C=US Trust Registry
Anyone can ask C=US whether an agent is authorized, right now, to take an action on a resource, using the ToIP Trust Registry Query Protocol v2.0. The answer comes from the live directory by the same code the agent gateway uses to allow or refuse an agent's requests, so the two cannot disagree. Each answer is signed with the gateway's key and checked in this browser. Nothing a query sends can change a C=US decision.
Calling it yourself
curl -s https://cequs.com/trust-registry/authorization -H 'Content-Type: application/json' \
-d '{"entity_id":"wimse://cequs.com/agents/qc-maple-quality-001",
"authority_id":"https://cequs.com/trust-registry",
"action":"maple.lot.grade.propose","resource":"lot:qc:2026:017"}'
The answer carries the TRQP fields (authorized, time_requested, time_evaluated, message) plus a c_us block naming the agent's directory entry, the grant that covers it, and validUntil (five minutes). The proof is an Ed25519 signature over the rest of the answer as canonical JSON, under the key published at /agent-gateway/status. POST /trust-registry/recognition answers whether C=US recognizes another authority; today that is only the chained c=CA directory (https://cequs.com/trust-registry/c=CA, action directory.chain, resource c=CA). Errors are RFC 7807 problem objects.
Answers are for the present only: the directory keeps no history, so time_evaluated is always now. "Authorized" means an agent presenting its bound, unexpired certificate would be allowed; it does not prove that whoever holds the identifier holds the key. The registry is open, so it shows which demonstration agents hold which grants; a real deployment might require callers to identify themselves. At most 120 queries a minute are answered.