Recognition Framework (prototype, version 0.1)
Files signed with Reconize that carry the creator’s accounts credential also carry a short signed statement, the recognition statement. This page says what it means.
What the statement says
It is signed by the Reconize registry’s recognizer key and says: the issuer did:web:id.reconize.me (Reconize’s accounts credential) is recognised as an identity claims aggregator, held to this framework, at assurance level IAL1, between two dates. It travels inside the file, so any checker can read it without contacting us.
What IAL1 means here
Account control. When the credential was issued, the creator signed in to each linked account, or published a code on it, or proved control of their website through DNS. Reconize does not check documents or government ID for this credential. A linked account shows that the same person controls that account; it does not prove their legal name.
Who is vouching
Today the recognizer is Reconize itself. That is a self-declaration, and the statement says so (basis: self-declared). It is not a CAWG trust list and not a third-party audit. It is a working prototype of the “stapled recognition statement” the CAWG Trust Task Force discussed in September 2026, offered so validators can test the format. If CAWG publishes a list of recognised aggregators, the statement can be signed by that list’s operator instead, with no change to files already signed.
How it is checked
Reconize on the Mac, reconize.me/verify and the Reconize browser extension check the signature against the recognizer’s published public key, check that the statement names the same issuer as the file’s accounts credential, and check that the statement held when the file was signed. The public keys are at https://relay.reconize.me/recognition/recognizer.jwk.json and the current statement at https://relay.reconize.me/recognition/statement.jws.
What it does not change
The accounts credential stands or falls on its own signature and revocation check. The recognition statement only adds who recognises that issuer and at what level. A file without one is not less authentic. A higher-assurance identity (an ID-checked certificate) is a separate path.