Scale
ECZ-ID Active Entity Capacity (AEC)
A free Passport exists and resolves whether or not you use any AEC. AEC is the capacity to actively manage entities in production — one pool for your whole organisation, whichever families those entities belong to.
Your ECZ-ID does not change.
How it works
How AEC works, in plain English.
Three things cover it: what one AEC is, why one pool serves every family, and what AEC never does.
What one AEC is, how the pool works, and the four things AEC never does
What one AEC is
One AEC is one actively managed production entity with live bindings and current state.
For MCP Passports: An MCP server you actively manage in production, with live bindings and current state.
One pool across families
AEC is one pool shared across your Agent, MCP, Plugin, API, SDK and logical Service & Workload identities, and your IoT product, model and fleet identities.
What AEC never does
- AEC never makes an identity more verified.
- AEC never replaces a Passport.
- AEC never changes an ECZ-ID. Your ECZ-ID does not change.
- Running out of AEC never deletes, revokes or unpublishes an identity.
Individual IoT device instances are counted separately, in IoT Fleet Capacity, and never consume AEC.
Prices and what can be bought today come from TrustOps, which owns every purchase, entitlement and renewal. Your organisation’s included AEC and any additional capacity are configured there.
The meter
What counts, and what never does.
One AEC is one actively managed production entity with live bindings and current state.
Counts as an active entity
- An MCP server you actively manage in production, with live bindings and current state.
- The same for your agents, plugins, APIs, SDKs and logical services and workloads.
- Your IoT product, model and fleet identities.
Never counts
- The Passport itself. Identity exists and resolves without AEC.
- The number of tools inside a server. Tools are not entities.
- Ephemeral replicas of a server you already manage.
- Individual IoT device instances — those use IoT Fleet Capacity.
- Public Resolver reads and public machine-readable records are never metered, never authenticated and never counted against any allowance.
At the limit
What happens when you reach your AEC.
AEC governs how much you actively manage. It never governs whether your identities exist.
Identity and proof keep working
Every ECZ-ID you hold keeps resolving, and every public record stays readable. Reaching a limit never deletes, revokes, detaches or unpublishes anything.
Optional work waits first
Duplicate work is avoided and optional, scheduled activity slows or pauses before anything else is affected.
You are told
You are notified so you can add capacity or discuss a larger arrangement — nothing changes silently.
Separate axes
AEC changes how much you manage — nothing else.
AEC confers no verification
An organisation with a large AEC pool is exactly as independently checked as one with none, unless it has separately taken Parent VERIFIED or ASSURED. AEC is a scale entitlement, not evidence, and it says nothing about any MCP server you operate.
A Parent tier includes its own AEC
Each Parent tier carries an included AEC allowance, and additional AEC adds to it. The current allowances are shown in TrustOps, which owns them — they are not restated here.
Configure in TrustOps(opens in a new tab — trustops.ecocitizenz.com)
Prices and what can be bought today come from TrustOps, which owns every purchase, entitlement and renewal.
Start with the identity. Add AEC when you operate at scale.
A free MCP Passport needs no AEC to exist, resolve or be re-checked. Very large estates are arranged directly.