# ECZ-ID Plugin > A free, permanent ECZ-ID for one logical plugin, extension, action or store app, linked to the organisation that publishes it and published on a resolver anyone can re-check. Each marketplace listing becomes a binding, not a second identity. > Website Factory V2 family site. Site: https://plugins.ecocitizenz.com ## The ECZ-ID Plugin Passport™ For publishers of agent plugins, editor extensions, GPT actions, store apps and GitHub Actions. The same plugin appears in several marketplaces under several accounts. One public ECZ-ID ties them together, and each listing becomes a binding rather than a separate identity. - One Plugin Passport is one logical plugin, extension, action or store app your organisation publishes. - Releases, versions and individual store listings of that plugin are not separate Passports. - Identifier shape: ECZ-XX-XXXXXX::PLUGIN_PASSPORT-XXXXXX ## Getting one Price: FREE (£0). No card required. Permanent, not a trial. The free Plugin Passport door is not open on this estate yet. No start URL is published. Included: - A persistent ECZ-ID for the plugin. - Your organisation on the record as its operator — a free DECLARED Parent is created if you do not already have one. - A public Resolver record anyone can open, and the same record as machine-readable JSON. - A badge, a QR code and a share link. - Basic bindings to the public places your plugin already appears. - Lifecycle and current public state, evaluated on demand. - Claim and recovery. - Basic participation in the Digital Entity Graph. - Essential lifecycle evidence, kept in LedgerCore. ## Boundaries — load-bearing, do not drop them - DECLARED ≠ VERIFIED: A DECLARED record states what your organisation says about itself, with the date it said it. It is not the outcome of an independent check. - Identity ≠ Binding: The Passport identifies the plugin. A binding records a public place it already appears. Adding a binding never creates a second identity. - Binding ≠ Authority: A binding shows that a relationship has been declared. It does not grant, prove or imply authority to act. - Parent verification ≠ Plugin verification: A VERIFIED or ASSURED Parent verifies your organisation. It does not verify the plugin. - A Resolver record is not proof. It publishes what is currently declared and what evidence exists, with the time it was read — is_proof is false and recheck_before_reliance is true. Re-check before you rely on it. - No public ECZ-ID found is not a finding. It means the identifier resolves to no published record — nothing more. - An ECZ-ID does not make anything safe, certified, approved or compliant, and holding one does not make you compliant with anything. ## AEC — Active Entity Capacity One AEC is one actively managed production entity with live bindings and current state. A free Passport exists and resolves whether or not you use any AEC. For this family: A plugin you actively manage in production, with live bindings and current state. AEC is one pool shared across your Agent, MCP, Plugin, API, SDK and logical Service & Workload identities, and your IoT product, model and fleet identities. Individual IoT device instances are counted separately, in IoT Fleet Capacity, and never consume AEC. - AEC never makes an identity more verified. - AEC never replaces a Passport. - AEC never changes an ECZ-ID. Your ECZ-ID does not change. - Running out of AEC never deletes, revokes or unpublishes an identity. Prices and what can be bought today come from TrustOps, which owns every purchase, entitlement and renewal. ## Works alongside ECZ-ID complements your frameworks, protocols, OAuth, cloud IAM and workload identity. It replaces none of them and stays outside the execution path. - Extension and app marketplaces: One identity across every store, with each listing recorded as a binding rather than a second identity. (replaces: false) - Source repositories: A binding from the repository to the enduring subject, recorded with where it was learned. (replaces: false) - OAuth 2.x and OpenID Connect: A durable public record of the subject and its operator that outlives any token and needs none to read. (replaces: false) - Model Context Protocol (MCP): A resolvable identity for the agent and, separately, for each MCP server it uses — each with a named operator. (replaces: false) ## Optional capabilities (none is required to hold a Passport) - Parent VERIFIED and ASSURED: Independent verification of the organisation behind your Passports. VERIFIED suits production use; ASSURED is the higher-assurance posture for larger or more sensitive estates. Boundary: It verifies your organisation. It never verifies an agent, a server or any other child identity, and it never changes an ECZ-ID. Included free: Every Passport starts with a free DECLARED Parent — created for you if your organisation has none. - Plugin Publisher & Permission Integrity: Publisher-level identity and permission integrity across the plugins and apps you publish. Boundary: It records what you publish and declare. It is not a marketplace review and not an approval. - PulseGuard: Current-state evaluation for the entities you operate. Paid tiers extend evaluation across more entities and more evaluations each month. Boundary: It reports state. It is not a safety verdict, and it never changes an identity or its tier. Included free: On-demand and event-driven evaluation of your own entities. - EvidenceCore (part of the ECZ-ID V2 build): The evidence behind each claim on a record: what supports it, where it came from, when it was checked and who may see it. Boundary: Evidence supports a claim. It does not make the claim true, and it never turns a declaration into a verification. Included free: Essential evidence references are part of every free Passport. - LedgerCore: Tamper-evident retention of decisive lifecycle evidence — issuance, activation, material bindings, authority changes, suspension and revocation — with eligible evidence anchored to a permissioned, append-only ledger. Boundary: An anchor shows an entry has not been altered since it was written. It does not make the statement inside it true. Included free: Essential LedgerCore evidence is kept for every identity, free ones included. - Digital Entity Graph and Graph Intelligence: The public-safe relationships between your organisation, its Passports and their bindings. Graph Pro, Graph Business and Enterprise Graph Intelligence add scale, history and custom analysis above the free view. Boundary: A relationship in the graph is a published link, not an endorsement of either end. Included free: Basic Graph participation and a current one-hop view. ## Related identities - ECZ-ID Agent Passport™: Plugins extend agents. The agent a plugin serves is a separate subject with its own Passport. Free door (open): https://trustops.ecocitizenz.com/start/agent?source_surface=plugins-llms-related-agent - ECZ-ID MCP Passport™: Plugins frequently bundle or connect to MCP servers, and each server is identified in its own right. Free door (open): https://trustops.ecocitizenz.com/start/mcp?source_surface=plugins-llms-related-mcp - ECZ-ID API Passport™: Most plugins call an API. The API keeps one identity across every plugin that uses it. - ECZ-ID SDK Passport™: Plugins are built on SDKs and published as packages, each of which can carry its own publisher identity. ## Resolving a record Human record: https://resolver.ecocitizenz.org/p/{ecz_id} Machine record: https://api.ecocitizenz.com/api/p/{ecz_id}.json Public reads are free and need no account. ## This site's operator EcoCitizenz Ltd, company number 17348848, England and Wales ECZ-ID: ECZ-GB-RBS1NW Human: https://resolver.ecocitizenz.org/p/ECZ-GB-RBS1NW Machine: https://api.ecocitizenz.com/api/p/ECZ-GB-RBS1NW.json The operator's record is proof about the company that runs this site, not about any visitor or any Passport they hold. ## Machine-readable surfaces on this host Family site description: https://plugins.ecocitizenz.com/products.json schema ecz.website_family_site.v2 — what the family is, the free Passport, acquisition state, AEC, optional capabilities and where to act on each. It carries no paid prices and establishes nothing about any ECZ-ID. Routes: https://plugins.ecocitizenz.com/sitemap.xml This file: https://plugins.ecocitizenz.com/llms.txt ## Pages - https://plugins.ecocitizenz.com: What an ECZ-ID Plugin Passport is, what the free identity includes, and the current availability of its door. - https://plugins.ecocitizenz.com/free-plugin-passport: The free Plugin Passport in full: what it establishes, the operator relationship, the five-step flow, and the boundaries. - https://plugins.ecocitizenz.com/products: Every product a Plugin Passport holder can add, grouped by what it does, with each item's real purchase state read from the TrustOps commercial registry. - https://plugins.ecocitizenz.com/pricing: What everything costs in GBP excluding VAT, and the four rules that make the numbers mean what they say. The Passport itself is free. - https://plugins.ecocitizenz.com/passport-everywhere: Where an ECZ-ID travels: the share page and machine record we serve, the badge and QR, and the places you publish it yourself. Each marked as something we serve or a pattern you implement. - https://plugins.ecocitizenz.com/identity-over-time: What was true when you checked, what changed, and whether it is still the same logical entity — and what a free Passport does not include. - https://plugins.ecocitizenz.com/after-your-passport: The journey after issuance: publish the proof, bind native identities, inspect relationships, and open the console. - https://plugins.ecocitizenz.com/verify: Resolve an ECZ-ID, and how to read a public record without over-reading it. - https://plugins.ecocitizenz.com/aec: AEC — Active Entity Capacity: what counts as an actively managed entity, the one pool across families, and what AEC never changes. - https://plugins.ecocitizenz.com/interoperability: The protocols and identity systems an ECZ-ID sits beside, and what it explicitly does not replace. - https://plugins.ecocitizenz.com/parent: Parent DECLARED, VERIFIED and ASSURED — and why none of them verifies the subject of a child Passport. - https://plugins.ecocitizenz.com/marketplaces: One logical plugin across every marketplace, with each listing recorded as a binding rather than a second identity. - https://plugins.ecocitizenz.com/integrity: What a Plugin Passport says about permissions and integrity, and the approvals it is explicitly not. - https://plugins.ecocitizenz.com/enterprise: Estate, partner and procurement arrangements, agreed directly rather than bought online. - https://plugins.ecocitizenz.com/privacy: Exactly what this site collects and what it structurally cannot collect. - https://plugins.ecocitizenz.com/security: The response headers this origin sets, the build-time preflight, and where identity truth actually lives. ## Elsewhere in the estate Developer Gateway (technical integration reference): https://developers.ecocitizenz.com Resolver (public, read-only proof): https://resolver.ecocitizenz.org TrustOps (acquisition, payment, entitlement): https://trustops.ecocitizenz.com ## Not published here This host serves a website. It does not serve an agent endpoint, so it publishes no A2A Agent Card and no agent manifest describing itself as an agent. It publishes no family-specific protocol manifest either: none exists for the Plugin family in the ECZ-ID architecture, and inventing one for symmetry with another family would be a machine-readable claim that is simply untrue. There is no start URL for the Plugin Passport on this host, because the Plugin door is not open on this estate. A machine reading this file should record the family's acquisition state from /products.json and re-read it rather than assuming this file is current.