Skip to content
ECZ-IDIoT

Free identity

The free IoT Passport

One IoT Passport covers one physical device, or one device identity module — a fleet is many Passports, and a firmware version is never one. This page is the whole of what the free identity establishes, and the four things it deliberately does not say.

Current availability

The IoT door is not open yet.

The IoT Passport is free — £0, permanently, and never sold. That is the price, and it is not what is missing. What is not ready is the door: ECZ-ID Core is not issuing IoT Passports yet, and the Resolver is not projecting IoT records yet.

So this site publishes no start link, no waiting list and no date. When both are live, the family is opened through one configuration value in the Website Factory and the control appears on every page here at once. No page on this site is rewritten to do it.

Nothing on this site can be bought in the meantime. Paid capabilities are described here and configured in TrustOps, which owns every purchase.

How an ECZ-ID resolves, and what a record is not

Read this as carefully as the rest

An ECZ-ID does not replace any of these

An ECZ-ID IoT Device Passport is a persistent, resolver-verifiable identity for something you operate. It records who operates it, what has been declared and bound, and what the current public state is. It is not a substitute for, and must never be presented as replacing:

  • device security
  • network security
  • authentication
  • firmware security
  • safety engineering
  • device-management platforms

An ECZ-ID does not make a device safe, secure or correct, and it is not a certification, approval or test result. Your policy decides what to do with what the record says.

The subject

One IoT Passport is one connected device

One IoT Passport is one physical device, or one device identity module, operated by your organisation. A fleet is many Passports.

What never becomes a second Passport

Firmware versions, MAC and IP addresses, and the gateways and hubs a device registers with are not separate Passports.

The shape of the identifier

ECZ-XX-XXXXXX::IOT_DEVICE-XXXXXX

A pattern, not a real record. The Parent identifier comes first and the child follows the :: separator.

Included

What the free Passport establishes

£0 · No card required · Permanent, not a trial.
  • A persistent ECZ-ID for the connected device.
  • Your organisation on the record as its operator — a free DECLARED Parent is created if you do not already have one.
  • A public Resolver record anyone can open, and the same record as machine-readable JSON.
  • A badge, a QR code and a share link.
  • Basic bindings to the public places your connected device already appears.
  • Lifecycle and current public state, evaluated on demand.
  • Claim and recovery.
  • Basic participation in the Digital Entity Graph.
  • Essential lifecycle evidence, kept in LedgerCore.

Publishing the record is your decision. Nothing becomes public until you consent, and you can withdraw publication later.

The flow

How you would get one

Five steps, and only the first two need anything from you.
  1. Create or claim the identity

    Start in TrustOps with one sign-in. Your organisation's free DECLARED Parent is reused or created, and the connected device gets its ECZ-ID.

  2. Configure and bind

    Add the public places your connected device already appears — a manufacturer product page or published device documentation. Each binding records where it was learned.

  3. Prove it on the Resolver

    Anyone can open the public record and its JSON, with no account and no API key — and re-check it before relying on it.

  4. Operate

    Publish the ECZ-ID where people and machines already look, and manage it from your ECZ-ID console.

  5. Strengthen, only if useful

    Parent verification, monitoring, evidence and authority are optional. None is needed to hold a Passport.

The boundary

What the Passport deliberately does not say

These four distinctions are the whole reason the record is worth reading. A page may shorten its own copy; it may not weaken these.
  • DECLARED ≠ VERIFIED

    A DECLARED record states what your organisation says about itself, with the date it said it. It is not the outcome of an independent check.

  • Identity ≠ Binding

    The Passport identifies the connected device. A binding records a public place it already appears. Adding a binding never creates a second identity.

  • Binding ≠ Authority

    A binding shows that a relationship has been declared. It does not grant, prove or imply authority to act.

  • Parent verification ≠ IoT verification

    A VERIFIED or ASSURED Parent verifies your organisation. It does not verify the connected device.

An ECZ-ID does not make anything safe, certified, approved or compliant, and holding one does not make you compliant with anything.

A Resolver record is not proof. It publishes what is currently declared and what evidence exists, with the time it was read — is_proof is false and recheck_before_reliance is true. Re-check before you rely on it.