Authorization

PIC-X receives an OAuth access token at the selected realm token endpoint, validates it, and derives the initial PIC Context of Authority, or PCA. A PCA is the logical Context of Authority. Its signed representation is a PIC PCA COSE. PIC-X then returns a realm-signed PIC Token JWT carrying a settled PIC Continuity COSE in pic.root.

PIC-X stands for Provenance Identity Continuity Exchange.
Verifiable Authority Continuity across execution boundaries.
PIC has reached a point where the questions are becoming practical:
How can we use it? How can we test it? What should a real implementation look like?
Answering those questions requires more than specifications. It requires building the components that enable software engineers and architects to experiment with PIC in real systems.
On April 20–21, 2026, the 4th International Workshop on Trends in Digital Identity (TDI 2026) takes place in Verona. The workshop program also includes the talk “Provenance Identity Continuity (PIC): Secure Authority Propagation from Human and Non-Human Origins Across Trust Boundaries”, presented by Nicola Gallo and Antonio Radesca (Nitro Agility Srl).
On March 3, 2026, LF Decentralized Trust hosted the session “From Identity-First to Authority Continuity”, presented by Nicola Gallo.
On March 3, 2026, LF Decentralized Trust hosted the session “Trusted AI Agents by Design: From Trust Ecosystems to Authority Continuity”, presented by Nicola Gallo.