Skip to content

depth_insufficient

HTTP 403 · Ludion-Error: depth_insufficient

Your signature verified: the Gate knows which agent you are. This route also asks for a minimum Depth, the level of trust the Ludion Registry records for an agent, and yours is lower. An agent that signs with Web Bot Auth but has not registered is at D0.

Depth What it takes
D0 A valid Web Bot Auth signature
D1 Registered keys, a confirmed contact, and the Ballast v0 commitments (free)
D2 D1 plus identity verification of the operator (a person or a company)
D3 D2 plus Ballast v1, which Ludion does not offer yet
D4 D3 plus 90 days without incidents and a third-party audit (spec §13.4)

Depth lets a site open its most sensitive routes (payments, accounts) to agents whose operators can be reached and held to account, without learning who they are. The site sees a level, not a name.

  • Register your Diver with the Registry once registration opens. npx ludion register approves your Session key and fetches a Staple that carries your Depth; send it with every request (npx ludion sign and the SDK do).
  • D2 and above involve checks by outside providers. The rules for each level are public, and a lowered Depth always comes with a reason and a way to appeal.

Ludion does not replace Web Bot Auth: any agent that signs requests with Web Bot Auth (RFC 9421) and publishes its key directory is already VERIFIED by Ludion Gates, at depth 0. If you have not signed anything yet, the free Ludion CLI gets you there.

Three minutes is our target for this path, written down as the check DIV-1: in a clean container, from init to VERIFIED within 180 seconds.

  1. Create your agent identity (a Diver). The Root key is sealed with your passphrase and never signs a request; a short-lived Session key does.

    Terminal window
    npx ludion init --name "My Agent" --contact mailto:you@example.com
  2. Publish the public files it wrote at your Signature-Agent origin over HTTPS: .well-known/http-message-signatures-directory (your keys, served as application/http-message-signatures-directory+json) and card (who you are). Your own domain works; so will dvr-….agents.ludion.ai once registration opens.

  3. Sign each request. This prints a ready-to-run curl with the Signature-Agent, Signature-Input and Signature headers; a signature lives 60 seconds (spec §10.4), so make a new one per request.

    Terminal window
    npx ludion sign GET https://shop.example/checkout --curl
  4. Check yourself. doctor fetches your published directory and Card and checks what a Gate checks: a 200 without redirects, the content type, and your current key in the directory.

    Terminal window
    npx ludion doctor

A Gate now classifies your requests as VERIFIED. What a site additionally asks for (Depth, Ballast, a Mandate) is on top of that; each has its own page among the Gate errors.