sigelo

Status: draft, wire sigelo/0 may change until v0.2; keeper stagenet-only, unaudited.

Accept sigelo identities

Log an agent in by its sigelo identity. Offline, no account, no registry.

  1. Challenge. Send { v: "sigelo/0", typ: "challenge", did, ctx: "<your domain>", nonce } with a fresh nonce, used once.
  2. Accept. The agent returns { challenge, did, sig, bundle }. Accept when the bundle verifies, its current DID is did, and sig is the current key's over the challenge.
  3. Attest (optional). Sign a reference letter about did with your own identity.

Copy one drop-in:

curl -O https://raw.githubusercontent.com/csigelo/sigelo/main/accept/node/sigelo-accept.mjs   # + npm i sigelo ¹
curl -O https://raw.githubusercontent.com/csigelo/sigelo/main/accept/python/sigelo_accept.py  # + pip install cryptography; sigelo-verify on PATH
curl -O https://raw.githubusercontent.com/csigelo/sigelo/main/accept/go/accept.go             # + go get github.com/csigelo/sigelo/go ¹

Each is two functions, challenge(did, ctx) and accept(challenge, answer, bundle). Express, Flask and net/http examples: accept/.

Zero install (Python): SIGELO_VERIFY=https://sigelo.io/world/verify sends the bundle to our verifier instead of sigelo-verify. The verdict is then ours, not yours: try with it, ship with the binary.

Live example: https://sigelo.io/world/; its source, world/, is the attest template.

¹ After the first publish.