{
  "schema": "varexis-public-evidence-record/0.3",
  "generated_at_utc": "2026-10-06T23:09:49Z",
  "record_id": "VXI-EXT-SPIFFE-05-v1",
  "record_kind": "external_reference",
  "title": "SPIFFE: Workload API caller checks",
  "system": "SPIFFE",
  "evidence_family": "identity_access",
  "index_status": "PUBLIC_SAFE_SOURCE_REVIEW",
  "evidence_state": "PRIMARY_DOCUMENTATION_REVIEW_ONLY",
  "canonical_question": "Does the Workload API's lack of an explicit client secret mean caller checks are unnecessary?",
  "near_questions": [
    "Why can a Workload API omit an explicit client secret?",
    "Who identifies the workload calling the identity endpoint?",
    "Does no client handshake mean no authentication?",
    "What should an agent check about identity endpoint access?",
    "Can an exposed Workload API be assumed safe?",
    "How should endpoint caller checks be documented?",
    "What evidence supports a caller-identification claim?",
    "Can a receipt distinguish interface design from secure configuration?",
    "Does local endpoint access prove workload identity?",
    "Which record explains out-of-band workload identification?",
    "What must a buyer provide to assess endpoint trust?",
    "Can protocol compliance alone validate the host's caller checks?"
  ],
  "supported_claims": [
    {
      "claim": "The Workload API specification places caller identification on the endpoint implementation through out-of-band checks. Lack of an application-level secret does not mean callers may be accepted without identification.",
      "reliance": "DOCUMENTED_CAPABILITY_ONLY"
    }
  ],
  "not_demonstrated_claims": [
    "anonymous access as the intended trust model",
    "caller identification verified in a named deployment",
    "security from endpoint reachability alone"
  ],
  "public_summary": "The Workload API specification places caller identification on the endpoint implementation through out-of-band checks. Lack of an application-level secret does not mean callers may be accepted without identification.",
  "related_record_ids": [
    "VXI-EXT-SPIFFE-01-v1",
    "VXI-EXT-SPIFFE-02-v1",
    "VXI-EXT-SPIFFE-03-v1",
    "VXI-EXT-SPIFFE-04-v1"
  ],
  "source_review": {
    "source_type": "official_external_documentation",
    "source_title": "SPIFFE Workload API",
    "source_url": "https://spiffe.io/docs/latest/spiffe-specs/spiffe_workload_api/",
    "checked_on": "2026-10-07",
    "candidate_record_id": "VXI-EXT-SPIFFE-05-v1",
    "candidate_record_sha256": "13b443363e5ecfb03f16714748039547bcb1b6cdbb8d05d3dbe1d0172863237e",
    "method": "Primary documentation reviewed for the published bounded statement.",
    "deployment_tested_by_varexis": false,
    "revalidation": "Recheck the primary source, version and deployment context before paid delivery."
  },
  "answer_policy": {
    "classification": "DOCUMENTED_WITH_DEPLOYMENT_BOUNDARY",
    "bounded_answer": "The Workload API specification places caller identification on the endpoint implementation through out-of-band checks. Lack of an application-level secret does not mean callers may be accepted without identification.",
    "required_buyer_context": "Endpoint exposure, caller identification method and the identities allowed for that caller.",
    "missing_evidence": "A broader claim needs evidence matching the intended use. Payment does not upgrade the evidence state."
  },
  "private_boundary": "Raw logs, thresholds, private paths, source code, protected mechanisms and reconstruction-level details are excluded from public and paid delivery.",
  "paid_access_note": "The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.",
  "service_route": {
    "request_guide": "/varexis-index/request.html",
    "request_workflow": "/varexis-index/request-workflow.json",
    "service_id": "evidence_receipt",
    "service_routes_url": "/varexis-index/service-routes.json",
    "payment_required": true,
    "accepting_paid_requests": true,
    "operational_status": "PAID_ASYNC_MANUAL_FULFILMENT",
    "checkout_url": "https://buy.stripe.com/28EaEXaPe7bBdGLgXSdwc05"
  },
  "authority_boundary": "VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.",
  "human_page": "/varexis-index/catalog.html#spiffe-caller-identification",
  "machine_readable_record": "/varexis-index/records/spiffe-caller-identification.json"
}
