{
  "canonicalClaimUrl": "https://xn--mwe.com/questions/can-authentication-prove-authority/#clm-k03-q-025",
  "claimStatus": "CURRENT TECHNICAL STANDARD",
  "correctionStatus": "CURRENT K03 RECORD",
  "id": "CLM-K03-Q-025",
  "lastReviewed": "2026-08-14",
  "machineRecordUrl": "https://xn--mwe.com/data/claims/clm-k03-q-025.json",
  "name": "Can authentication prove authority?",
  "ownerAnchor": "clm-k03-q-025",
  "ownerId": "K01-Q-025",
  "ownerRoute": "/questions/can-authentication-prove-authority/",
  "ownerType": "question",
  "proposition": "No. Authentication can establish that a presented identity or credential controlled an expected secret or key. Authority requires a separate legal, constitutional, contractual or delegated basis defining what that subject may decide or do.",
  "qualification": "The answer is bounded by the owning topic, current source catalog, and explicit project-doctrine labels.",
  "releaseId": "K12-2026-08-16",
  "releaseVersion": "2.1.0",
  "researchCutoff": "2026-08-14",
  "scope": "Direct answer for Can authentication prove authority?",
  "slug": "clm-k03-q-025",
  "sourceIds": [
    "SRC-W3C-DID-CORE",
    "SRC-W3C-VC-DM",
    "SRC-RFC-5280",
    "SRC-W3C-PROV-O"
  ],
  "sourceSections": [
    {
      "section": "Verification methods",
      "sourceId": "SRC-W3C-DID-CORE",
      "supportRelationship": "QUALIFIES OR SUPPORTS WITHIN STATED SCOPE",
      "supports": "A DID document can express verification methods associated with a DID subject.",
      "url": "https://www.w3.org/TR/did-core/#verification-methods"
    },
    {
      "section": "Services",
      "sourceId": "SRC-W3C-DID-CORE",
      "supportRelationship": "QUALIFIES OR SUPPORTS WITHIN STATED SCOPE",
      "supports": "A DID document can advertise service endpoints; that does not itself establish legal identity or authority.",
      "url": "https://www.w3.org/TR/did-core/#services"
    },
    {
      "section": "Abstract",
      "sourceId": "SRC-W3C-VC-DM",
      "supportRelationship": "QUALIFIES OR SUPPORTS WITHIN STATED SCOPE",
      "supports": "A verifiable credential expresses claims by an issuer and can be secured against tampering.",
      "url": "https://www.w3.org/TR/vc-data-model-2.0/#abstract"
    },
    {
      "section": "Ecosystem overview",
      "sourceId": "SRC-W3C-VC-DM",
      "supportRelationship": "QUALIFIES OR SUPPORTS WITHIN STATED SCOPE",
      "supports": "The model distinguishes issuers, holders and verifiers; verification of a credential is not universal proof that every claim is true or legally authoritative.",
      "url": "https://www.w3.org/TR/vc-data-model-2.0/#ecosystem-overview"
    },
    {
      "section": "RFC status and update chain",
      "sourceId": "SRC-RFC-5280",
      "supportRelationship": "QUALIFIES OR SUPPORTS WITHIN STATED SCOPE",
      "supports": "RFC 5280 is a Proposed Standard and has been updated by later RFCs.",
      "url": "https://www.rfc-editor.org/info/rfc5280/"
    },
    {
      "section": "Certificate and CRL profile",
      "sourceId": "SRC-RFC-5280",
      "supportRelationship": "QUALIFIES OR SUPPORTS WITHIN STATED SCOPE",
      "supports": "The RFC profiles X.509 certificates and revocation lists; a valid certificate binds data under a PKI but does not establish every external legal or factual claim.",
      "url": "https://www.rfc-editor.org/rfc/rfc5280.html#section-4"
    },
    {
      "section": "Abstract and status",
      "sourceId": "SRC-W3C-PROV-O",
      "supportRelationship": "QUALIFIES OR SUPPORTS WITHIN STATED SCOPE",
      "supports": "PROV-O defines classes, properties and restrictions for representing and interchanging provenance information.",
      "url": "https://www.w3.org/TR/prov-o/#abstract"
    },
    {
      "section": "PROV-O at a glance",
      "sourceId": "SRC-W3C-PROV-O",
      "supportRelationship": "QUALIFIES OR SUPPORTS WITHIN STATED SCOPE",
      "supports": "Provenance relationships can be represented as entities, activities, agents and qualified relations.",
      "url": "https://www.w3.org/TR/prov-o/#prov-o-at-a-glance"
    }
  ],
  "type": "ClaimRecord"
}
