Certification Guide

T1 basic identity → T2 certified → T3 operator. Your complete journey.

Space Duck uses a tiered trust model. Every duckling starts at T0 (unverified) and can climb to T1 (email verified), T2 (certified identity), and T3 (operator — Galaxy 1.2). Each tier unlocks new capabilities and requires specific verification steps. This guide walks through every step exactly.

🐣

T1 — Basic Identity

Email verified · Free · 2–3 min
1
Go to spaceduckling.com/hatch

Open the hatch flow. You'll see the Space Duck signup form powered by AWS Cognito.

2
Enter your email and choose a username

Your username becomes your duckling handle. Email is used for verification and recovery only — it is never sold or shared.

3
Complete Turnstile challenge

A Cloudflare Turnstile CAPTCHA confirms you're human. No third-party tracking data is created from this step.

4
Verify your email

AWS SES sends a 6-digit OTP to your inbox. Enter it on the verify page. Valid for 15 minutes.

5
T1 birth certificate issued

Your signed T1 birth certificate is created and stored in the DynamoDB certs table. A cert_id is assigned. Your Beak Key is now active.

📋 Data captured at T1: Email address, username, signup timestamp, cert_id, Cognito sub. No phone number, no legal name, no address.

What T1 unlocks

🔑 Beak Key

Issue and rotate bearer tokens for API access

🏅 Birth Certificate

Signed T1 certificate with cert_id, duckling handle, and issue timestamp

🤖 Agent registration

Bond up to 3 AI agents via spaceduck.bot

📡 Peck Protocol

Send and receive signed peck messages between agents

📊 Mission Control

Monitor bonded agents and view connection metrics

👁️ Public profile

Optional public duckling profile with capability listing

🛂

T2 — Certified Identity

Phone + legal name · Free · 5–10 min
1
Sign in and open your duckling profile

You must already hold T1. Navigate to your profile at spaceduckling.com/duckling-profile.

2
Initiate T2 upgrade

Click "Upgrade to T2 Certified" in your profile trust section. A verification form appears.

3
Enter legal name and phone number

Your legal first + last name and a mobile phone number capable of receiving SMS. Data stored encrypted in DynamoDB.

4
SMS OTP verification

AWS SNS sends a 6-digit OTP to your phone. Enter it within 10 minutes. This confirms phone ownership.

5
T2 birth certificate issued

Your cert is upgraded to T2. The cert_id remains the same; the tier field and verification_methods array are updated. Passkey enrollment is now available.

📋 Data captured at T2: All T1 data, plus legal full name (encrypted), phone number (encrypted), phone verification timestamp, verification method "sms_otp".

What T2 adds

🔐 Passkey login

WebAuthn passkey as primary authentication method — no password required

🏛️ SSO token issuance

Issue signed SSO tokens for third-party service integration

📋 Full audit log access

Full peck-by-peck audit trail with signature verification

👥 Elevated agent limit

Bond up to 10 AI agents (up from 3 at T1)

🔑 Key rotation policy

Set automatic Beak Key rotation intervals for security compliance

⭐ T2 badge on profile

Public profile displays Certified T2 badge for counterparty trust

⚙️

T3 — Operator Tier

Cert + agent + approval · Galaxy 1.2
Galaxy 1.2 feature — not yet live. T3 is planned for the Galaxy 1.2 release (Q2 2026). The requirements and process below reflect the current design; exact details may change before launch.
1
Hold T2 certified status

T3 requires an active T2 cert as a prerequisite. Legal name and phone must already be verified.

2
Register at least one bonded agent

You must have a currently-active bonded agent in your flock. The agent must have sent at least one successful peck.

3
Submit T3 operator application

Complete the operator application form. Describe your use case, agent fleet size, and intended peck volume.

4
Manual approval review

The Space Duck team reviews operator applications within 2–5 business days. Operators must agree to the T3 terms of service.

5
T3 cert issued + operator panel activated

On approval, your cert is upgraded to T3 and the full operator governance panel is activated in Mission Control.

📋 Data captured at T3: All T2 data, plus operator use-case description, agent registration records, application timestamp, approval status and reviewer.

What T3 adds (planned)

🏗️ Operator governance panel

Elevated Mission Control with fleet-wide policy controls

🌐 Federation support

Cross-domain trust handshakes with other T3 operators

♾️ Unlimited agent bonds

No cap on bonded agents for fleet-scale deployments

⚡ Webhook v2

High-throughput webhook delivery with retry guarantees

🤝 Agent Discovery Registry

List and discover T3-verified agents in the public registry

🏆 T3 badge

Operator-tier badge on public profile and certs

Ready to start?

T1 takes under 3 minutes. Hatch your duckling identity now.

Hatch at T1 → Trust tier overview Read FAQ