Sandbox · invented parties only

The system.

Three seats at one table: a resident, a county department, and the public verifier. Keys for the resident are generated in this browser and never leave it. Department keys are sandbox keys; in a pilot they live in the department's own custody.

C-node

Your resident wallet

A keypair is created on this device with WebCrypto and stored non-extractably in this browser. The identifier is derived from the public key, so nobody can claim it without holding the key.

DID
Algorithm
Public key
Registered
Held credentials

What this wallet holds

Issued by a department G-code, non-transferable, anchored to the DID above. Refreshes after each issuance.

No wallet yet.
G-code

Act as a county department

Each department is anchored to a namespace root that exists on three public chains. The sandbox key is filled for you; a pilot never serves department keys.


Attribution

Record who opened the door

Recorded once, permanently. A second introduction for the same resident and programme is refused, and the first stands.

Response

What the engine wrote

Select a department and issue a credential to a DID.

Every action above returns the receipt it wrote: sequence, hash and the hash it commits to.

Verifier

Prove one fact, disclose nothing else

A bank, an inspector or a landlord asks one question. The resident signs the verifier's nonce with the key on their device; the answer to that single fact comes back, and the record behind it does not.

Choose a credential held by your wallet.
Revocation

Issuing department withdraws it

Only the department that issued a credential can revoke it, and revocation is itself a receipt — the history is never edited, only extended.

Receipt chain

Replay it yourself

Each receipt's hash is sha256 of the previous hash and the canonical record. The verifier walks the whole chain and names the first sequence where the arithmetic disagrees, if there is one. No login.

SeqEventActorSubjectHashAt