Anatomía de un pipeline de ver... Note

Anatomía de un pipeline de verificación de 12 etapas para credenciales de agentes IA

The Universal Trust Adapter (UTA) was designed with a 12-stage verification pipeline because simply checking a cryptographic signature is insufficient. A credential can be signed correctly but still be expired, revoked, have incorrect scope, come from an unknown issuer, lack proof of possession, or have questionable provenance. Each of these issues requires a distinct verification step. The twelve stages are PARSER, DETECT, SCHEMA, CRYPTO, ISSUER, KEY_BINDING, POP, PROVENANCE, LIFECYCLE, EVIDENCE, POLICY, and DECISION. The PARSER converts raw bytes into an internal format, while DETECT identifies the credential's type. SCHEMA validates mandatory fields, and CRYPTO verifies the digital signature. ISSUER resolves the issuer's identity, and KEY_BINDING ensures the signing key belongs to the declared issuer. POP confirms the presenter possesses the private key, and PROVENANCE traces the credential's origin. LIFECYCLE checks for expiration and revocation. EVIDENCE gathers supporting cryptographic information, and POLICY applies system-specific rules. Finally, DECISION combines all previous results for an overall verdict. Separating stages allows for debugging, partial caching, policy customization, and audits, providing observability and flexibility. The pipeline is implemented in TypeScript and can verify thousands of credentials per second. Treating credential verification as a pipeline, rather than a single step, prevents both invalid credentials from passing and valid ones from failing.