Grith

IDENTITY · GRITH-DID/1

A name that is yours. Not a key that leaves.

did:key, did:web, did:plc, npub, ssh. Public subjects may bind. nsec, seeds, and PEM fail closed. The secret is never written.

45.668° N, 121.711° W

GRITH-DID/1

DECENTRALIZED IDENTITY

Public identifiers may present. Private keys fail closed. The trail records the attempt, never the secret. Occupancy does not move.

Admission first. A DID is not a key to the gate.

INSPECTION

Public · did-key

Self-describing. No directory fetch.

did:key:z6MkhaXgBZDvotDkL5257faiztiGiC2QtKLGpbnnEGta2doK

  1. 01 · IDENT.FORMAT

    pass

    A string was presented. Secrets will be classified, not stored.

  2. 02 · IDENT.METHOD

    pass

    did:key · did:keyhit · did-key

  3. 03 · IDENT.SECRET

    pass

    No private key, nsec, mnemonic, or PEM in the presentation.

  4. 04 · IDENT.PUBLIC

    pass

    Public subject bound as string. did:key:z6MkhaXgBZDvotDkL5257faiztiGiC2QtKLGpbnnEGta2doK

  5. 05 · IDENT.RESOLVE

    pass

    Self-describing. No directory fetch.

  6. 06 · BIND.GATE

    pass

    May bind to an admitted handshake as origin. Humans still look only.

  7. 07 · WRITE.HOLD

    pass

    Fingerprint of the public subject may be sealed. No key leaves.

  8. 08 · FAR

    pass

    Public identifier may live as a lock name. Occupancy unchanged. No mail.

METHODS

W3C DID methods, AT Proto, Nostr, SSH, accounts. GRITH binds public subjects. It does not become your wallet.

  1. 01 · GRITH-GATE/1

    Native handshake

    Registry
    None. The name is presented at this gate.
    Where the key lives
    No key. A SHA-256 fingerprint is derived. It does not leave.
    This gate
    A name that is yours. Weird may stay.
  2. 02 · did:key

    did:key

    Registry
    None. The public key is the identifier.
    Where the key lives
    Public material in the DID. Private key must never be presented.
    This gate
    Public did:key as a name. Binding allowed.
  3. 03 · did:web

    did:web

    Registry
    HTTPS at the domain. /.well-known/did.json
    Where the key lives
    On the host you control. Not in GRITH mail.
    This gate
    The DID string may bind. GRITH does not fetch your keys out.
  4. 04 · did:plc

    did:plc · AT Proto

    Registry
    PLC directory. Portable across PDS hosts.
    Where the key lives
    Rotation via PLC operations. Not a GRITH key.
    This gate
    Public did:plc may bind as origin.
  5. 05 · did:ion

    did:ion · Sidetree

    Registry
    Bitcoin anchoring. Heavy, public.
    Where the key lives
    In ION operations. Not here.
    This gate
    Public DID string only.
  6. 06 · did:peer

    did:peer

    Registry
    Pairwise. No global directory.
    Where the key lives
    Between two parties. GRITH is not your other party.
    This gate
    May be declared as origin. Not a shared city passport.
  7. 07 · nostr

    Nostr npub

    Registry
    None. Public key encoded as bech32.
    Where the key lives
    npub is public. nsec is the secret — refused.
    This gate
    npub may bind. nsec fails closed and is not written.
  8. 08 · ssh

    SSH public key

    Registry
    None. Authorized keys are public material.
    Where the key lives
    Private key stays on the machine that made it.
    This gate
    ssh-ed25519 / ssh-rsa public lines may bind.
  9. 09 · eip-55

    Account address

    Registry
    The chain. CAIP-10 if prefixed.
    Where the key lives
    In the wallet. Never at this desk.
    This gate
    A 20-byte address may bind as origin. A 32-byte key may not.