revoked
HTTP 403 · Ludion-Error: revoked
What happened
Section titled “What happened”The signature was valid, but the key that made it, or the agent identity (Diver) behind it, has been revoked. Revocations come from the operator (for example after a key leak) or from the Registry when an operator breaks its commitments. Gates that subscribe to the revocation stream apply them within seconds; every other Gate when the last Staple expires, within an hour (spec §10.10).
Why this site asks
Section titled “Why this site asks”A revoked key may be in someone else’s hands. The site refuses it on every route that requires verification, so that a stolen key stops working everywhere at once.
How to fix it
Section titled “How to fix it”-
If you revoked a single Session key, rotate to a new one and publish the updated directory:
Terminal window npx ludion rotate -
If your whole identity was revoked because it was compromised, create a new one with
npx ludion init --forceand publish it. The old identity stays revoked. -
If the Registry revoked your identity and you believe it is a mistake, appeal: the Registry states a reason for every revocation it makes, and hears appeals.
Get verified in 3 minutes
Section titled “Get verified in 3 minutes”Ludion does not replace Web Bot Auth: any agent that signs requests with Web Bot Auth (RFC 9421) and publishes its key directory is already VERIFIED by Ludion Gates, at depth 0. If you have not signed anything yet, the free Ludion CLI gets you there.
Three minutes is our target for this path, written down as the check DIV-1: in a clean container, from init to VERIFIED within 180 seconds.
-
Create your agent identity (a Diver). The Root key is sealed with your passphrase and never signs a request; a short-lived Session key does.
Terminal window npx ludion init --name "My Agent" --contact mailto:you@example.com -
Publish the public files it wrote at your
Signature-Agentorigin over HTTPS:.well-known/http-message-signatures-directory(your keys, served asapplication/http-message-signatures-directory+json) andcard(who you are). Your own domain works; so willdvr-….agents.ludion.aionce registration opens. -
Sign each request. This prints a ready-to-run
curlwith theSignature-Agent,Signature-InputandSignatureheaders; a signature lives 60 seconds (spec §10.4), so make a new one per request.Terminal window npx ludion sign GET https://shop.example/checkout --curl -
Check yourself.
doctorfetches your published directory and Card and checks what a Gate checks: a 200 without redirects, the content type, and your current key in the directory.Terminal window npx ludion doctor
A Gate now classifies your requests as VERIFIED. What a site additionally asks for (Depth, Ballast, a Mandate) is on top of that; each has its own page among the Gate errors.