TrustMark developers

Build against TrustMark IP infrastructure.

This page is for approved partners integrating TrustMark checks into real products and production workflows: studios, platforms, tools, marketplaces, model providers, and enterprise systems that need identity-use verification, authorization checks, receipts, watermarks, and audit proof.

What developers can integrate

These are TrustMark integration surfaces, not a public copy of the DIAP protocol docs. Detailed endpoint references are provided after access approval.

Verification APIs

Verify whether media, captures, receipts, or watermarks map to an authorized TrustMark record before publishing, distributing, or escalating a review.

Studio workflow hooks

Connect TrustMark checks to capture review, performer evidence, roster workflows, approvals, reports, and downstream production systems.

Vault-aware authorization

Request and verify scoped identity-use grants through the TrustMark authorization layer without taking custody of raw face, voice, motion, or likeness data.

Receipts and audit trails

Submit post-use proof: token IDs, output hashes, watermark handles, distribution URLs, and review context that can be audited later.

Watermark verification

Check image, video, and audio provenance markers and link them back to TrustMark records, receipts, and revocation state.

Enterprise controls

Use server-side keys, environment separation, webhook signatures, revocation handling, and fail-closed policy for production integrations.

Access path

1

Request access

Tell us what product or workflow you want to connect and what identity surfaces are involved.

2

Scope the integration

We define which APIs, vault flows, receipts, and verification checks belong in your environment.

3

Build in sandbox

Use test identities, test grants, and non-production keys to prove the flow end to end.

4

Certify behavior

Show that the integration fails closed, handles revocation, and does not store raw identity data unless explicitly approved.

5

Go live

Move to production keys, signed webhooks, monitoring, and audit-ready receipts.

Production requirements

Approved integrations must fail closed.

TrustMark integrations are meant for real identity-risk surfaces. If verification, scope, receipts, revocation, or webhook validation is uncertain, the integration should block the operation until it can be safely resolved.

  • Server-side verification before identity-derived generation, editing, distribution, or monetization.
  • No client-only authorization decisions.
  • Separate sandbox and production app IDs, API keys, webhook secrets, and redirect URLs.
  • Immediate revocation handling for pending and future use.
  • Idempotent receipt submission with output hash, token ID, watermark ID where required, and product context.
  • Minimal data custody by default: store TrustMark IDs, token IDs, receipt IDs, and decisions — not raw biometric assets.