{
  "schema": "varexis-public-evidence-record/0.3",
  "generated_at_utc": "2026-10-06T23:09:49Z",
  "record_id": "VXI-EXT-SPIFFE-03-v1",
  "record_kind": "external_reference",
  "title": "SPIFFE: Identity material retrieval",
  "system": "SPIFFE",
  "evidence_family": "identity_access",
  "index_status": "PUBLIC_SAFE_SOURCE_REVIEW",
  "evidence_state": "PRIMARY_DOCUMENTATION_REVIEW_ONLY",
  "canonical_question": "What can a workload obtain through the SPIFFE Workload API?",
  "near_questions": [
    "How can a workload obtain SVIDs and trust bundles?",
    "Does Workload API support prove my endpoint is running?",
    "Can a client retrieve any identity it requests?",
    "What is the difference between an SVID and a trust bundle?",
    "Which material supports verification of another workload?",
    "How should a review handle missing workload identity material?",
    "Does API documentation establish a caller's entitlement?",
    "What context is needed to assess Workload API integration?",
    "Can an agent rely on an expired local identity cache?",
    "Which record covers workload identity retrieval?",
    "What should an identity retrieval receipt capture?",
    "Can retrieving a bundle replace verification policy?"
  ],
  "supported_claims": [
    {
      "claim": "The Workload API defines retrieval of workload identity documents and trust material. Availability and entitlement depend on the implementation and its configured caller identification.",
      "reliance": "DOCUMENTED_CAPABILITY_ONLY"
    }
  ],
  "not_demonstrated_claims": [
    "access to identities belonging to other workloads",
    "an available endpoint in a buyer's deployment",
    "automatic entitlement"
  ],
  "public_summary": "The Workload API defines retrieval of workload identity documents and trust material. Availability and entitlement depend on the implementation and its configured caller identification.",
  "related_record_ids": [
    "VXI-EXT-SPIFFE-01-v1",
    "VXI-EXT-SPIFFE-02-v1",
    "VXI-EXT-SPIFFE-04-v1",
    "VXI-EXT-SPIFFE-05-v1"
  ],
  "source_review": {
    "source_type": "official_external_documentation",
    "source_title": "SPIFFE Workload API",
    "source_url": "https://spiffe.io/docs/latest/spiffe-specs/spiffe_workload_api/",
    "checked_on": "2026-10-07",
    "candidate_record_id": "VXI-EXT-SPIFFE-03-v1",
    "candidate_record_sha256": "5eacadddc7b748329b37f72076613f221ee8884874fb75b11bf837399597d59d",
    "method": "Primary documentation reviewed for the published bounded statement.",
    "deployment_tested_by_varexis": false,
    "revalidation": "Recheck the primary source, version and deployment context before paid delivery."
  },
  "answer_policy": {
    "classification": "DOCUMENTED_WITH_DEPLOYMENT_BOUNDARY",
    "bounded_answer": "The Workload API defines retrieval of workload identity documents and trust material. Availability and entitlement depend on the implementation and its configured caller identification.",
    "required_buyer_context": "The enabled API profile, caller entitlement, returned material and deployment configuration.",
    "missing_evidence": "A broader claim needs evidence matching the intended use. Payment does not upgrade the evidence state."
  },
  "private_boundary": "Raw logs, thresholds, private paths, source code, protected mechanisms and reconstruction-level details are excluded from public and paid delivery.",
  "paid_access_note": "The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.",
  "service_route": {
    "request_guide": "/varexis-index/request.html",
    "request_workflow": "/varexis-index/request-workflow.json",
    "service_id": "evidence_receipt",
    "service_routes_url": "/varexis-index/service-routes.json",
    "payment_required": true,
    "accepting_paid_requests": true,
    "operational_status": "PAID_ASYNC_MANUAL_FULFILMENT",
    "checkout_url": "https://buy.stripe.com/28EaEXaPe7bBdGLgXSdwc05"
  },
  "authority_boundary": "VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.",
  "human_page": "/varexis-index/catalog.html#spiffe-workload-api-material",
  "machine_readable_record": "/varexis-index/records/spiffe-workload-api-material.json"
}
