People & Orgs
Personhood and relationship credentials, wallets, and selective / zero-knowledge disclosure.
VTI handles trust between people, AI agents, and communities — on cryptographic rails, with human-in-the-loop governance and regulatory alignment built into the architecture, not bolted on.
Personhood and relationship credentials, wallets, and selective / zero-knowledge disclosure.
Scoped agent identity that acts on your behalf — with mandates it cannot exceed.
Verifiable Trust Communities write their own membership rules and own their trust graph.
did:webvh, DIDComm v2, the Trust Spanning Protocol, post-quantum and ZK cryptography.
Human-in-the-loop approval, least privilege, kill-switch, and tamper-evident audit.
Architecturally aligned with eIDAS 2.0, Utah SEDI, and China’s 2026 agent rules.
Delegated Trust-Task Execution keeps a human in the loop without breaking agent workflows. Every approval is bound to an exact payload digest — single-use, no replay, two-device separation enforced.
Proposes a task and payload. Holds zero authority. Never learns who approved, or when.
Dry-runs the real handler, produces human-readable effects, and enforces the boundary. The only party that sees everything.
Receives the effects and a 6-character match code. Signs a single-use decision. Never sees the payload.
// Anti-bait-and-switch: approval carries a fingerprint of the
// exact request. Any change and the vault refuses to execute.
digest = hmac(salt, length_prefix(type_uri) + payload_bytes)
// Anti-replay: each approval is single-use, consumed at execution.
grant.status = GrantStatus::Consumed;
// Two-device separation: the device that acts is never the one
// that approves.
assert!(requester_did != approver_did); eIDAS 2.0 has no agent trust, no community trust graph, and no DTTE. VTI does.
One signed envelope for 555 agent operations, transport-independent.
Approval bound to an exact payload digest — single-use, two-device separation.
Operations that carry their own authority, preventing approval regress.
Isolated BIP-32 key hierarchies, one per life domain.
Something that acts — not just something that presents credentials.
VRCs (Verifiable Relationship Credentials), cross-community recognition, witness evidence.
“This operation needs two approvers” is one config row.
use affinidi_tdk::{VTA, CredentialBuilder, TrustTask};
let vta = VTA::new()
.with_context("work") // isolated key hierarchy
.with_enclave(EnclaveMode::Nitro) // TEE for key custody
.build().await?;
let credential = CredentialBuilder::new()
.subject(holder_did)
.claim("age_over_18", true)
.selective_disclosure() // BBS+ ZKP
.sign(&vta).await?; EUDI ARF-aligned (v2.x)
State-Endorsed Digital Identity · aligned
May 2026 — architecture aligned
In plain terms: one agent that holds its own keys and credentials, signs without ever exposing them, talks to other agents, and only acts on operations a human approved. The full technical map is one click away.
| Plane | Capabilities | Status |
|---|---|---|
| A · Cryptographic Core | BIP-32 key derivation, Ed25519 / X25519 / P-256, ML-DSA (PQC), a signing oracle that never exports keys, secrets vault with soft-delete. | Live |
| B · Identity | Full did:webvh lifecycle, 11 DID document templates, agent naming, serverless and server-managed publication. | Live |
| C · Credentials | Issuance with EdDSA-JCS-2022, SD-JWT VC, BBS-2023, ZKP and mdoc formats; selective disclosure; human-in-the-loop approval on inbound offers. | Live |
| D · Access Control | Challenge-response auth over TSP / DIDComm / REST, Data-Integrity Trust Tasks, 5 role classes, 11 capability types, Rego policy engine. | Live |
| E · Agents & Devices | Per-context agent memory (isolated KV stores), MCP bridge over stdio, device binding, push-wake channels. | Live |
| F · Transport | Preference TSP › DIDComm v2 › REST with no silent degradation, mediator drain windows. Early TSP production deployment (with CardInfoLink). | Live |
| G · Operations | Two-phase backup / recovery, audit logging at the dispatch spine, TEE attestation (Nitro, SEV-SNP), anti-rollback anchor MAC. | Live |
| H · Interop | OID4VCI, OID4VP, DCQL, SIOPv2, SD-JWT VC, ISO mdoc 18013-5/-7, BBS-2023, TSP, DIDComm v2. | Live |