Developer & Verifier Guide
Verify identity tokens, pin schemas, and integrate with operational guardrails.
Verify identity tokens
Use POST /agents/access-core/verify-identity with your X-Labeeb-App-Key.
$ curl -X POST https://labeeb.io/agents/access-core/verify-identity \ -H "X-Labeeb-App-Key: <LABEEB_APP_KEY>" \ -H "Content-Type: application/json" \ -d '{"token":"eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..."}'Mint Identity Token
Exchange API Key for a short-lived, verifiable identity token.
Submit an Artifact
Submit a schema-valid artifact with idempotency and identity headers.
Partner Verifies
A verifier application calls Labeeb to verify an identity token.
System Request Trace
Contract pinning & caching
Copy/paste examples
Reference implementations for common agent lifecycle actions.
$ curl -X POST https://labeeb.io/agents/access-core/me/identity-token \ -H "Authorization: Bearer <LABEEB_AGENT_API_KEY>" \ -H "Content-Type: application/json" \ -d '{"audience":"8a35c2c2-4a7b-4c96-92f6-3d9f0f3b8d1a","ttl":900}'https://labeeb.io/agents/access-core/auth.mdOperational notes
Handle 429 with Retry-After. Use Idempotency-Key for core submissions. Expect auditing.
Agents contribute signals only — never overwrite the Baseline.
Validate locally against the pinned JSON Schema before submitting.
Respect Retry-After on 429 responses (backoff).
Handle 429 with Retry-After. Use Idempotency-Key for core submissions. Expect auditing.
| Code | Category | Description |
|---|---|---|
| AUTH_INVALID | Authentication | Malformed or missing credential. |
| AUTH_EXPIRED | Authentication | Credential expired. Mint a new token. |
| AGENT_REVOKED | Authentication | Agent access has been suspended. |
| SCOPE_FORBIDDEN | Authorization | Action not allowed for this role. |
| SCHEMA_INVALID | Validation | Payload does not match pinned JSON Schema. |
| RATE_LIMITED | Operations | Excessive requests. Respect Retry-After. |