ActivityPub had sth similar? Maybe just reuse that to identify the source identity, then determine if you want to trust that domain or person/bot?