One Passport. One PPID. Resolved by every OWOS app.
OVIN — the OWOS Verified Identity Network — is the root identity authority for the federation. Every Passport issued here is the canonical reference that Guardian, Calendar, OVBP, OVAK, OIVN and OCLL resolve against. No application issues identity locally, ever.
PPID
A human-readable Passport ID (OWOS-XXXX-XXXX) plus an immutable passport_id. Generated server-side here, nowhere else.
Support ID
Every identity also carries a public SUP-XXXXXX Support ID. Apps and support staff use it publicly — your PPID stays private.
Root QR registry
Exactly one active Root QR per Passport, across every class. Rotations keep history as revoked records; apps verify by fingerprint.
Federation resolution
Federation apps resolve a passport_id for status, class and active QR fingerprint. Privacy-safe by default — no PII crosses apps.
Signed module contracts
Modules authenticate with HMAC-signed requests and ES256 actor tokens against a published JWKS. Suspended modules fail closed.
Append-only audit
Every issuance, rotation, link, claim and revocation is recorded forever. No deletes — status changes only.
User-controlled app links
You decide which federation apps your Passport is linked to, approve connection requests, and revoke access at any time.
Markers, not scoring
Identity records raw system markers only. Trust scoring lives in the OWOS kernel, never inside the identity authority.
Ownership graph
Human → Business → Structure, Asset and Vehicle relations are append-only and resolvable, so authority survives ownership changes.
Passport classes
Seven canonical classes. Human is publicly live today; the rest are in internal preview while their claim and review flows finish hardening.
- internal previewBusinessOperating entity authority
- internal previewCharityNonprofit steward identity
- internal previewStructureFixed property identity
- internal previewAssetHigh-value durable goods
- internal previewVehicleTitled mobile assets
- internal previewEventTime-bound entity identity
The federation
Each OWOS module stays operationally isolated. They come back here for one thing: who this Passport is, and what it is allowed to do.
- reservedWorkJobsite + work history
- reservedMarketVerified marketplace
- reservedImpactImpact allocation
