DID.is — Identity, Resolved
DID.is is the universal identity resolution, cryptographic evidence, verification, and agent trust infrastructure for the decentralized web and autonomous agent internet.
It resolves decentralized identifiers (DIDs), verifies underlying cryptographic proofs, inspects Verifiable Credentials (VCs), evaluates declarative policies, inspects Model Context Protocol (MCP) tool servers and Agent-to-Agent (A2A) cards, verifies delegation chains, and provides continuous monitoring and telemetry.
Every conclusion reached by DID.is is traceable to an auditable check that actually executed. Nothing is ever summarized into an arbitrary trust score or ungrounded badge.
Core Philosophy
Section titled “Core Philosophy”1. Cryptographic Evidence over Reputational Scores
Section titled “1. Cryptographic Evidence over Reputational Scores”Traditional web reputation models rely on opaque heuristics, centralized gatekeepers, and subjective scoring systems. DID.is replaces trust assumptions with deterministic cryptographic verification:
- Every statement is backed by verifiable cryptographic primitives (Ed25519, secp256k1, P-256, RSA).
- Signature validation is fail-closed: an unrecognized curve, missing key, or expired signature immediately marks verification as failed.
- Forensic logs track each resolution and verification step with nanosecond timestamps and SHA-256 content hashes.
2. Universal Standards Interoperability
Section titled “2. Universal Standards Interoperability”DID.is strictly complies with formal standards defined by the World Wide Web Consortium (W3C) and Internet Engineering Task Force (IETF):
- W3C DID Core 1.0 & 1.1: Universal identifier syntax, document data model, and verification relationships (
authentication,assertionMethod,capabilityInvocation,capabilityDelegation,keyAgreement). - W3C DID Resolution v1 (CR Draft): Standardized resolution output envelopes (
didDocument,didDocumentMetadata,didResolutionMetadata). - W3C Verifiable Credentials Data Model v2.0: JSON-LD, JWT (VC-JWT), and Data Integrity proof formats (
ed25519-2020,ecdsa-jws-2020). - RFC 9457 Problem Details: Standardized HTTP machine-readable error responses across all daemon endpoints.
3. Native Autonomous Agent Trust
Section titled “3. Native Autonomous Agent Trust”As artificial intelligence transitions from conversational interfaces to autonomous execution, agents require cryptographically verifiable identities and authorization boundaries:
- Model Context Protocol (MCP): Dynamic inspection and identity verification of MCP tool servers to protect autonomous agents against prompt injection and unauthorized capability invocation.
- Agent-to-Agent (A2A) Protocol: Rigorous validation of agent manifests, capability cards, and multi-tenant operational constraints.
- Cryptographic Delegation Chains: Verification of verifiable delegation receipts that limit agent execution scope, duration, and authority without exposing root private keys.
Architectural Pillars
Section titled “Architectural Pillars”+-----------------------------------------------------------------------------------+| Applications & Agents || TypeScript SDK (@didis/client) | Python SDK (didis-py) | CLI (didis) |+-----------------------------------------------------------------------------------+ | v+-----------------------------------------------------------------------------------+| DID.is Resolution Daemon || - Rate Limiting (Token Bucket) - SSRF Protection (SafeHttpClient) || - Content-Type Negotiation - Strict Path Decoding |+-----------------------------------------------------------------------------------+ | +-------------------------------+-------------------------------+ | | | v v v+------------------+ +-------------------+ +--------------------+| Native Drivers | | Evidence Engine | | Agent Sandbox || - did:web | | - Proof Invariants| | - MCP Tool Audit || - did:key | | - Status Lists | | - A2A Verification || - did:jwk | | - Policy Engine | | - Delegation Tree || - did:pkh | | - Forensic Graph | | - Scoped Auth |+------------------+ +-------------------+ +--------------------+Quick Navigation
Section titled “Quick Navigation”Explore the comprehensive documentation sections:
| Documentation Guide | Primary Audience | Key Topics Covered |
|---|---|---|
| User & Customer Guide | End-users, Platform Operators, Auditors | Web portal walkthrough, key management, credential inspection, audit dossiers, billing & usage limits |
| Developer Guide & SDKs | Engineers, Integration Architects | 5-minute quickstart, TypeScript & Python SDKs, CLI commands, webhook delivery, error handling |
| Standards & Verification | Cryptographers, Protocol Auditors | Normative standards conformance, signature verification suites, fail-closed status lists, cryptographic invariants |
| HTTP API Reference | API Integrators, Backend Engineers | Complete HTTP endpoint schemas, request/response payloads, authentication scopes, RFC 9457 problem details |
30-Second Example
Section titled “30-Second Example”Resolve any decentralized identifier directly using the public HTTP API:
# Resolve a did:web identifiercurl -s "https://did.is/api/v1/resolve/did:web:w3c-ccg.github.io:user:alice" | jq .Or dereference using the @didis/client TypeScript SDK:
import { DidisClient } from '@didis/client';
const client = new DidisClient({ baseUrl: 'https://did.is/api',});
// Resolve DID document and verify cryptographic evidenceconst resolution = await client.resolve('did:web:identity.foundation');
console.log('Status:', resolution.didDocumentMetadata.deactivated ? 'Deactivated' : 'Active');console.log('Verification Methods:', resolution.didDocument?.verificationMethod?.length);Next Steps
Section titled “Next Steps”- Ready to get started? Dive into the 5-Minute Quickstart.
- Need an end-user overview of the web explorer? Check the User & Customer Guide.
- Integrating via raw HTTP? Review the API Contract.