V0.1

Binding and provisioning lifecycle

Binding establishes a consumer-local association through a protected ceremony. It does not grant ongoing Passport authority.

Challenge and assertion

IP-BIND-01 — One-time challenge. The consumer creates an unpredictable challenge tied to its current Account/session generation, consumer instance, purpose, expected mapping version, and (for a Subordinate binding) exact reference and target. It expires and is consumed at most once. [Resolver contract, Challenge and assertion issuance; ADR 9F-A.]

IP-BIND-02 — Trusted issue. Only a trusted Passport issuer creates binding evidence after fresh Principal authentication and current Account/Principal association validation. A Subordinate bind also evaluates complete current exact-target IdentityResolve Use authority. [ADRs 8K-A, 8L-A, 8S-A, 8T-A.]

IP-BIND-03 — Bound claims. Evidence binds issuer, audience/consumer instance, purpose, challenge/assertion ID, issue/expiry, distinct Account and Principal, relevant security/association generations, and exact consumer reference/target when applicable. Cryptographic encoding is profile-specific. [Resolver contract, Challenge and assertion issuance; ADRs 8S-A, 9F-A.]

Live acceptance and local installation

IP-BIND-04 — Live acceptance. Signature verification alone is insufficient. Passport rechecks current issuer trust/status, audience, purpose, challenge, exact claims, expiry, replay/revocation state, current Account/Principal association and security generation, and exact-target authority before accepting. Acceptance is single-use and records an opaque receipt. [ADRs 8K-A–8M-A, 8S-A, 8T-A, 9F-A.]

IP-BIND-05 — Stable retry. Repeating the same acceptance operation ID returns the same receipt idempotently. Re-presenting an accepted assertion with a different operation ID is replay and is rejected. [ADR 9F-A; resolver contract, Live Passport acceptance contract.]

IP-BIND-06 — Separate commits. Passport acceptance and consumer mapping installation are distinct committed facts in separate databases. The receipt proves Passport acceptance only. The consumer revalidates challenge/session/context/mapping versions and performs local mapping update plus audit atomically under compare-and-swap. [ADRs 8H, 9F-A.]

IP-BIND-07 — No implied authority. Neither an assertion, receipt, nor local mapping grants a later resolve or protected action. Each later operation evaluates current authority. [ADRs 8G–8H.]

IP-BIND-08 — Uncertain local result. If the local commit is uncertain, check the local idempotency record; report installation only when mapping and audit are known committed. Retry only the same local operation with the same Passport receipt. If challenge or expected version changed, require fresh proof. A post-acceptance revocation does not erase the acceptance record, but cannot authorize future resolve. [Resolver contract, Local installation and cross-database behavior; ADR 9F-A.]

The Passport acceptance commit is not by itself the complete local provisioning result. Do not describe the two stores as distributed-atomic.