xChk: Bring Your Own Identity -- Heterogeneous Assurance with Verifier-Determined Sufficiency
Sean MacGuire
cs.CR, cs.CY
Submitted: 2026-07-15
Comments: 19 pages, 4 figures. Reference implementation at https://in.xchk.io; one documented RP (crabbyed.com, Appendix B)
Code: https://github.com/spiffe/spiffe
License: http://creativecommons.org/licenses/by/4.0/
The gist: We present xChk, a reference identity provider for Bring Your Own Identity (BYOI): users enroll via heterogeneous proofs (government KYC, corporate SSO, WebAuthn/FIDO2, professional networks, live
Terminology
Abstract
We present xChk, a reference identity provider for Bring Your Own Identity (BYOI): users enroll via heterogeneous proofs (government KYC, corporate SSO, WebAuthn/FIDO2, professional networks, live verification, longitudinal activity, behavioral signals) and disclose them as portfolio claims in standard OAuth 2.0 / OpenID Connect (OIDC) tokens, while each relying party applies its own sufficiency policy - the IdP transports claims and may evaluate an RP-supplied evidence policy for consent, but does not adjudicate access. Enrollment depth varies by modality (some paths are user-initiated; org KYB and officer binding are operator-assisted). xChk also supports human-in-the-loop attestation for high-risk actions: humans can initiate attestations directly (browser UI / POST /api/attestations), and AI agents acting under those principals can trigger the same gateway via scope-gated authorize/attest - hash-chained human approvals on a shared verification graph (humans via OIDC; agents via API keys). A production deployment at https://in.xchk.io ships both initiation paths with bilateral RP evaluation at consent; one documented relying party (https://crabbyed.com, Appendix B) exercises Login with xChk.
Sources
- Building the Web for Agents: A Declarative Framework for Agent-Web Interaction
- Behavioral Governance for Autonomous AI Agents: The AgentBound Framework
- Constructing Triangle Decomposable Multigraphs with Minimum Multi-edges
- OpenID Connect for Agents (OIDC-A) 1.0: A Standard Extension for LLM-Based Agent Identity and Authorization
- Context Lineage Assurance for Non-Human Identities in Critical Multi-Agent Systems
- AgentRiskBOM: A Risk-Scoping Security Bill of Materials for Agentic AI Systems
- Evolution of AI Agent Registry Solutions: Centralized, Enterprise, and Distributed Approaches
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs