SDK Publisher & Provenance (monthly)
£29.99 per monthExcludes VAT
- package identities
- 50 package identities
Not yet on sale online. The price is set; the purchase route is not open yet.
View details(opens in a new tab — trustops.ecocitizenz.com)ECZ-ID SDK Passport™
For publishers of SDKs, libraries and packages on npm, PyPI, Maven, NuGet and other registries. Consumers trace a package back to its publisher by guessing from a registry account name. One public ECZ-ID names the library and the organisation that publishes it.
£0 · No card required · Permanent, not a trial.
One SDK Passport
Identifier shown as a pattern, not a real record. DECLARED information is self-declared; re-check the live record before you rely on it.
The Resolver is the only authority on an ECZ-ID’s public state, and no answer it gives is a judgement about safety. Re-check before you rely on it.
Every public record has a machine form at https://api.ecocitizenz.com/api/p/{ecz_id}.json — no account, no key, no rate card for reading it.
Large estates, procurement evidence, OEM and distribution are a conversation, not a checkout.
One SDK Across Supply Chains
Consumers trace a package back to its publisher by guessing from an account name. Versions are history and channels are bindings; the library itself is one enduring subject with one identity.
Your organisation
One ECZ-ID Business Passport, created free the first time you acquire any Passport. Every Passport below hangs from it, and it never changes.
publishes
SDK Passport
One SDK Passport is one logical SDK, library or package your organisation publishes.
is published as
Every registry it lands in
One entry per registry, each a binding on the same Passport. A new registry is a new binding, never a new library.
wraps
API Passport
Most SDKs wrap an API. The API keeps its own identity, whichever SDKs call it.
A binding records that the publisher declared this listing. It is not a provenance attestation and it says nothing about the contents of any release.
The full graph, and what a line never means
Included free: Basic Graph participation and a current one-hop view.
Every registry keeps its own account, its own signing and its own release process.
Illustrative identifier shape
ECZ-XX-XXXXXX::SDK_PASSPORT-XXXXXX
Releases, versions and registry channels of that library are not separate Passports.
Bindings, versions, replicas, endpoints and deployments never consume AEC and never become a second Passport.
Illustrative. This is the shape a record of this kind can take, not a live estate — a new Passport starts with no bindings and no relationships, and shows only what its operator chooses to publish.
Reading a record is on demand, with no account and no key. Nothing here watches an entity for you; ongoing monitoring is a separate, optional capability.
Anyone auditing a dependency tree that contains your library is guessing at who publishes it. Stop making them guess.
Free SDK Passport
One SDK Passport is one logical SDK, library or package your organisation publishes. Releases, versions and registry channels of that library are not separate Passports.
Publishing the record is your decision. Nothing becomes public until you consent, and you can withdraw publication later.
How it works
Start in TrustOps with one sign-in. Your organisation's free DECLARED Parent is reused or created, and the SDK or library gets its ECZ-ID.
Add the public places your SDK or library already appears — a package registry listing or the canonical source repository. Each binding records where it was learned.
Anyone can open the public record and its JSON, with no account and no API key — and re-check it before relying on it.
Publish the ECZ-ID where people and machines already look, and manage it from your ECZ-ID console.
Parent verification, monitoring, evidence and authority are optional. None is needed to hold a Passport.
Interoperability
An SDK Passport complements package registries and the repositories behind them. The registry distributes your library; the Passport publishes who stands behind it.
Native where you operate. ECZ-ID where you interoperate.Keep the identities your platforms need. Add the identity everyone else can resolve.
Binds naturally with
What it does: Distribute the versions of your library.
What ECZ-ID adds beside it: One publisher-linked identity for the library across every registry it is published to.
What it does: Host the code a library, plugin or server is built from.
What ECZ-ID adds beside it: A binding from the repository to the enduring subject, recorded with where it was learned.
ECZ-ID complements your frameworks, protocols, OAuth, cloud IAM and workload identity. It replaces none of them and stays outside the execution path.
Digital Entity Graph
One identity, the representations it is bound to, and the other identities it legitimately relates to. Each is a separate ECZ-ID with its own operator — never a copy of this one.
Your organisation
One ECZ-ID Business Passport, created free the first time you acquire any Passport. Every Passport below hangs from it, and it never changes.
SDK Passport
One SDK Passport is one logical SDK, library or package your organisation publishes.
a package registry listing
A representation of the same subject. It never becomes a second Passport.
the canonical source repository
A representation of the same subject. It never becomes a second Passport.
an OCI registry reference
A representation of the same subject. It never becomes a second Passport.
your published documentation
A representation of the same subject. It never becomes a second Passport.
API Passport
Most SDKs wrap an API. The API keeps its own identity, whichever SDKs call it.
Plugin Passport
SDKs are the building blocks of plugins, and each plugin is identified in its own right.
Service & Workload Passport
Libraries run inside services and workloads, which are separate enduring subjects.
Illustrative. This is the shape a record of this kind can take, not a live estate — a new Passport starts with no bindings and no relationships, and shows only what its operator chooses to publish.
Every line above says two things are connected. None of them says one is allowed to act for the other. Authority is granted in your own systems, and ECZ-ID does not grant it, infer it or enforce it.
Live proof
EcoCitizenz Ltd runs this site and holds its own ECZ-ID. Everything below is read from the public record, by anyone, with no account and no key — including the parts that are empty.
ECZ-ID
activeEcoCitizenz
ECZ-GB-RBS1NW
The parent organisation's identity is verified. This machine is not.
Evidence available
The same record answers for humans and machines. One is a page, the other is JSON with no authentication in front of it.
curl -s https://api.ecocitizenz.com/api/p/ECZ-GB-RBS1NW.json | jq .resolver_v2.stateThat this company is safe to deal with, that its software is correct, or that anyone has audited it. A record establishes who an entity is and who operates it. Everything else is your decision, and you should re-check before you rely on it.
Scale
A free Passport exists and resolves whether or not you use any AEC. AEC is the capacity to actively manage entities in production.
One AEC is one actively managed production entity with live bindings and current state.
For SDK Passports: An SDK or package you actively manage in production, with live bindings and current state.
AEC is one pool shared across your Agent, MCP, Plugin, API, SDK and logical Service & Workload identities, and your IoT product, model and fleet identities.
Individual IoT device instances are counted separately, in IoT Fleet Capacity, and never consume AEC.
Prices and what can be bought today come from TrustOps, which owns every purchase, entitlement and renewal. Your organisation’s included AEC and any additional capacity are configured there.
Products
When the free Passport is not enough, these are the SDK products that extend it. Everything is bought and billed in TrustOps.
£29.99 per monthExcludes VAT
Not yet on sale online. The price is set; the purchase route is not open yet.
View details(opens in a new tab — trustops.ecocitizenz.com)£99.99 per monthExcludes VAT
Not yet on sale online. The price is set; the purchase route is not open yet.
View details(opens in a new tab — trustops.ecocitizenz.com)Prices and what can be bought today come from TrustOps, which owns every purchase, entitlement and renewal. What you see here is what it published on .
Strengthen
Nothing here is needed to hold a Passport, and not taking it never downgrades an identity you already hold.
Independent verification of the organisation behind your Passports. VERIFIED suits production use; ASSURED is the higher-assurance posture for larger or more sensitive estates.
Boundary: It verifies your organisation. It never verifies an agent, a server or any other child identity, and it never changes an ECZ-ID.
Included free: Every Passport starts with a free DECLARED Parent — created for you if your organisation has none.
Publisher identity and provenance across the SDKs and packages you publish.
Boundary: Provenance records where a package came from. It is not a security audit of its code.
Current-state evaluation for the entities you operate. Paid tiers extend evaluation across more entities and more evaluations each month.
Included free: On-demand and event-driven evaluation of your own entities.
The evidence behind each claim on a record: what supports it, where it came from, when it was checked and who may see it.
Included free: Essential evidence references are part of every free Passport.
Tamper-evident retention of decisive lifecycle evidence — issuance, activation, material bindings, authority changes, suspension and revocation — with eligible evidence anchored to a permissioned, append-only ledger.
Included free: Essential LedgerCore evidence is kept for every identity, free ones included.
The public-safe relationships between your organisation, its Passports and their bindings. Graph Pro, Graph Business and Enterprise Graph Intelligence add scale, history and custom analysis above the free view.
Included free: Basic Graph participation and a current one-hop view.
Prices and what can be bought today come from TrustOps, which owns every purchase, entitlement and renewal.
Build and operate
Publish the SDK or library's identity, wire it into what you already run, and check any ECZ-ID from anywhere.
Integration reference, schemas and machine-readable documentation for ECZ-ID.
Open the Developer Gateway
(opens in a new tab — developers.ecocitizenz.com)Resolve any ECZ-ID to its public record — free, with no account and no API key.
Verify an ECZ-ID
Every record as JSON at /api/p/{ecz_id}.json, for policy engines, gateways and agents. Shown here on EcoCitizenz's own record.
Open a live machine record
(opens in a new tab — api.ecocitizenz.com)Sign in to TrustOps to reach the Passports your organisation holds. It is where current commercial configuration lives, too.
Open your ECZ-ID console
(opens in a new tab — trustops.ecocitizenz.com)One identity layer
Each is a separate subject with its own Passport, its own operator and its own public record. They are the same identity layer, not seven products.
Agent
AI agent
MCP
MCP server
Plugin
plugin
Not open yet
API
API
Not open yet
IoT
connected device
Not open yet
SDKYou are here
SDK or library
Not open yet
Service & Workload
service or workload
Not open yet
When it is a different logical subject with its own operator and its own lifecycle. Something operated by someone else is a second subject. The same thing in three regions, versions or listings is still one.
Never mint a second Passport for another representation of the same thing — a version, a replica, an endpoint or a listing. Those are bindings, and they cost no capacity.
From here, the ones that most often turn out to be separate subjects are API, Plugin and Service & Workload.
£0 · No card required · Permanent, not a trial.
Current availability
The SDK Passport is free — £0, permanently, and never sold. That is the price, and it is not what is missing. What is not ready is the door: ECZ-ID Core is not issuing SDK Passports yet, and the Resolver is not projecting SDK records yet.
So this site publishes no start link, no waiting list and no date. When both are live, the family is opened through one configuration value in the Website Factory and the control appears on every page here at once. No page on this site is rewritten to do it.
Nothing on this site can be bought in the meantime. Paid capabilities are described here and configured in TrustOps, which owns every purchase.