TrustMark developers
Build against TrustMark IP infrastructure.
This page is for approved partners integrating TrustMark checks into real products and production workflows: studios, platforms, tools, marketplaces, model providers, and enterprise systems that need identity-use verification, authorization checks, receipts, watermarks, and audit proof.
What developers can integrate
These are TrustMark integration surfaces, not a public copy of the DIAP protocol docs. Detailed endpoint references are provided after access approval.
Verification APIs
Verify whether media, captures, receipts, or watermarks map to an authorized TrustMark record before publishing, distributing, or escalating a review.
Studio workflow hooks
Connect TrustMark checks to capture review, performer evidence, roster workflows, approvals, reports, and downstream production systems.
Vault-aware authorization
Request and verify scoped identity-use grants through the TrustMark authorization layer without taking custody of raw face, voice, motion, or likeness data.
Receipts and audit trails
Submit post-use proof: token IDs, output hashes, watermark handles, distribution URLs, and review context that can be audited later.
Watermark verification
Check image, video, and audio provenance markers and link them back to TrustMark records, receipts, and revocation state.
Enterprise controls
Use server-side keys, environment separation, webhook signatures, revocation handling, and fail-closed policy for production integrations.
Access path
Request access
Tell us what product or workflow you want to connect and what identity surfaces are involved.
Scope the integration
We define which APIs, vault flows, receipts, and verification checks belong in your environment.
Build in sandbox
Use test identities, test grants, and non-production keys to prove the flow end to end.
Certify behavior
Show that the integration fails closed, handles revocation, and does not store raw identity data unless explicitly approved.
Go live
Move to production keys, signed webhooks, monitoring, and audit-ready receipts.
Production requirements
Approved integrations must fail closed.
TrustMark integrations are meant for real identity-risk surfaces. If verification, scope, receipts, revocation, or webhook validation is uncertain, the integration should block the operation until it can be safely resolved.
- Server-side verification before identity-derived generation, editing, distribution, or monetization.
- No client-only authorization decisions.
- Separate sandbox and production app IDs, API keys, webhook secrets, and redirect URLs.
- Immediate revocation handling for pending and future use.
- Idempotent receipt submission with output hash, token ID, watermark ID where required, and product context.
- Minimal data custody by default: store TrustMark IDs, token IDs, receipt IDs, and decisions — not raw biometric assets.