Autonym specification
spec v0.1-draftApache-2.0
Reading this document
Normative language follows RFC 2119: MUST, SHOULD and MAY carry their defined meanings. Levels are written L0 to L3. Machine values, keys, scopes and paths are set in monospace. Examples are informative unless stated otherwise.
- L0CategoriesCategories only, no values
- L1PreferencesPreferences and needs, no direct identifiers
- L2NamedFirst names and household relationships
- L3IdentifiedIdentifying details
Contents
- 1Scope and terminology
- 2Handles and discovery: the
autonym:scheme and/.well-known/autonym - 3The record: entries, provenance, temporal attributes, conflict rules
- 4Domains and vocabulary v1
- 5Disclosure levels and the compiler
- 6Authorisation: OAuth 2.1, grants, scopes, delegation, revocation
- 7MCP surface
- 8REST API
- 9Errors
- 10Purge instructions
- 11Export, import and migration between hosts
- 12Recipient registry (Phase 2, placeholder)
- 13Emergency card (Phase 2, placeholder)
- 14Connectors and the observed lane (Phase 2, placeholder)
- 15Conformance profiles: Core, Write, Portable, Delegated
- 16Change process
Standards this builds on
Autonym does not define its own cryptography, authorisation or vocabularies where mature ones exist. A level is a human-facing name for a set of selectively disclosed claims: the person and the recipient see levels, the cryptography sees claims.
| Component | Standard |
|---|---|
| Agent delivery | Model Context Protocol |
| Authorisation and tokens | OAuth 2.1 with PKCE, RFC 7591, RFC 8414, RFC 9728, DPoP |
| Credentials and selective disclosure | SD-JWT VC over W3C Verifiable Credentials 2.0 |
| Presentation to wallets and services | OpenID4VP and OpenID4VCI |
| Health emergency subset | International Patient Summary (EN 17269 / ISO 27269), SNOMED coding |
| Accessibility vocabulary | ISO/IEC 24751 |
| Travel loyalty | IATA One ID |
How to cite
Autonym specification v0.1 draft. New Media Solutions Ltd, 2026. https://autonym.dev/spec