# ECZ-ID SDK > A free, permanent ECZ-ID for one logical SDK, library or package, linked to the organisation that publishes it and published on a resolver anyone can re-check. Registry channels are bindings and releases are history, not separate identities. > Website Factory V2 family site. Site: https://sdk.ecocitizenz.com ## The ECZ-ID SDK Passport™ For publishers of SDKs, libraries and packages on npm, PyPI, Maven, NuGet and other registries. Consumers trace a package back to its publisher by guessing from a registry account name. One public ECZ-ID names the library and the organisation that publishes it. - One SDK Passport is one logical SDK, library or package your organisation publishes. - Releases, versions and registry channels of that library are not separate Passports. - Identifier shape: ECZ-XX-XXXXXX::SDK_PASSPORT-XXXXXX ## Getting one Price: FREE (£0). No card required. Permanent, not a trial. The free SDK Passport door is not open on this estate yet. No start URL is published. Included: - A persistent ECZ-ID for the SDK or library. - Your organisation on the record as its operator — a free DECLARED Parent is created if you do not already have one. - A public Resolver record anyone can open, and the same record as machine-readable JSON. - A badge, a QR code and a share link. - Basic bindings to the public places your SDK or library already appears. - Lifecycle and current public state, evaluated on demand. - Claim and recovery. - Basic participation in the Digital Entity Graph. - Essential lifecycle evidence, kept in LedgerCore. ## Boundaries — load-bearing, do not drop them - DECLARED ≠ VERIFIED: A DECLARED record states what your organisation says about itself, with the date it said it. It is not the outcome of an independent check. - Identity ≠ Binding: The Passport identifies the SDK or library. A binding records a public place it already appears. Adding a binding never creates a second identity. - Binding ≠ Authority: A binding shows that a relationship has been declared. It does not grant, prove or imply authority to act. - Parent verification ≠ SDK verification: A VERIFIED or ASSURED Parent verifies your organisation. It does not verify the SDK or library. - A Resolver record is not proof. It publishes what is currently declared and what evidence exists, with the time it was read — is_proof is false and recheck_before_reliance is true. Re-check before you rely on it. - No public ECZ-ID found is not a finding. It means the identifier resolves to no published record — nothing more. - An ECZ-ID does not make anything safe, certified, approved or compliant, and holding one does not make you compliant with anything. ## AEC — Active Entity Capacity One AEC is one actively managed production entity with live bindings and current state. A free Passport exists and resolves whether or not you use any AEC. For this family: An SDK or package you actively manage in production, with live bindings and current state. AEC is one pool shared across your Agent, MCP, Plugin, API, SDK and logical Service & Workload identities, and your IoT product, model and fleet identities. Individual IoT device instances are counted separately, in IoT Fleet Capacity, and never consume AEC. - AEC never makes an identity more verified. - AEC never replaces a Passport. - AEC never changes an ECZ-ID. Your ECZ-ID does not change. - Running out of AEC never deletes, revokes or unpublishes an identity. Prices and what can be bought today come from TrustOps, which owns every purchase, entitlement and renewal. ## Works alongside ECZ-ID complements your frameworks, protocols, OAuth, cloud IAM and workload identity. It replaces none of them and stays outside the execution path. - Package registries — npm, PyPI, Maven, NuGet and others: One publisher-linked identity for the library across every registry it is published to. (replaces: false) - Source repositories: A binding from the repository to the enduring subject, recorded with where it was learned. (replaces: false) ## Optional capabilities (none is required to hold a Passport) - Parent VERIFIED and ASSURED: Independent verification of the organisation behind your Passports. VERIFIED suits production use; ASSURED is the higher-assurance posture for larger or more sensitive estates. Boundary: It verifies your organisation. It never verifies an agent, a server or any other child identity, and it never changes an ECZ-ID. Included free: Every Passport starts with a free DECLARED Parent — created for you if your organisation has none. - SDK Publisher & Provenance: Publisher identity and provenance across the SDKs and packages you publish. Boundary: Provenance records where a package came from. It is not a security audit of its code. - PulseGuard: Current-state evaluation for the entities you operate. Paid tiers extend evaluation across more entities and more evaluations each month. Boundary: It reports state. It is not a safety verdict, and it never changes an identity or its tier. Included free: On-demand and event-driven evaluation of your own entities. - EvidenceCore (part of the ECZ-ID V2 build): The evidence behind each claim on a record: what supports it, where it came from, when it was checked and who may see it. Boundary: Evidence supports a claim. It does not make the claim true, and it never turns a declaration into a verification. Included free: Essential evidence references are part of every free Passport. - LedgerCore: Tamper-evident retention of decisive lifecycle evidence — issuance, activation, material bindings, authority changes, suspension and revocation — with eligible evidence anchored to a permissioned, append-only ledger. Boundary: An anchor shows an entry has not been altered since it was written. It does not make the statement inside it true. Included free: Essential LedgerCore evidence is kept for every identity, free ones included. - Digital Entity Graph and Graph Intelligence: The public-safe relationships between your organisation, its Passports and their bindings. Graph Pro, Graph Business and Enterprise Graph Intelligence add scale, history and custom analysis above the free view. Boundary: A relationship in the graph is a published link, not an endorsement of either end. Included free: Basic Graph participation and a current one-hop view. ## Related identities - ECZ-ID API Passport™: Most SDKs wrap an API. The API keeps its own identity, whichever SDKs call it. - ECZ-ID Plugin Passport™: SDKs are the building blocks of plugins, and each plugin is identified in its own right. - ECZ-ID Service & Workload Passport™: Libraries run inside services and workloads, which are separate enduring subjects. ## Resolving a record Human record: https://resolver.ecocitizenz.org/p/{ecz_id} Machine record: https://api.ecocitizenz.com/api/p/{ecz_id}.json Public reads are free and need no account. ## This site's operator EcoCitizenz Ltd, company number 17348848, England and Wales ECZ-ID: ECZ-GB-RBS1NW Human: https://resolver.ecocitizenz.org/p/ECZ-GB-RBS1NW Machine: https://api.ecocitizenz.com/api/p/ECZ-GB-RBS1NW.json The operator's record is proof about the company that runs this site, not about any visitor or any Passport they hold. ## Machine-readable surfaces on this host Family site description: https://sdk.ecocitizenz.com/products.json schema ecz.website_family_site.v2 — what the family is, the free Passport, acquisition state, AEC, optional capabilities and where to act on each. It carries no paid prices and establishes nothing about any ECZ-ID. Routes: https://sdk.ecocitizenz.com/sitemap.xml This file: https://sdk.ecocitizenz.com/llms.txt ## Pages - https://sdk.ecocitizenz.com: What an ECZ-ID SDK Passport is, what the free identity includes, and the current availability of its door. - https://sdk.ecocitizenz.com/free-sdk-passport: The free SDK Passport in full: what it establishes, the operator relationship, the five-step flow, and the boundaries. - https://sdk.ecocitizenz.com/products: Every product a SDK Passport holder can add, grouped by what it does, with each item's real purchase state read from the TrustOps commercial registry. - https://sdk.ecocitizenz.com/pricing: What everything costs in GBP excluding VAT, and the four rules that make the numbers mean what they say. The Passport itself is free. - https://sdk.ecocitizenz.com/passport-everywhere: Where an ECZ-ID travels: the share page and machine record we serve, the badge and QR, and the places you publish it yourself. Each marked as something we serve or a pattern you implement. - https://sdk.ecocitizenz.com/identity-over-time: What was true when you checked, what changed, and whether it is still the same logical entity — and what a free Passport does not include. - https://sdk.ecocitizenz.com/after-your-passport: The journey after issuance: publish the proof, bind native identities, inspect relationships, and open the console. - https://sdk.ecocitizenz.com/verify: Resolve an ECZ-ID, and how to read a public record without over-reading it. - https://sdk.ecocitizenz.com/aec: AEC — Active Entity Capacity: what counts as an actively managed entity, the one pool across families, and what AEC never changes. - https://sdk.ecocitizenz.com/interoperability: The protocols and identity systems an ECZ-ID sits beside, and what it explicitly does not replace. - https://sdk.ecocitizenz.com/parent: Parent DECLARED, VERIFIED and ASSURED — and why none of them verifies the subject of a child Passport. - https://sdk.ecocitizenz.com/packages: Registry channels and the canonical repository as bindings, and releases as history rather than new identities. - https://sdk.ecocitizenz.com/provenance: SDK Publisher and Provenance: what provenance records about a package, and the security audit it is not. - https://sdk.ecocitizenz.com/enterprise: Estate, partner and procurement arrangements, agreed directly rather than bought online. - https://sdk.ecocitizenz.com/privacy: Exactly what this site collects and what it structurally cannot collect. - https://sdk.ecocitizenz.com/security: The response headers this origin sets, the build-time preflight, and where identity truth actually lives. ## Elsewhere in the estate Developer Gateway (technical integration reference): https://developers.ecocitizenz.com Resolver (public, read-only proof): https://resolver.ecocitizenz.org TrustOps (acquisition, payment, entitlement): https://trustops.ecocitizenz.com ## Not published here This host serves a website. It does not serve an agent endpoint, so it publishes no A2A Agent Card and no agent manifest describing itself as an agent. It publishes no family-specific protocol manifest either: none exists for the SDK family in the ECZ-ID architecture, and inventing one for symmetry with another family would be a machine-readable claim that is simply untrue. There is no start URL for the SDK Passport on this host, because the SDK door is not open on this estate. A machine reading this file should record the family's acquisition state from /products.json and re-read it rather than assuming this file is current.