Operational overview

XCIM Network

Public technical state for XCIM verification.

An XCIM reference issuer sandbox is operating through Emabled. The shared multi-issuer registry, public transparency roots, anchor feed and reference resolver remain unpublished; this page keeps those network-layer boundaries explicit.

ENVIRONMENT: REFERENCE SANDBOXPROTOCOL: DRAFT v0.1REFERENCE XCIM CONSENT ISSUER: OPERATIONALUPDATED: 2026-08-13

Component state

Public XCIM and reference implementation components
Component State Last update Evidence or dependency
Emabled issuer API Operational sandbox 2026-08-13 Readiness endpoint ↗
Emabled issuer keys Published 2026-08-13 Ed25519 key set ↗
Hosted consent Operational sandbox 2026-08-13 Issuer-hosted flow on consent.emabled.com
Identity Evidence metadata Profile-based 2026-08-13 Profile-qualified status JSON
Shared issuer registry Not public 2026-08-13 Schema and conformance policy pending
Public event/state roots Not published 2026-08-13 Normative proof algorithms pending
Public anchor feed Not published 2026-08-13 Test-network profile pending
Reference resolver Not released 2026-08-13 Vectors and verification profile pending

What is live

Emabled currently exercises application registration, issuer-hosted consent, signed receipts, revocation processing, webhooks, public issuer keys and an OIDC-backed identity-evidence path inside an isolated reference sandbox. XCIM's identity layer is being generalized so receipts can record profile-qualified Identity Evidence, including an experimental EVP-01 profile, without changing receiver-side permission semantics.

What is not live

XCIM does not yet operate a production trust network. A healthy reference issuer does not make unavailable registry, root, anchor or resolver components healthy by implication.

Identity-evidence boundary

EVP and OIDC are used when permission is granted, not as per-message dependencies for receivers. A receiver validates the XCIM Consent Issuer's signed receipt, current permission state, current application/domain bindings and local trust policy. It does not need to rerun EVP for every email.

Machine-readable status · Operator and continuity · Incident record