Skip to content

DID.is — Identity, Resolved

DID.is is the universal identity resolution, cryptographic evidence, verification, and agent trust infrastructure for the decentralized web and autonomous agent internet.

It resolves decentralized identifiers (DIDs), verifies underlying cryptographic proofs, inspects Verifiable Credentials (VCs), evaluates declarative policies, inspects Model Context Protocol (MCP) tool servers and Agent-to-Agent (A2A) cards, verifies delegation chains, and provides continuous monitoring and telemetry.

Every conclusion reached by DID.is is traceable to an auditable check that actually executed. Nothing is ever summarized into an arbitrary trust score or ungrounded badge.


1. Cryptographic Evidence over Reputational Scores

Section titled “1. Cryptographic Evidence over Reputational Scores”

Traditional web reputation models rely on opaque heuristics, centralized gatekeepers, and subjective scoring systems. DID.is replaces trust assumptions with deterministic cryptographic verification:

  • Every statement is backed by verifiable cryptographic primitives (Ed25519, secp256k1, P-256, RSA).
  • Signature validation is fail-closed: an unrecognized curve, missing key, or expired signature immediately marks verification as failed.
  • Forensic logs track each resolution and verification step with nanosecond timestamps and SHA-256 content hashes.

DID.is strictly complies with formal standards defined by the World Wide Web Consortium (W3C) and Internet Engineering Task Force (IETF):

  • W3C DID Core 1.0 & 1.1: Universal identifier syntax, document data model, and verification relationships (authentication, assertionMethod, capabilityInvocation, capabilityDelegation, keyAgreement).
  • W3C DID Resolution v1 (CR Draft): Standardized resolution output envelopes (didDocument, didDocumentMetadata, didResolutionMetadata).
  • W3C Verifiable Credentials Data Model v2.0: JSON-LD, JWT (VC-JWT), and Data Integrity proof formats (ed25519-2020, ecdsa-jws-2020).
  • RFC 9457 Problem Details: Standardized HTTP machine-readable error responses across all daemon endpoints.

As artificial intelligence transitions from conversational interfaces to autonomous execution, agents require cryptographically verifiable identities and authorization boundaries:

  • Model Context Protocol (MCP): Dynamic inspection and identity verification of MCP tool servers to protect autonomous agents against prompt injection and unauthorized capability invocation.
  • Agent-to-Agent (A2A) Protocol: Rigorous validation of agent manifests, capability cards, and multi-tenant operational constraints.
  • Cryptographic Delegation Chains: Verification of verifiable delegation receipts that limit agent execution scope, duration, and authority without exposing root private keys.

+-----------------------------------------------------------------------------------+
| Applications & Agents |
| TypeScript SDK (@didis/client) | Python SDK (didis-py) | CLI (didis) |
+-----------------------------------------------------------------------------------+
|
v
+-----------------------------------------------------------------------------------+
| DID.is Resolution Daemon |
| - Rate Limiting (Token Bucket) - SSRF Protection (SafeHttpClient) |
| - Content-Type Negotiation - Strict Path Decoding |
+-----------------------------------------------------------------------------------+
|
+-------------------------------+-------------------------------+
| | |
v v v
+------------------+ +-------------------+ +--------------------+
| Native Drivers | | Evidence Engine | | Agent Sandbox |
| - did:web | | - Proof Invariants| | - MCP Tool Audit |
| - did:key | | - Status Lists | | - A2A Verification |
| - did:jwk | | - Policy Engine | | - Delegation Tree |
| - did:pkh | | - Forensic Graph | | - Scoped Auth |
+------------------+ +-------------------+ +--------------------+

Explore the comprehensive documentation sections:

Documentation Guide Primary Audience Key Topics Covered
User & Customer Guide End-users, Platform Operators, Auditors Web portal walkthrough, key management, credential inspection, audit dossiers, billing & usage limits
Developer Guide & SDKs Engineers, Integration Architects 5-minute quickstart, TypeScript & Python SDKs, CLI commands, webhook delivery, error handling
Standards & Verification Cryptographers, Protocol Auditors Normative standards conformance, signature verification suites, fail-closed status lists, cryptographic invariants
HTTP API Reference API Integrators, Backend Engineers Complete HTTP endpoint schemas, request/response payloads, authentication scopes, RFC 9457 problem details

Resolve any decentralized identifier directly using the public HTTP API:

Terminal window
# Resolve a did:web identifier
curl -s "https://did.is/api/v1/resolve/did:web:w3c-ccg.github.io:user:alice" | jq .

Or dereference using the @didis/client TypeScript SDK:

import { DidisClient } from '@didis/client';
const client = new DidisClient({
baseUrl: 'https://did.is/api',
});
// Resolve DID document and verify cryptographic evidence
const resolution = await client.resolve('did:web:identity.foundation');
console.log('Status:', resolution.didDocumentMetadata.deactivated ? 'Deactivated' : 'Active');
console.log('Verification Methods:', resolution.didDocument?.verificationMethod?.length);