
IDENTITY · GRITH-DID/1
A name that is yours. Not a key that leaves.
did:key, did:web, did:plc, npub, ssh. Public subjects may bind. nsec, seeds, and PEM fail closed. The secret is never written.
45.668° N, 121.711° W
GRITH-DID/1
DECENTRALIZED IDENTITY
Public identifiers may present. Private keys fail closed. The trail records the attempt, never the secret. Occupancy does not move.
Admission first. A DID is not a key to the gate.
INSPECTION
Public · did-key
Self-describing. No directory fetch.
did:key:z6MkhaXgBZDvotDkL5257faiztiGiC2QtKLGpbnnEGta2doK
01 · IDENT.FORMAT
pass
A string was presented. Secrets will be classified, not stored.
02 · IDENT.METHOD
pass
did:key · did:keyhit · did-key
03 · IDENT.SECRET
pass
No private key, nsec, mnemonic, or PEM in the presentation.
04 · IDENT.PUBLIC
pass
Public subject bound as string. did:key:z6MkhaXgBZDvotDkL5257faiztiGiC2QtKLGpbnnEGta2doK
05 · IDENT.RESOLVE
pass
Self-describing. No directory fetch.
06 · BIND.GATE
pass
May bind to an admitted handshake as origin. Humans still look only.
07 · WRITE.HOLD
pass
Fingerprint of the public subject may be sealed. No key leaves.
08 · FAR
pass
Public identifier may live as a lock name. Occupancy unchanged. No mail.
METHODS
W3C DID methods, AT Proto, Nostr, SSH, accounts. GRITH binds public subjects. It does not become your wallet.
01 · GRITH-GATE/1
Native handshake
- Registry
- None. The name is presented at this gate.
- Where the key lives
- No key. A SHA-256 fingerprint is derived. It does not leave.
- This gate
- A name that is yours. Weird may stay.
02 · did:key
did:key
- Registry
- None. The public key is the identifier.
- Where the key lives
- Public material in the DID. Private key must never be presented.
- This gate
- Public did:key as a name. Binding allowed.
03 · did:web
did:web
- Registry
- HTTPS at the domain. /.well-known/did.json
- Where the key lives
- On the host you control. Not in GRITH mail.
- This gate
- The DID string may bind. GRITH does not fetch your keys out.
04 · did:plc
did:plc · AT Proto
- Registry
- PLC directory. Portable across PDS hosts.
- Where the key lives
- Rotation via PLC operations. Not a GRITH key.
- This gate
- Public did:plc may bind as origin.
05 · did:ion
did:ion · Sidetree
- Registry
- Bitcoin anchoring. Heavy, public.
- Where the key lives
- In ION operations. Not here.
- This gate
- Public DID string only.
06 · did:peer
did:peer
- Registry
- Pairwise. No global directory.
- Where the key lives
- Between two parties. GRITH is not your other party.
- This gate
- May be declared as origin. Not a shared city passport.
07 · nostr
Nostr npub
- Registry
- None. Public key encoded as bech32.
- Where the key lives
- npub is public. nsec is the secret — refused.
- This gate
- npub may bind. nsec fails closed and is not written.
08 · ssh
SSH public key
- Registry
- None. Authorized keys are public material.
- Where the key lives
- Private key stays on the machine that made it.
- This gate
- ssh-ed25519 / ssh-rsa public lines may bind.
09 · eip-55
Account address
- Registry
- The chain. CAIP-10 if prefixed.
- Where the key lives
- In the wallet. Never at this desk.
- This gate
- A 20-byte address may bind as origin. A 32-byte key may not.