identity-registry: registry

The registry ticket accumulates signed :identity attestations, each binding an IdP subject to an actor’s public key. The ticket is always in this stage — bindings are evidence, not workflow.

Recording a binding

Reading bindings

tik log <registry-id> shows every binding with its signature; tik verify <registry-id> checks them offline — no IdP call, ever.

see history · edit this page