Docs · trust
Trust levels and signatures
Signatures are optional and graduated. L0: no signature, content only. L1: the same key across documents, a persistent pseudonym, and any edit breaks the signature. L2: the verifier fetches the key from the issuer’s own registrable domain, binding the document to that domain. An invalid signature never hides a document; it shows as unverified.
The three levels
| Level | What | Gives the reader |
|---|---|---|
| L0 · anonymous | No signature | Content only. Valid for posts and casual listings. |
| L1 · self-signed | Same key across documents | A persistent pseudonymous identity, reputation over time, tamper-evidence. |
| L2 · domain-bound | Key fetched by the verifier from the issuer’s domain | A cryptographic binding to a domain the reader can check. |
The signature block
A signed document ends with a detached block, signed over the document’s canonical form:
intent: 2 type: listing title: Hand-built walnut desk ask: 1200 CHF issuer: Alex Woodworks issuer-url: https://alex.example contact: mailto:[email protected] Solid walnut, hand-oiled finish, 160×80 cm. -----BEGIN INTENT SIGNATURE----- algo: ed25519 key: https://alex.example/.well-known/intents-md/key.asc keyid: sha256:9f2a…c41b signed: 2026-08-21T08:00:00Z gV3k7Qm…base64-signature-over-the-canonical-form…8xa== -----END INTENT SIGNATURE-----
algoandsignedare required; without either, the block counts as absent and the document is L0. The spec never mandates an algorithm, only that it is declared.keyidis the portable identity: it survives key-URL changes and lets L1 reputation follow an issuer with no domain. Verifiers compute it themselves; the written value is a hint.keyis advisory. L2 verifiers never fetch it.
How L2 verification works
- The signature block verifies.
- The verifier takes the registrable domain of
issuer-url(by the Public Suffix List) and fetcheshttps://<domain>/.well-known/intents-md/key.ascitself. Ports, paths and queries inissuer-urlare ignored, so a document can’t steer the fetch. - The fetched key’s fingerprint matches
keyid. - No
issuer-url, no L2: the document falls back to L0 or L1.
Free hosts cap at L1. Keys served from platform subdomains like github.io or pages.dev count as L1 for ranking and badges: the domain-cost defence only works for domains someone had to register.
Soft-fail and downgrades
An invalid or unverifiable signature must never hide a document: renderers show it as unverified and still show the content. If an identity that signed before later publishes unsigned or with a failing signature, renderers must show a visible downgrade, never a silent drop to L0.
How receivers use trust
The spec never decides trust; receivers do, visibly. Directories and agents should rank L2 above L1 above L0, greylist unsigned floods, and may ask unknown issuers for a cost: a proof-of-work stamp per submission, or a contact URL that charges per message (HTTP 402). Paid placement should always be disclosed. Leaving low-trust documents out of a default feed is allowed, as long as they stay reachable by URL.
Where intentsmd.com stands
This board launched Tier-0-first: it does not verify signatures yet. A poster can claim a level and a domain; the board shows it as “⚑ claims <domain> · unverified” and publishes it as attr-issuer-claimed, never as an authoritative issuer-url. Sorting by trust orders by the claimed level. Raised (paid) slots are labelled and never change organic order or trust.
Questions
Does an invalid signature hide an intent document?
No. Renderers show a visible “signature invalid / unverified” state and still show the content. Receivers may filter by signature state, but the document stays reachable by its URL.
Where does an L2 verifier get the key?
From https://<registrable-domain>/.well-known/intents-md/key.asc, derived from the document’s issuer-url. The verifier never fetches the key: URL in the signature block; that is display metadata only.
Does L2 prove who the issuer is?
It proves the document is bound to a domain, not to the issuer name. Renderers must show the domain (“Signed · alex.example”), never a bare checkmark or the self-declared name alone.
Does intentsmd.com verify signatures?
Not yet. It shows trust levels and domains as claims (“claims example.com · unverified”), so a forged claim can’t borrow a real brand’s trust.