# Scopes & Trust Levels

INFRA uses two trust tiers. Standard apps can access public profile data and verified claims. Trusted apps can additionally request encrypted sensitive documents.

## Standard Apps

Default tier for all registered developer apps. Access to public identity data and verified claims.

- User profile (name, email, country)
- KYC level and verification status
- Verified claims
- Document metadata (type only)
- Consent management
- Webhook events

## Trusted Apps

Elevated tier for regulated platforms (fintech, healthcare, etc.). Requires approval. Includes everything in Standard plus:

- JWE-encrypted passport data
- National ID number (NIN)
- Bank Verification Number (BVN)
- Full document images (encrypted)
- Enhanced KYC data

## Full scope reference

| Scope | Returns | Tier |
|---|---|---|
| `profile:read` | id, email, first_name, last_name, country, photo_url | Standard |
| `kyc:read` | kyc_level, status, verified_at, provider | Standard |
| `claims:read` | Array of verification claims with type, provider, revoked status | Standard |
| `documents:metadata` | Document type, country, verification status (no content) | Standard |
| `documents:read` | JWE-encrypted document content (passport, NIN, BVN) | Trusted |

## JWE Encryption

Sensitive documents returned by Trusted apps are encrypted using JSON Web Encryption (JWE). Your app must hold the corresponding private key to decrypt the payload. Key exchange is handled during the Trusted app approval process.

---

Source: https://docs.infraidentity.com/scopes/ · Full docs: https://docs.infraidentity.com/llms-full.txt
