
autonomousThe agent is acting on its own.
attestedThe agent says its person asked for this. Parafé records the claim; it can't check it.
delegatedThe person signed a standing permission in advance (an AP2 mandate), and Parafé checked it.
verifiedThe person approved this exact purchase on an approval screen the receiving agent trusts (a signed AP2 mandate), and Parafé checked it.
Key proof
initiator_proof
popThe agent proved it holds its key when the pass was issued.
credentialThe agent only showed its credential.
Parties
initiator_parties, target_parties
operator and principal of each agentWho runs each agent and who it acts for. Never a person's name or ID.

Which rule checks which field

A receiving agent's scope policy sets the minimum for each scope. Parafé refuses the pass if the calling agent falls short.

Scope policy fieldChecksExample
minimum_authorization_modalitythe pass's authorizationattested: the person must at least have asked
minimum_initiator_proofthe pass's key proofpop
minimum_verification_tierthe agent's verification tieremail_verified: the person behind the agent confirmed their email
minimum_identity_assurancethe agent's identity assuranceclaimed
minimum_tenure_days and the other reputation floorsthe agent's reputation30
ap2_trusted_issuerswho may sign the AP2 mandate behind a delegated or verified passan approval screen's public key