TVEN Connect separates referral attribution from data access. An affiliate relationship does not grant data access, and a data-sharing relationship does not imply compensation.
Referral contract
TVEN creates an opaque reference and redirects only to a destination registered in the partner manifest.
GET /connect/out/{partnerId}?from=registry
Destination:
https://partner.example/start
?tven_ref=<opaque-id>
&tven_source=registry
Names, email addresses, conditions, claim information, and document identifiers are prohibited in referral URLs.
Secure handoff contract
Secure handoff is agreement-gated. The user selects scopes, approves the receiving business, and receives a one-time handoff. TVEN records consent/audit metadata but the architecture is designed so TVEN does not retain the sensitive payload.
Short-lived, one-time redemption code
Destination-bound and scope-bound authorization
No protected payload in browser URLs
Explicit consent receipt before issuance
Revocation and expiration events
Standard data scopes
A partner agreement authorizes only the scopes it needs. Sensitive scopes should remain off by default.
profile.basic
profile.contact
veteran.service
benefits.summary
claim.calculation
claim.conditions
claim.status
documents.metadata
documents.transfer
referral.status
Webhook event namespace
referral.created
referral.accepted
conversion.recorded
handoff.accepted
intake.started
intake.completed
service.started
service.completed
connection.revoked
consent.expired
Fail-closed activation
A manifest may advertise the protocol, but API, webhook, and secure-handoff capabilities stay disabled until TVEN records an approved agreement, verified domain, required disclosure, and technical endpoint.