VeriFeed Working draft

VeriFeed · The Verifiable Agent Feed

A Feed a Subscriber Can Prove Is Complete

A signature proves an entry is genuine. It cannot show you that another entry was removed.

A Verifiable Agent Feed is an append-only sequence of entries published by one issuer. Each entry is Ed25519-signed and commits by hash to its predecessor. A subscriber walking a contiguous run from an anchor it holds establishes authenticity, integrity and completeness in one pass. A signed head fixes the feed at a position and exposes a later rewind. The payload is opaque: one format carries any agent's stream. Transport, storage and payload semantics belong to the consumer.

Properties

Three properties matter to a subscription channel. Two are widely solved. The third decides whether an agent can act on what it read.

Authenticity

The entries came from the claimed publisher

Each entry is Ed25519-signed by the issuer DID over its JCS-canonical bytes. RSS and Atom have no cryptographic answer. A signed webhook does.

Integrity

No entry was altered

entry_hash content-addresses the entry. Editing any covered field breaks the hash, the signature, or both. Absent from RSS, present in a signed webhook.

Completeness

Nothing was dropped or reordered

Entries are hash-chained by prev_hash with contiguous seq. A dropped entry, a reordered pair or a spliced-in foreign entry breaks the chain from the subscriber's anchor. A signed but unchained webhook cannot establish this.

The chain. Each entry commits to its predecessor's entry_hash and to its own content, with seq contiguous within a feed. Completeness follows from walking that chain: from genesis for end-to-end, or from a trusted signed head to start mid-stream. There is no Merkle tree — a decided non-goal, not a deferred feature.

Limits. A valid page establishes that the subscriber received an authentic, complete run of entries the issuer signed. It establishes nothing about whether those entries are true, and nothing about what the issuer showed anyone else. Completeness is also not currency: an issuer that freezes one subscriber's view has not tampered, rewound or forked, and no mechanism here detects it.

Application

The first-person case is an agent announcing what it can do. Announcement is cheap. Withdrawal is where the channel matters. A peer that learns an agent offers a capability, and never receives the withdrawal, keeps dispatching work to something retired. It cannot detect the omission: no withdrawal and no change look the same. Under a chained feed the omission breaks the walk.

The third-person case is a registry publishing its change log, where a dropped deregistration leaves a puller routing to a revoked agent. Both are specified in full under Payload Profiles.