Network Working Group B. Morrison Internet-Draft Alter Meridian Pty Ltd Intended status: Informational 9 August 2026 Expires: 10 February 2027 The 'alter' URI Scheme for Dispatchable ~handle References draft-morrison-alter-uri-scheme-02 Abstract This document defines the alter URI scheme as a dispatchable reference syntax for ~handle identity references published under the DNS substrate defined in [MCPDNS]. An alter: URI binds a textual ~handle reference to a resolution and verification procedure that retrieves the handle's envelope from the publishing zone, validates the envelope's signature chain, and dispatches the result to an operating-system URI handler. The reference may be scoped to an organisation, narrowed to a named facet of the identity, and addressed to a typed action surface. The scheme is the addressing form of the ~handle@org:facet/action reference; its resolution semantics are those of [MCPDNS], reused without modification. The scheme is provider-neutral, introduces no new cryptographic primitive, and reuses the resolution and verification procedures of [MCPDNS] without modification. The principal contribution is a single, self-verifying dispatch surface for handle-typed references: clicking, typing, or scanning an alter: URI yields a verified handle resolution rather than a free-text string or an unauthenticated fetch, and where an action is addressed it yields a verify-before- side-effect dispatch. This document requests provisional registration of the alter scheme with IANA per [RFC7595] Section 3. Status of This Memo This Internet-Draft is submitted in full conformance with the provisions of BCP 78 and BCP 79. Internet-Drafts are working documents of the Internet Engineering Task Force (IETF). Note that other groups may also distribute working documents as Internet-Drafts. The list of current Internet- Drafts is at https://datatracker.ietf.org/drafts/current/. Internet-Drafts are draft documents valid for a maximum of six months and may be updated, replaced, or obsoleted by other documents at any time. It is inappropriate to use Internet-Drafts as reference material or to cite them other than as "work in progress." Morrison Expires 10 February 2027 [Page 1] Internet-Draft alter URI Scheme August 2026 This Internet-Draft will expire on 10 February 2027. Copyright Notice Copyright (c) 2026 IETF Trust and the persons identified as the document authors. All rights reserved. This document is subject to BCP 78 and the IETF Trust's Legal Provisions Relating to IETF Documents (https://trustee.ietf.org/ license-info) in effect on the date of publication of this document. Please review these documents carefully, as they describe your rights and restrictions with respect to this document. Table of Contents 1. Introduction . . . . . . . . . . . . . . . . . . . . . . . . 3 1.1. Requirements Language . . . . . . . . . . . . . . . . . . 4 2. Terminology . . . . . . . . . . . . . . . . . . . . . . . . . 4 3. Scheme Definition . . . . . . . . . . . . . . . . . . . . . . 4 3.1. Scheme Name . . . . . . . . . . . . . . . . . . . . . . . 4 3.2. Status . . . . . . . . . . . . . . . . . . . . . . . . . 5 3.3. URI Scheme Syntax . . . . . . . . . . . . . . . . . . . . 5 3.4. Scheme Semantics . . . . . . . . . . . . . . . . . . . . 7 3.5. Encoding Considerations . . . . . . . . . . . . . . . . . 8 3.6. Applications and Protocols That Use This Scheme . . . . . 8 3.7. Interoperability Considerations . . . . . . . . . . . . . 8 3.8. Security Considerations . . . . . . . . . . . . . . . . . 9 3.9. Author / Change Controller . . . . . . . . . . . . . . . 9 3.10. References . . . . . . . . . . . . . . . . . . . . . . . 9 4. Operating-System Handler Registration . . . . . . . . . . . . 9 4.1. Linux desktops . . . . . . . . . . . . . . . . . . . . . 9 4.2. macOS . . . . . . . . . . . . . . . . . . . . . . . . . . 9 4.3. Windows . . . . . . . . . . . . . . . . . . . . . . . . . 9 4.4. Android . . . . . . . . . . . . . . . . . . . . . . . . . 10 4.5. iOS . . . . . . . . . . . . . . . . . . . . . . . . . . . 10 5. Addressing Examples . . . . . . . . . . . . . . . . . . . . . 10 6. Security Considerations . . . . . . . . . . . . . . . . . . . 10 6.1. Verification Mandate . . . . . . . . . . . . . . . . . . 10 6.2. Action-Address Confusion . . . . . . . . . . . . . . . . 11 6.3. Handler Substitution . . . . . . . . . . . . . . . . . . 11 6.4. Path-Component Privacy . . . . . . . . . . . . . . . . . 11 6.5. Cross-Scheme Confusion . . . . . . . . . . . . . . . . . 11 6.6. IRI Considerations . . . . . . . . . . . . . . . . . . . 12 7. IANA Considerations . . . . . . . . . . . . . . . . . . . . . 12 8. Acknowledgements . . . . . . . . . . . . . . . . . . . . . . 13 9. References . . . . . . . . . . . . . . . . . . . . . . . . . 13 9.1. Normative References . . . . . . . . . . . . . . . . . . 13 9.2. Informative References . . . . . . . . . . . . . . . . . 14 Morrison Expires 10 February 2027 [Page 2] Internet-Draft alter URI Scheme August 2026 Appendix A. Change Log . . . . . . . . . . . . . . . . . . . . . 14 A.1. draft-morrison-alter-uri-scheme-02 . . . . . . . . . . . 14 A.2. draft-morrison-alter-uri-scheme-01 . . . . . . . . . . . 15 A.3. draft-morrison-alter-uri-scheme-00 . . . . . . . . . . . 15 Author's Address . . . . . . . . . . . . . . . . . . . . . . . . 15 1. Introduction The ~handle identity primitive defined in [MCPDNS] binds a textual identifier (Sovereign, Bot, or Instrument tier per [IDCOMMITS]) to a cryptographic principal published under an _alter. DNS TXT record. A handle reference written in running text, such as ~alice, ~example.com or ~cc-example-model, is interpretable to a human reader but is not, by itself, a dispatchable reference for a machine. This document defines the alter URI scheme as the dispatchable form of a handle reference. An alter: URI binds a ~handle to the resolution procedure of [MCPDNS] and to a URI handler registered with the host operating system. It carries three optional addressing components, an organisational scope, a facet, and an action-path. Once a handler is installed, clicking alter:~alice in a browser, chat window, or terminal yields a verified envelope; the handler decides what to do with the resulting envelope (open an inbox, show a profile card, initiate an Accord ceremony per [IDACCORD], dispatch to a per- surface MCP tool). The scheme's addressing model is deliberately fuller than a bare handle. A reference frequently needs to name not just _who_ but _which organisational context_, _which facet_ of that identity, and _which action surface_ under it. One example is "the security facet of ~blake at acme, verify action". The alter: scheme carries all four in a single dispatchable token, alter:~blake@acme:security/ verify, so that the whole reference travels as one clickable, scannable, copy-pasteable string. Every component beyond the handle is OPTIONAL; a bare alter:~alice remains valid. This document specifies the addressing syntax, the dispatch and verification obligations of a handler, and the operating-system registration entries a handler installs. It does NOT specify the resolution semantics of any facet or action surface: what a given facet or action _means_, and how a resolver computes its answer, are owned by the specification that defines that surface and are out of scope here. This document is the standalone registration request submitted to IANA per [RFC7595] Section 3, separating the administrative ceremony of scheme registration from the substantive specification of the DNS substrate. Morrison Expires 10 February 2027 [Page 3] Internet-Draft alter URI Scheme August 2026 1.1. Requirements Language The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "NOT RECOMMENDED", "MAY", and "OPTIONAL" in this document are to be interpreted as described in BCP 14 [RFC2119] [RFC8174] when, and only when, they appear in all capitals, as shown here. 2. Terminology ~handle A textual identity reference defined in [MCPDNS] and tiered in [IDCOMMITS]. Handles begin with the tilde character U+007E. Envelope The signed identity record retrieved from the _alter. DNS TXT record of the publishing zone, as specified in [MCPDNS] Section 5. Organisational scope An optional DNS-named organisation qualifying a handle, written after an @ separator, e.g. ~blake@acme.example. The scope identifies the publishing zone under which the handle's envelope is resolved; a handle with no scope resolves under its own zone. Facet An optional named aspect of an identity, written after a : separator, e.g. :security. A facet narrows a reference to one addressable face of the identity. What a facet denotes, and how a resolver answers it, are defined by the surface specification that owns the facet, not by this document. Action-path An optional typed surface addressed under a handle (and facet, if present), expressed as the path component of the URI, e.g. verify, decisions/123, seat/architect. An action-path names an operation or resource surface; its semantics are owned by the specification that defines it. Handler An operating-system component registered to receive alter: URIs and dispatch to a resolver. Examples include xdg-mime associations [XDG-MIME] on Linux, LaunchServices URL handlers [LSHANDLERS] on macOS, registry entries under HKCR on Windows, intent filters on Android, and universal links on iOS. 3. Scheme Definition 3.1. Scheme Name alter Morrison Expires 10 February 2027 [Page 4] Internet-Draft alter URI Scheme August 2026 3.2. Status Provisional. This document requests provisional registration of the alter scheme per [RFC7595] Section 3. A permanent registration per [RFC7595] Section 7 is the intended upgrade path once the scheme specification stabilises; this document records that intent without asserting a permanent registration that IANA has not yet made. 3.3. URI Scheme Syntax The alter URI scheme's generic syntax conforms to [RFC3986]: Morrison Expires 10 February 2027 [Page 5] Internet-Draft alter URI Scheme August 2026 alter-URI = "alter:" handle-ref [ "@" org-scope ] [ ":" facet ] [ "/" action-path ] [ "?" query ] [ "#" fragment ] handle-ref = "~" handle-name handle-name = sovereign-name / bot-name / instrument-name sovereign-name = ALPHA *( ALPHA / DIGIT / "-" / "." ) ; Per [IDCOMMITS] Section 4. bot-name = ALPHA *( ALPHA / DIGIT / "-" / "." ) ".bot" instrument-name = "cc-" 1*( ALPHA / DIGIT / "-" / "." ) ; Per [IDCOMMITS] Section 4. org-scope = domain-label *( "." domain-label ) ; the organisational zone qualifying the handle domain-label = ALPHA / ( ALPHA *( ALPHA / DIGIT / "-" ) ( ALPHA / DIGIT ) ) facet = facet-label *( "." facet-label ) ; a named aspect of the identity surface facet-label = ALPHA *( ALPHA / DIGIT / "-" ) action-path = action-segment *( "/" action-segment ) action-segment = 1*( unreserved / pct-encoded / sub-delims / ":" / "@" ) query = *( pchar / "/" / "?" ) fragment = *( pchar / "/" / "?" ) pchar = unreserved / pct-encoded / sub-delims / ":" / "@" unreserved = ALPHA / DIGIT / "-" / "." / "_" / "~" pct-encoded = "%" HEXDIG HEXDIG sub-delims = "!" / "$" / "&" / "'" / "(" / ")" / "*" / "+" / "," / ";" / "=" The handle-name ABNF mirrors the tier productions of [IDCOMMITS] without restating tier-level invariants; an alter: URI carries a single handle and the parser determines the tier from the lexical form. Morrison Expires 10 February 2027 [Page 6] Internet-Draft alter URI Scheme August 2026 The four identity-bearing components are parsed left to right and each is bounded by its introducing delimiter: the handle follows the scheme separator, an @ introduces the organisational scope, the first : after the handle (or scope) introduces the facet, and the first / introduces the action-path. A : appearing after the first / is a literal action-segment character, not a facet delimiter, because the facet, if present, is fully consumed before any /. Every component after handle-ref is OPTIONAL and any combination MAY be omitted. The host-component slot of a generic URI is not used. All identity- bearing material is carried in the path-like productions immediately after the scheme separator; the @ in org-scope is a component delimiter within that material and MUST NOT be read as the userinfo @ of an [RFC3986] authority. 3.4. Scheme Semantics Operations on an alter: URI are retrieval-and-verify by default. Submitting an alter: URI to a handler MUST perform the resolution and verification procedure specified in [MCPDNS] Section 8 before any content, directive, or action derived from the resulting envelope is acted upon. Specifically, the handler MUST: 1. Parse the URI per the ABNF above, isolating the handle, and any organisational scope, facet, and action-path. 2. Resolve ~handle (under org-scope if present) to a publishing zone via the procedures of [MCPDNS] Section 6. 3. Retrieve and DNSSEC-validate [RFC4033] the _alter. TXT record. 4. Verify the envelope signature against the published Ed25519 key per [MCPDNS] Section 8. 5. If a facet or action-path is present, dispatch the request to the resolver indicated by the envelope, carrying the facet and action-path verbatim. The facet and action-path are ADDRESSING information only. This document assigns them no resolution meaning: it does not define what any facet denotes, how a resolver answers an action, or what value a dereference yields. Those semantics are owned entirely by the surface specification that defines the facet or action, and are out of scope here. A conforming handler treats the facet and action-path as opaque, verified-then-forwarded tokens. Morrison Expires 10 February 2027 [Page 7] Internet-Draft alter URI Scheme August 2026 Where an action-path names an operation with a side effect, the verification of Step 4 is a precondition to that side effect: handlers MUST NOT perform, initiate, or authorise any action addressed by an alter: URI until the envelope has been retrieved and verified. Handlers SHOULD treat any verification failure as a hard error and SHOULD NOT fall back to unverified retrieval or to executing the addressed action. 3.5. Encoding Considerations alter URIs are ASCII per [RFC3986]; characters outside the unreserved set MUST be percent-encoded. The IRI form per [RFC3987] is supported for action-paths that contain non-ASCII characters; the handle-ref, org-scope, and facet productions MUST be ASCII to align with the DNS label production of [MCPDNS]. The tilde character U+007E is reserved as the handle prefix and is treated as a literal, not as an unreserved-character escape. 3.6. Applications and Protocols That Use This Scheme A reference substrate operated by the present author uses alter: URIs to dispatch handle references between operating-system handlers, an alter command-line interface, chat clients, and agent runtimes that consume the DNS substrate of [MCPDNS]. Any agent runtime, client, or operating-system component that resolves ~handle references can register a handler for the scheme. 3.7. Interoperability Considerations Operating-system URI handler registries are well-defined for each target platform: * Linux desktops: xdg-mime associations [XDG-MIME]. * macOS: CFBundleURLSchemes entries in an application's Info.plist [LSHANDLERS]. * Windows: HKEY_CLASSES_ROOT\alter with URL Protocol and shell\open\command subkeys. * Android: with . * iOS: associated-domains and universal-link entitlement entries. Where multiple applications register a handler for alter:, the operating system's default-application policy applies. No special arbitration mechanism is defined by this document. Morrison Expires 10 February 2027 [Page 8] Internet-Draft alter URI Scheme August 2026 Browsers MAY treat alter: URIs as opaque external schemes and delegate dispatch to the operating-system handler. Clients SHOULD NOT attempt direct retrieval of alter: URIs over HTTP; the resolution procedure of [MCPDNS] does not run over HTTP. The alter scheme does not displace any existing scheme and does not contradict the path-handling rules of [RFC3986]. It coexists with https:, mailto:, and other schemes that an operating system may dispatch on the same surface. 3.8. Security Considerations See Section 6 below. 3.9. Author / Change Controller Blake Morrison, Alter Meridian Pty Ltd, blake@truealter.com. Change control transfers to the IETF if this scheme is later specified by an IETF Stream document. 3.10. References [MCPDNS], [IDCOMMITS], [RFC3986], [RFC7595]. 4. Operating-System Handler Registration The following non-normative subsections sketch the platform- specific registration entries that a conforming handler installs. Implementations are responsible for the platform-specific syntax; this document does not prescribe handler binaries or invocation shapes. 4.1. Linux desktops A .desktop file with MimeType=x-scheme-handler/alter; and a Exec= line invoking the platform resolver. The alter-cli reference implementation registers itself as the default handler on first run. 4.2. macOS A CFBundleURLTypes entry with CFBundleURLSchemes=("alter") and a CFBundleURLName of Identity Handle Reference in the application's Info.plist. 4.3. Windows Registry entries under HKEY_CLASSES_ROOT\alter: Morrison Expires 10 February 2027 [Page 9] Internet-Draft alter URI Scheme August 2026 * A default value of URL:Identity Handle Reference. * A URL Protocol value of empty string. * A shell\open\command subkey with the handler invocation. 4.4. Android An declaring on an Activity capable of performing the resolution procedure of [MCPDNS] Section 8. 4.5. iOS An associated-domains entitlement listing the publishing zone, plus a LSApplicationQueriesSchemes entry that includes alter. 5. Addressing Examples The following non-normative examples illustrate the addressing syntax. Facet and action semantics are out of scope; each surface is defined by the specification that owns it. alter:~alice alter:~example.com/decisions/123 alter:~bob/inbox alter:~blake@acme.example alter:~blake@acme.example:security alter:~blake@acme.example:security/verify alter:~example.com:seat/architect alter:~cc-example-model/sessions/last The first form addresses an envelope; the second and third address action surfaces under an envelope; the fourth scopes a handle to an organisation; the fifth adds a facet; the sixth adds a typed action under that facet; the seventh addresses a facet-scoped surface; the eighth illustrates Instrument-tier addressing. 6. Security Considerations 6.1. Verification Mandate The verification mandate of [MCPDNS] Section 8 is the security floor of this scheme. Handlers that accept an alter: URI without verifying the envelope's signature against the DNSSEC-validated publishing record violate the scheme's invariants. An attacker who induces a handler to perform unverified retrieval can substitute an envelope. Implementations MUST treat envelope verification as a precondition to Morrison Expires 10 February 2027 [Page 10] Internet-Draft alter URI Scheme August 2026 any side effect (writing files, sending requests, dispatching a sub- handler, or performing an addressed action). 6.2. Action-Address Confusion Because an alter: URI MAY address a typed action, a handler that acts on the action-path before verifying the envelope exposes a confused- deputy surface: an attacker-supplied URI could name a privileged action under a handle the attacker does not control. The Step-4 verification MUST complete, binding the resolved envelope to the addressed handle, before any action-path is dispatched. A handler MUST NOT infer authority from the URI's textual form alone. 6.3. Handler Substitution The operating-system's default-application policy is the trust-anchor for which binary handles alter: URIs. Users configuring the default handler MUST treat handler selection with the same caution they apply to default browsers or default mail clients. A malicious handler could parse an alter: URI, present a forged envelope to the user, and act on attacker-supplied data without performing verification. Implementations SHOULD cross-check the handler binary's signature against the publishing substrate's expected handler manifest where such a manifest is defined by a future specification. 6.4. Path-Component Privacy An organisational scope, facet, or action-path included in an alter: URI is part of the URI's textual form and may be logged by the operating-system handler registry, browser history, terminal scrollback, and chat-client indexers. Surface owners that consider a facet or action identifier (e.g. a decision identifier, a thread identifier) sensitive SHOULD provide indirected forms (opaque tokens, ephemeral identifiers) and SHOULD NOT recommend embedding sensitive identifiers in the URI. 6.5. Cross-Scheme Confusion A URI of the form alter://~alice (with the authority-component double-slash) is malformed and MUST be rejected. Implementations MUST NOT silently coerce alter://~handle to alter:~handle; divergent parsers risk confusing a third-party authority component with a handle reference. Similarly, the @ of an org-scope MUST NOT be parsed as an [RFC3986] userinfo delimiter; there is no authority component in an alter: URI. Morrison Expires 10 February 2027 [Page 11] Internet-Draft alter URI Scheme August 2026 6.6. IRI Considerations When an alter: URI is presented in IRI form per [RFC3987] with non- ASCII characters in the action-path, implementations MUST apply the conversion procedure of [RFC3987] Section 3.1 before performing the resolution procedure. Non-ASCII characters in the handle-ref, org- scope, or facet MUST be rejected; those productions are restricted to the ASCII forms above. 7. IANA Considerations This document requests that IANA register the alter URI scheme in the Uniform Resource Identifier (URI) Schemes registry per [RFC7595] Section 3 (provisional registration), recording the provisional registration cross-referenced under [MCPDNS] Section 11 with the following body: * URI scheme name: alter * Status: Provisional * URI scheme syntax: As specified in Section 3.3 above. * URI scheme semantics: As specified in Section 3.4 above. * Encoding considerations: As specified in Section 3.5 above. * Applications/protocols that use this URI scheme name: As specified in Section 3.6 above. * Interoperability considerations: As specified in Section 3.7 above. * Security considerations: As specified in Section 6 above. * Contact: Blake Morrison blake@truealter.com (mailto:blake@truealter.com), Alter Meridian Pty Ltd. * Author/Change controller: Blake Morrison, Alter Meridian Pty Ltd. Change control transfers to the IETF if this scheme is later specified by an IETF Stream document. * References: This document; [MCPDNS]; [IDCOMMITS]. A permanent registration per [RFC7595] Section 7 is the intended upgrade path once the scheme specification stabilises. Morrison Expires 10 February 2027 [Page 12] Internet-Draft alter URI Scheme August 2026 8. Acknowledgements The scheme builds on the ~handle identity primitive defined in [MCPDNS] and the tier taxonomy of [IDCOMMITS]. The lexical choice of tilde for the handle prefix is informed by [POSIX-TILDE] and by the long-standing shell convention that the tilde denotes a named principal. 9. References 9.1. Normative References [RFC2119] Bradner, S., "Key words for use in RFCs to Indicate Requirement Levels", BCP 14, RFC 2119, DOI 10.17487/RFC2119, March 1997, . [RFC8174] Leiba, B., "Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words", BCP 14, RFC 8174, DOI 10.17487/RFC8174, May 2017, . [RFC3986] Berners-Lee, T., Fielding, R., and L. Masinter, "Uniform Resource Identifier (URI): Generic Syntax", STD 66, RFC 3986, DOI 10.17487/RFC3986, January 2005, . [RFC7595] Thaler, D., Ed., Hansen, T., and T. Hardie, "Guidelines and Registration Procedures for URI Schemes", BCP 35, RFC 7595, DOI 10.17487/RFC7595, June 2015, . [RFC3987] Duerst, M. and M. Suignard, "Internationalized Resource Identifiers (IRIs)", RFC 3987, DOI 10.17487/RFC3987, January 2005, . [RFC4033] Arends, R., Austein, R., Larson, M., Massey, D., and S. Rose, "DNS Security Introduction and Requirements", RFC 4033, DOI 10.17487/RFC4033, March 2005, . [MCPDNS] Morrison, B., "Discovery of Model Context Protocol Servers via DNS TXT Records", 2026, . Morrison Expires 10 February 2027 [Page 13] Internet-Draft alter URI Scheme August 2026 [IDCOMMITS] Morrison, B., "Identity-Attributed Git Commits via Tier- Structured Trailers", 2026, . 9.2. Informative References [RFC8615] Nottingham, M., "Well-Known Uniform Resource Identifiers (URIs)", RFC 8615, DOI 10.17487/RFC8615, May 2019, . [IDACCORD] Morrison, B., "Identity Accord Protocol", 2026, . [IDPRONOUNS] Morrison, B., "Identity Pronouns: A Reference-Axis Extension to ~handle Identity Systems", 2026, . [POSIX-TILDE] "IEEE Std 1003.1-2017, Shell Command Language, Section 2.6.1 Tilde Expansion", 2017, . [XDG-MIME] "Shared MIME-info Database Specification", 2024, . [LSHANDLERS] "Apple URL Scheme Reference (CFBundleURLSchemes / LSHandlers)", 2024, . Appendix A. Change Log A.1. draft-morrison-alter-uri-scheme-02 * Broaden the addressing syntax to the full ~handle@org:facet/action reference: add the org-scope, facet, and action-path productions and their left-to-right parsing rules. Every added component is OPTIONAL; a bare alter:~handle is unchanged. Morrison Expires 10 February 2027 [Page 14] Internet-Draft alter URI Scheme August 2026 * State explicitly that facet and action-path are addressing information only, with resolution semantics owned by the surface specification and out of scope here. * Add an Action-Address Confusion security consideration and extend the verification mandate to cover addressed actions. * Correct the registration Status to Provisional, matching the registration this document actually requests; record permanent registration as the intended upgrade path rather than asserting it. A.2. draft-morrison-alter-uri-scheme-01 * Editorial and reference alignment. A.3. draft-morrison-alter-uri-scheme-00 * Initial submission. Upgrades the provisional registration recorded in [MCPDNS] Section 11. Author's Address Blake Morrison Alter Meridian Pty Ltd Email: blake@truealter.com Morrison Expires 10 February 2027 [Page 15]