Documentation · Identity
  1. Documentation overview
  2. Core concepts
  3. Protocol Line
  4. Foundation
  5. Identity
  6. Pairwise protection
  7. Messaging & reliability
  8. HTTPS transport
  9. Groups & federation
  10. Verification
  11. Governance & license

Identity: user authority across independent endpoints

Identity defines self-certifying user authority, predecessor-bound transitions, independent Endpoint devices, recovery, private Routes, and transparency evidence.

User authority state

A self-certifying user reference derives from canonical genesis management and recovery public-key material. Every authority state binds the line identity, epoch, exact predecessor, transition kind, management and recovery keys, a bounded device set, and authority signatures.

Independent devices stay independent

Each authorized device remains a distinct Endpoint with its own keys, state, and sessions. Device authorization admits possession under an accepted authority state; it does not merge keys, establish peer trust, identify one legal human, or create a directory.

Recovery is an atomic transition

A predecessor recovery-key-authorized transition may replace authority keys while revoking compromised Endpoints and admitting replacements. It cannot recreate absent data or bypass external account policy. Forks remain explicit.

Three independent chains

User authority, Endpoint identity state, and Station descriptor lineage each advance under their own validation rules. Pairwise establishment binds sibling authority-state digests beside the two Endpoint-state digests without putting peer digests inside authority snapshots.

Private relationship Routes

Relationship routing information is Endpoint-controlled. Discovery and transparency evidence are local-policy inputs; infrastructure does not become an identity authority, and a successful proof does not automatically set peer trust.