OAuth, CIMD and ID-JAG
CIMD server resolution, ID-JAG mint and redeem, RFC 9207 issuer handling, client creation and a dual-era OAuth-protected MCP server binding are implemented and tested in VerifableSystem. On 10 August 2026, Lumoin committed Verifable to the OpenID AIIM MCP Security Interoperability Event. The current /mcp/{segment} binding has four tools: resolve_did, sparql_query, public dpp_chain_walk and governed product_passport_get. The passport read derives caller, tenant, represented principal and disclosure tier from the validated token, applies AuthZEN and records trace-linked dpp.passport.read action evidence. This public origin advertises no callable endpoint and has no accepted partner result. The full product contract keeps represented authority, per-operation policy, permitted disclosure and attributable evidence together whenever a governed product operation is bound. Commitment is not certification.