Skip to content

Universal Command Bar & Showcase Vectors

The primary entry point to DID.is is the Universal Command Bar located on the homepage (/) and sticky header. It accepts any identifier, URL, credential, or token, applying client-side regex and structural heuristics to automatically route the user to the correct workbench.

┌──────────────────────────────────────────────────────────────────────────────────┐
│ did:web:example.com · a credential · a JWT · https://agent.example [→]│
├──────────────────────────────────────────────────────────────────────────────────┤
│ ● DID · did:web Resolve to a document and evidence dossier ⬆ drop a file │
└──────────────────────────────────────────────────────────────────────────────────┘

The classification engine (classifyInput) analyzes input without transmitting keystrokes to the server:

Input Pattern Detected Kind Destination Route Action / Payload Handoff
did:key:z6M... did /[...did] Resolves key, extracts multicodec, verifies curve point.
did:web:example.com did /[...did] Resolves /.well-known/did.json, pins IP, checks TLS.
did:...#key-1 did-url /[...did] Dereferences exact verification method fragment.
did:...?service=agent did-url /[...did] Dereferences service endpoint URL.
example.com domain /[...did] Suggests resolving as did:web:example.com.
https://agent.example/mcp mcp /agents?tab=mcp Automatically routes to the Streamable HTTP MCP Inspector.
https://.../agent-card.json a2a /agents?tab=a2a Automatically routes to the A2A Agent Card Inspector.
https://my-company.com origin /[...did] Proposes resolving as did:web:my-company.com, with alternatives for A2A and MCP inspection.
JWS (typ: didis-delegation+jwt) delegation /agents?tab=delegation Passes single receipt via sessionStorage (didis.handoff.chain).
JSON Array of JWS tokens delegation-chain /agents?tab=delegation Passes full receipt chain via sessionStorage.
JSON ("type": ["VerifiableCredential"]) credential /verify Passes Data Integrity credential via sessionStorage (didis.handoff.credential).
JWS (typ: vc+jwt or vc claim) credential-jwt /verify Passes compact JWT credential via sessionStorage.
JSON ("id": "did:...") did-document /[...did] Extracts id and compares local document against published origin.

Users can drag and drop any local file directly onto the Universal Command Bar:

  • Maximum File Cap: Enforces a strict client-side cap of 512 KiB. Files exceeding 512 KiB are rejected with an explicit warning notice.
  • Handling: Reads file content via file.text() in browser memory, immediately classifies the contents, and updates the detection status badge.
  • Global Palette Access: Pressing ⌘K (macOS) or Ctrl+K (Windows/Linux) immediately focuses the Command Bar from anywhere on the platform.
  • Submission: Pressing Enter on single-line inputs executes the resolution. On multi-line pasted inputs (such as JSON credentials), pressing ⌘Enter or Ctrl+Enter triggers execution.
  • Escape: Closes any active modal, drawer, or search suggestion.

Instant Interactive Showcase (Ready-to-Test Vectors)

Section titled “Instant Interactive Showcase (Ready-to-Test Vectors)”

To experience the power and objectivity of DID.is immediately, you do not need to generate new credentials or configure web servers. Copy and paste any of the three reference showcase vectors below into the Universal Command Bar on the homepage (/):

┌────────────────────────────────────────────────────────────────────────────────────────┐
│ INSTANT INTERACTIVE SHOWCASE VECTORS │
├────────────────────────────────────────────────────────────────────────────────────────┤
│ Vector 1: Pure Mathematical Key │
│ did:key:z6MkhaXgBZDvotDkL5257faiztiGiC2QtKLGpbnnEGta2doK │
├────────────────────────────────────────────────────────────────────────────────────────┤
│ Vector 2: Domain-Bound with DIF Linkage │
│ did:web:identity.foundation │
├────────────────────────────────────────────────────────────────────────────────────────┤
│ Vector 3: W3C GitHub Ecosystem │
│ did:web:w3c.github.io │
└────────────────────────────────────────────────────────────────────────────────────────┘

Showcase Vector 1: did:key:z6MkhaXgBZDvotDkL5257faiztiGiC2QtKLGpbnnEGta2doK

Section titled “Showcase Vector 1: did:key:z6MkhaXgBZDvotDkL5257faiztiGiC2QtKLGpbnnEGta2doK”

Pure mathematical Ed25519 identity.

did:key:z6MkhaXgBZDvotDkL5257faiztiGiC2QtKLGpbnnEGta2doK
  • Classification & Route: The Command Bar immediately classifies this as ● DID · did:key and routes directly to /did:key:z6MkhaXgBZDvotDkL5257faiztiGiC2QtKLGpbnnEGta2doK.
  • Execution Mechanism: Zero outbound network traffic. The entire identity is mathematically derived in-memory from the multibase fingerprint in microseconds.
  • What You Will See in the Dossier:
    • Level 1 (Verdict):
      • Outcome Badge: RESOLVED (Green).
      • Summary Grouping: 3 confirmed · 1 not confirmed (with origin, transport, and history marked Not Applicable).
      • Confirmed Items:
        • Document Integrity (SELF_CERTIFYING): The document is mathematically derived from the identifier bytes.
        • Key Material (SELF_CERTIFYING): Publishes an Ed25519 public key that lies on a valid curve point.
        • Update Authority (SELF_CERTIFYING): Key changes are self-certifying.
      • Not Confirmed Item:
        • Real-World Identity (NOT_ESTABLISHED): No legal entity is confirmed.
    • Level 2 (Evidence Graph):
      • A minimal, elegant two-node graph: The Subject node connects directly to the Ed25519 Key node via a VERIFIED solid edge with an animated green pulse dot.
    • Level 3 (Telemetry):
      • Sub-millisecond execution (~15–50 µs total). Only local stages are recorded (syntax.parse, crypto.decode_multikey, crypto.validate_curve_point). Network stages (dns.resolve, tls.handshake, web.fetch) do not exist.
    • Level 4 (Substrate):
      • Keys Tab: Deconstructs the multikey into its exact multicodec varint breakdown (multibase: z (base58btc), varint: 0xed (ed25519-pub), and raw 32-byte public key hex).
      • TLS & Linkage Tabs: Omitted automatically because they do not apply to did:key.

Showcase Vector 2: did:web:identity.foundation

Section titled “Showcase Vector 2: did:web:identity.foundation”

Domain-bound Decentralized Identity Foundation identifier with two-way DIF Domain Linkage.

did:web:identity.foundation
  • Classification & Route: The Command Bar detects ● DID · did:web and navigates to /did:web:identity.foundation.
  • Execution Mechanism: Outbound HTTPS resolution to https://identity.foundation/.well-known/did.json, followed by an automatic secondary audit of /.well-known/did-configuration.json.
  • What You Will See in the Dossier:
    • Level 1 (Verdict):
      • Outcome Badge: RESOLVED (Green).
      • Verdict Headline: “Cryptographically controlled via Ed25519, origin-bound to identity.foundation.”
      • Summary Grouping: 4 confirmed · 3 not confirmed.
      • Confirmed Items:
        • Document Integrity (ESTABLISHED): Fetched document matches the domain origin.
        • Key Material (ESTABLISHED): Published Ed25519 multikeys pass curve point verification.
        • Origin Binding (ESTABLISHED): A verified DIF Domain Linkage credential proves that identity.foundation authoritatively claims this DID.
        • Transport Security (ESTABLISHED): TLS 1.3 certificate validated against Mozilla WebPKI.
      • Not Confirmed Items:
        • Update Authority (NOT_ESTABLISHED): Updates are method-governed by web hosting.
        • Verifiable History (NOT_ESTABLISHED): No hash-chained log is present.
        • Real-World Identity (NOT_ESTABLISHED): Fixed at not established.
    • Level 2 (Evidence Graph):
      • An extensive, multi-tier DAG linking Subject, Origin, TLS, Document, Keys, and the Domain Linkage Credential.
      • Both VERIFIED (cryptographic proof) and OBSERVED (transport layer) edges are displayed.
    • Level 3 (Telemetry):
      • Real-time monotonic waterfall showing dns.resolve, tls.handshake, web.fetch, crypto.validate_keys, linkage.fetch, and linkage.verify_proof (eddsa-jcs-2022). Total time: ~35–65 ms.
    • Level 4 (Substrate):
      • Domain Linkage Tab: Displays the full DIF credential table, verifying the issuer, origin, proof suite, and status PASS.
      • TLS Tab: Full certificate chain details, validity window countdown in days, serial number, and DNS SAN records.

W3C GitHub ecosystem identifier.

did:web:w3c.github.io
  • Classification & Route: The Command Bar detects ● DID · did:web and navigates to /did:web:w3c.github.io.
  • Execution Mechanism: Outbound HTTPS resolution to https://w3c.github.io/.well-known/did.json.
  • What You Will See in the Dossier:
    • Level 1 (Verdict):
      • Outcome Badge: RESOLVED (Green).
      • Summary Grouping: 3 confirmed · 4 not confirmed.
      • Confirmed Items:
        • Document Integrity (ESTABLISHED): Published document matches the host.
        • Key Material (ESTABLISHED): Keys are structurally valid on curves.
        • Transport Security (ESTABLISHED): TLS certificate presented by GitHub Pages is valid.
      • Not Confirmed Items:
        • Origin Binding (NOT_ESTABLISHED): No DIF did-configuration.json credential is published on this domain.
        • Update Authority (NOT_ESTABLISHED): Governed by GitHub Pages hosting.
        • Verifiable History (NOT_ESTABLISHED): Unversioned static web hosting.
        • Real-World Identity (NOT_ESTABLISHED): Corporate entity registration is not proved.
    • Level 2 (Evidence Graph):
      • The graph clearly shows Subject, Document, Keys, and TLS. Crucially, the Domain Linkage Credential node is absent, and the Origin edge is merely OBSERVED.
    • Level 4 (Substrate):
      • The Domain Linkage tab is omitted or empty.
  • The Core Architectural Lesson (Truth Over Scores):
    • Contrast did:web:w3c.github.io directly with did:web:identity.foundation.
    • In a conventional scoring system, w3c.github.io would receive an arbitrary 99/100 simply because the brand name “W3C” is renowned.
    • DID.is refuses this bias. Because w3c.github.io does not publish a bidirectional DIF credential, origin remains honestly and transparently NOT_ESTABLISHED.
    • This illustrates the fundamental DID.is principle: Never mistake domain reputation for cryptographic proof.