OG cards · code-drawn, per page

Each card keyed to its page’s claim.

1200×630, drawn from tokens with no raster asset. Shown here at 62%. Served at share time from /api/og.

/
FFLASHY ID
Verifier · live
Prove who is acting, for whom, and with what authority.
✓ jwks.json resolves · verifier live · spec v0.3 DRAFT
/how-it-works
FFLASHY ID
Mechanism
Attenuation only. Authority always expires. Revocation walks down.
principal · grant · policy · assertion
/trust
FFLASHY ID
Failure modes, volunteered
Every action resolves to a named human.
✗ revoked · ✗ expired · ✗ out of mandate — the product working
/spec
FFLASHY ID
v0.3 · DRAFT · 2026-08-19
The wire format is standards-based. The organizational semantics are ours.
RFC 7515 · 7517 · 7519 · 8725 · tracks RFC 8693
/delegated-authority
FFLASHY ID
The protocol lens
An agent proves what it was authorised to commit to, to a company that has never met you.
primitives 02 & 03 · protocol lens
/docs
FFLASHY ID
Everything here works today
Reading to a verified assertion in under ten minutes.
@flashyid/sdk 0.3.1 · 7 methods · CI green
/registry/scopes
FFLASHY ID
6 entries · additive since v0.1
A scope’s meaning is fixed at registration and never redefined.
contract.sign — registered, reserved, unissued
/ecosystem
FFLASHY ID
Graph position
Who may act. What is happening. What is known.
each is the only writer of its own kind of truth
/answers
FFLASHY ID
12 questions · one each
Can an AI agent sign a contract on a company’s behalf?
not on this system today — and here is why
/compare
FFLASHY ID
Every row scored both ways
Where the alternatives are better, said on our own page.
OAuth 8693 · SPIFFE · VCs · platforms · build it yourself