This page — the iqa:// URI reference · release 1.2.8
Normative here: AICENT-009 §10 (the iqa URI — syntax, ABNF, client requirements, registration status) and §11 (default dereference and operation safety). Everything below is verified offline, in your browser, from the envelope itself. Current packages: 1.2.8 on PyPI and npm, 1.2.8-alpha on crates.io — every asserted count (75 default · 78 with the Ed25519 backend · 32 on npm · 37/38 on crates.io) is reproduced by CI on every push.
V1.2.6 — archived release (superseded by 1.2.8)
Normative here: AICENT-009 §10 (the iqa URI — syntax, ABNF, client requirements, registration status) and §11 (default dereference and operation safety). Everything below is verified offline, in your browser, from the envelope itself.
Measured 2026-09-21: the 1.2.6 default (zero-dependency) install could not complete its self-test — verify_envelope raised NameError instead of returning its documented error when the optional Ed25519 backend was absent. Fixed in 1.2.7; 1.2.8 ships the expanded, fully runnable suite.
Aicent Stack narrative (v1.3.0) — non-normative
A separate narrative layer of the Aicent Stack is published alongside the specification. It is not part of the URI scheme's normative text, and it is not required to implement or to verify an envelope.
Verify, Don't Trust.
Paste an attestation envelope below. This page verifies it in your browser — crypto.subtle, no account, no network call, no server. [PASS] or it is not.
Citable standing — this page is [IQA-SPEC]
An iqa URI names the attestation state of a subject as reported by one of three named organs (forge · tss · gateway), without carrying the underlying proof. Reading the syntax establishes nothing about any subject — standing is established only by the seal and by the answering organ.
This is a Demo Center scenario, not the normative page.
The reference specification cited as [IQA-SPEC] lives at
iqa.org/URI; the standing
vocabulary it defines (ghost · probation · radiant · genesis, a closed set)
and the Table 1 safety classes are exactly what this verifier enforces.
This browser cannot verify offline.
No Ed25519 in crypto.subtle. Use a current Chrome / Edge / Safari 17+ / Firefox, or replay the vectors with npx @aicent/iqa / python -m iqa.selftest.
2 · Verify an envelope
3 · Seal a claim (your own key, generated in this tab)
3 · The 30-second loop — one address, three ways to know it
# ① machine side — a clean machine pulls this from the registry first:
$ npx @aicent/iqa
[PASS] all 32 checks passed (node, individual implementation)
one address: iqa://3f9a1b2c.gateway.iqa
│
┌─────────────┴─────────────┐
▼ ▼
③ web side (for humans) ② code side (for machines)
who the address is: where it goes:
organ · standing · action 4-byte route fingerprint
resolved above, live 5c378581 — pure computation
│ │
└────────────┬──────────────┘
▼
① 32 published vectors pin both → PASS