Keyra for Music
The trust infrastructure
for the direct-to-fan economy
Keyra — the trust infrastructure for music. Ciright Beats is the flagship verified direct-to-fan network — Keyra is the trust plane underneath it.
Why Keyra
Modern music infrastructure has unresolved trust questions
Keyra records what participating systems and principals authorize and attest. Absence of a Keyra record is not proof of fraud.
- Who is actually the artist?
- Who has authority to act for the artist?
- Was this message authorized?
- Was this AI-generated content approved by the artist?
- Is this voice or likeness authorized?
- Is this fan a real person?
- Is this account unique?
- Is this device trusted?
- Is this purchaser eligible for the ticket allocation?
- Was this transaction authorized?
- Who authorized an AI agent to perform an action?
- Did the rights holder permit this use?
- Can authorization later be proven?
Trust objects
Verified or attestable objects
Architected around evidence classifications — never claims beyond available evidence.
- Verified Artist
- Verified Fan
- Verified Manager
- Verified Agent
- Verified Label Representative
- Verified Rights Holder
- Verified Venue
- Verified Promoter
- Verified Device
- Verified Transaction
- Verified Ticket
- Verified Membership
- Verified Content
- Artist-Authorized AI Content
- Verified Communication
- Verified Access Event
- Verified AI Agent
- Verified Delegated Authority
Evidence levels
- Self-asserted
- System-attested
- Device-attested
- Communication-verified
- Transaction-verified
- Identity-assured
- Delegated authorization
- Third-party attested
- No Keyra authorization record
Verified Artist
Keyra Verified Artist
High-assurance identity for legal person, stage identity, organization, management representation, label relationship, and authorized team — without exposing unnecessary private data to fans.
Expandable trust information is gated by the viewer's permissions.
Delegated authority
Scoped power. Auditable actions.
Every consequential action retains actor, principal, role, scope, time, device/session, authorization source, and result. Native grants are BETA — bridged from Ciright team roster and checkable via Keyra.
Beta Verify Representative Authority
Roles
- Artist / Principal
- Manager
- Business Manager
- Label
- Publisher
- Booking Agent
- Tour Manager
- Merchandise Team
- Digital Team
- Marketing Agency
- Publicist
- Finance
- Legal
- Venue
- Promoter
Every role supports
- scope
- permissions
- start date
- expiry
- territory
- transaction limits
- content authority
- communication authority
- financial authority
- delegation authority
Audit fields
- actor
- principal
- role
- scope
- time
- device/session
- authorization source
- result
Verified Fan
Keyra Fan Passport
A progressive trust ladder and persistent trust relationship controlled through the fan's Keyra experience. Verification must feel like gaining privileges — not surrendering privacy.
- L0Visitor
Browse public surfaces without friction.
- L1Registered Fan
Account created; basic relationship can begin.
- L2Trusted Fan
Account + device + communication verification.
- L3Verified Human
Enhanced identity assurance where risk justifies it.
- L4Verified Purchaser
Persistent transaction relationship with the artist network.
- L5Verified Member
Ongoing membership with scoped privileges.
- L6Privileged / Superfan Access
Highest relationship privileges within artist rules.
- L7High-Assurance Identity
Used only where risk, regulation, age, or economics justify it.
Why verify?
- Fairer ticket access
- Presales
- Priority drops
- VIP access
- Members-only experiences
- Exclusive releases
- Rewards
- Artist-authorized communication
- Private livestreams
- Event access
- Fan recognition
- Community access
- Limited merchandise
- Travel offers
- Meet-and-greet opportunities
Identity assurance is progressive, risk-based, purpose-limited, privacy-preserving, and user-understandable. High-assurance identity is never required for ordinary browsing.
Ticketing trust
Keyra Verified Fan Access
Not necessarily a replacement ticketing engine — a trust and authorization layer capable of integrating with ticketing providers. Native Ciright purchase and transfer flows now record Keyra eligibility decisions (BETA).
Beta Authorize Presale · Verify Ticket Transfer · Authorize Transaction
Fan → Keyra trust → Artist eligibility rules → Presale authorization → Ticketing partner → Purchase → Transfer → Venue entry
The artist determines who receives access without Ciright Beats necessarily becoming the system of record for ticketing. Partner adapters remain partner-dependent stubs.
Privacy
My Keyra Trust
Permissioned relationship infrastructure with fan-controlled privacy rights and consent-based processing. Do not assume the artist universally owns personal data.
- Artist relationships
- Connected accounts
- Permissions
- Communication consent
- Devices
- Memberships
- Authorizations
- Data portability
- Relationship deletion
- Consent withdrawal
- History where legally appropriate
Connectivity
Telecom sequenced correctly
The strategic value of connectivity is persistence and network-rooted trust — not simply airtime margin. Artists are not required to become telecommunications providers.
- Phase 1BetaWeb/app trust
Permissioned relationships, verification ladders, and audit events on Ciright Beats.
- Phase 2PlannedNetwork intelligence APIs
Signals that strengthen device and session trust without requiring carrier ownership.
- Phase 3PlannedOptional eSIM connectivity
Connectivity as persistence — not a requirement that every artist become a telecom provider.
- Phase 4PlannedPersistent artist network endpoint
A durable network-rooted relationship channel for the artist network.
Integrations
Works with the music industry you already use
Every integration is status-tagged. Nothing is claimed live unless it is live.
- DSPSpotifyPlanned
Audience and presence linking.
- DSPApple MusicPlanned
- DSPYouTube MusicPlanned
- SocialInstagramPlanned
- SocialTikTokPlanned
- SocialYouTubePlanned
- SocialFacebookPlanned
- CommerceShopifyPlanned
- CommerceApproved payment processorsBeta
Stripe adapter LIVE when PAYMENT_PROVIDER=stripe + STRIPE_SECRET_KEY; mock default.
- TicketingTicketmasterPartner dependent
Trust layer for eligibility / transfer — not a replacement ticketing engine.
- TicketingAXSPartner dependent
- TicketingDICEPartner dependent
- TicketingTixrPartner dependent
- TicketingEventbritePartner dependent
- TicketingBandsintownPlanned
- TicketingSeatedPlanned
- TicketingCiright Beats ticketingLive
Native ticket, credential, and gate workflows.
- MediaMux live streamingIn development
Adapter LIVE when STREAMING_PROVIDER=mux + MUX_TOKEN_ID/SECRET; default none. Playback gated by entitlement/rights/territory.
- MessagingEmailBeta
Resend/SendGrid LIVE when EMAIL_PROVIDER + API key set; mock default.
- MessagingSMSBeta
Twilio LIVE when SMS_PROVIDER=twilio + credentials; mock default.
- MessagingWhatsAppPlanned
- MessagingPush notificationsIn development
- WalletsApple WalletPlanned
- WalletsGoogle WalletPlanned
- DataREST APIBeta
/api/keyra/v1/* with KEYRA_API_KEYS.
- DataWebhooksBeta
/api/webhooks/stripe and /api/webhooks/keyra.
- DataSDKPlanned
- DataData warehouse export/importPlanned
- AISecure agent APIsIn development
- AIMCP-compatible toolingPlanned
- IdentityKeyra identity federationIn development
External federation adapter not live. Native attestation ledger is BETA.
- TelecomNetwork intelligence APIsPlanned
Phase 2 — after web/app trust.
- TelecomOptional eSIM connectivityPlanned
Phase 3 — persistence and network-rooted trust, not mandatory airtime.
