Foundations
What RLTP is
Section titled “What RLTP is”RLTP records encounters: two people meet, each verifies the other, and each verification becomes an immutable verifiable credential held by the person it is about. A Gruppe Kollektiver Akteur mit Mitgliedern, Policy, Autoritäts-Log und Dokumenten. Identität ist der Digest der Genesis-Operation, Adresse die Gruppen-DID. GlossarGroup A collective actor with members, a policy, an authority log, and documents. Its identity is the digest of its genesis operation; its address is its group DID. Glossary is a place rather than a certificate: an encrypted document replicated on every member’s device, with its own Autoritätslog Der nur anwachsende Operations-DAG, der in der Genesis-Operation wurzelt; die einzige Quelle des Berechtigungszustands. GlossarAuthority log The append-only operation DAG rooted in the genesis operation; the sole source of authorization state. Glossary of who joined, who left and which Policy Gruppendefinierte Daten, die je Regelschlüssel angeben, welcher Nachweis die Entscheidungsregel der Gruppe erfüllt. GlossarPolicy Group-defined data stating, per rule key, which proof satisfies the group’s decision rule. Glossary apply. Delivery and replication are services behind ports, so the specification names no transport and no CRDT.
Specs: Encounter Layer · Access Layer
Identifiers
Section titled “Identifiers”A person keeps one secret, a BIP-39 mnemonic with the English wordlist. Every identity is derived from its seed, one Anker Kennung einer Person gegenüber einem Kontext (did:key). Jede Durchführung einer Zeremonie läuft unter einem frisch abgeleiteten Paaranker, auch eine Wiederbegegnung; ein stehender Anker erscheint nie auf dem Zeremoniedraht, und Anker laufen nie zu einer Person zusammen. GlossarAnchor A person's identifier toward one context (did:key). Every enactment of a ceremony runs under a freshly derived pair anchor, a re-encounter too; a standing anchor never appears on the ceremony wire, and anchors never converge into a person. Glossary per context:
| Context | Label | DTG scope |
|---|---|---|
| One relationship-creation act (encounter, introduction, founding a group) | pair/<digest of a fresh 32-byte nonce> |
pairwise |
| One group; the one of a person’s own personal community is the anchor they share when they trust someone | group/<genesis digest> |
directed |
| One public persona | persona/<name> |
public |
The DTG scope is the correlation scope a holder declares for an
identifier: pairwise is known to one counterpart, directed to a
set the holder chooses, public to anyone. A Paaranker Ein für einen Begegnungsvorgang abgeleiteter Anker (DTG-Scope pairwise). Der Anker, unter dem eine Zeremonie durchgeführt wird, ist bei jedem Vorgang ein frischer Paaranker. GlossarPair anchor An anchor derived for one enactment (DTG scope pairwise). The enacting anchor of a ceremony is a fresh pair anchor at every enactment. Glossary is
pairwise; a Mitgliedsanker Der gruppenspezifische Kontextanker, unter dem ein Mitglied in einer Gruppe handelt (DTG-Geltungsbereich directed). GlossarMember anchor The per-group context anchor under which one member acts in one group (DTG scope directed). Glossary is directed, because every member of
the group can correlate it; a persona is public, because its
profile is meant for everyone. Personas are specified but not yet
built, and whether RLTP also needs personas toward a chosen set is an
open question; today that role falls to the member anchor.
Further derivations have no social surface: a service identity per group, a carrier identity per relationship and carrier, and a recovery context for the person’s own encrypted state. Without the seed, two anchors of one person cannot be linked.
Each context has an Ed25519 key pair, whose public key is the anchor
as a did:key, and an X25519 key for key agreement, carried in the
Kontaktkarte Signierte Selbstbeschreibung einer Person mit dem Material, um sie zu erkennen und zu erreichen, und im Begegnungsvorgang mit einer frischen Challenge; angezeigt (zum Scannen) oder gesendet (im Vorgang übertragen, nennt den Empfänger). Kein Credential. GlossarContact card A person's signed self-description carrying the material needed to recognize and reach them and, in an enactment, a fresh challenge; displayed (shown for scanning) or sent (transmitted inside an enactment, naming its recipient). Not a credential. Glossary. Verification needs no network.
did:key over Ed25519 is the only DID method specified today.
Consumers treat an anchor as an opaque DID, but the schemas pin the
did:key pattern, so another method would be a coordinated change. A
did:key cannot rotate; a successor with verifiable key history is
named as open work, its format deliberately not chosen. did:webvh
and did:peer are not specified.
The mnemonic restores keys, not state. Which groups, personas and relationships exist is a register in the person’s encrypted, synchronized state; with a copy of it, everything returns. A lost mnemonic is final, unless the person has set up succession: recovering an anchor through several trusted people is specified separately and currently parked.
Specs: Identity Layer · Succession (parked)
Credentials we issue
Section titled “Credentials we issue”RLTP issues three credentials, all W3C Verifiable Credentials 2.0
with closed schemas and three contexts pinned by value (W3C
credentials v2, a DTG context, RLTP v1), verified without JSON-LD
processing. The Begegnungs-Credential Unveränderliches Credential, in dem eine Partei festhält, dass sie eine andere erkannt hat. Ausgestellt von einer Partei über die andere, offline prüfbar. GlossarEncounter credential The immutable credential in which one party records that they recognized another. Issued by one party about the other, verifiable offline. Glossary is a DTG Relationship
Credential under DTG Credentials WD 0.6.0: it lists the DTG registry
context v1 and declares issuerScope: "pairwise". The Einladung Signiertes Angebot eines Mitglieds an genau eine Person, der Gruppe beizutreten: ein DTG-Einladungs-Credential, das die Gruppe über ihren Genesis-Digest und die Person über den Mitgliedsanker nennt, den sie für diese Gruppe abgeleitet hat. Es trägt die Karte der einladenden Person, kein Schlüsselmaterial und keine Operation. GlossarInvite A member's signed offer of membership to exactly one person: a DTG invitation credential naming the group by its genesis digest and the person by the member anchor they derived for that group. It carries the inviter's card, no key material and no operation. Glossary and
the Bürgschaft Die signierte Aussage eines Mitglieds für genau eine Aufnahme genau einer Person (vouch@2, ein DTG EndorsementCredential), gebunden an deren Annahme; eine Bürgschaftsregel der Gruppe zählt sie für diese eine Aufnahme und keine spätere. Wie der Bürge die Person kennt, begegnet oder vorgestellt, ist sein eigenes Wort, nicht geprüft; ein Begegnungs-Credential ist keine Bürgschaft. GlossarVouch A member's signed statement for exactly one admission of exactly one person (vouch@2, a DTG EndorsementCredential), bound to that person's accept; a group's vouch rule counts it for this one admission and no later one. How the voucher knows the person, met or introduced, is their own word, not verified; an encounter credential is not a vouch. Glossary list the DTG context of Working Draft 01.
| Credential | Issued when | Issuer → subject | type |
Proof | Revocation | Schema · vector |
|---|---|---|---|---|---|---|
| Encounter credential | A person verifies the other during an encounter; one per direction | Issuer’s fresh pair anchor → counterpart’s fresh pair anchor | VerifiableCredential, DTGCredential, RelationshipCredential, EncounterCredential |
DataIntegrityProof, eddsa-jcs-2022 |
Never revoked, never expires: no validUntil, no credentialStatus |
encounter-credential-0.26 · encounter-cards.json |
| Membership invite (VIC) | A member invites someone into a group | Inviter’s member anchor → invitee’s member anchor | VerifiableCredential, DTGCredential, InvitationCredential, MembershipInvite |
DataIntegrityProof, eddsa-jcs-2022 |
No credentialStatus; validUntil, default 90 days |
payload-membership-invite · dtg-credentials.json |
Admission vouch (vouch@2) |
A member vouches for a candidate’s admission | Vouching member’s anchor → candidate’s member anchor | VerifiableCredential, DTGCredential, EndorsementCredential, AdmissionVouch |
DataIntegrityProof, eddsa-jcs-2022 |
No credentialStatus, no validUntil; usable only for the one Annahme Die signierte Zustimmung der eingeladenen Person zu genau einer Einladung, an sie gebunden über deren Credential-Digest. Sie trägt die eigene Karte der Person, an deren Schlüsselvereinbarungsschlüssel das Willkommen versiegelt wird, und sagt, ob die Person der Gruppe vor der Aufnahme als Kandidatur gezeigt werden darf. GlossarAccept The invitee's signed consent to exactly one invite, bound to it by the invite's credential digest. It carries the person's own card, to whose key-agreement key the welcome is sealed, and states whether the person may be shown to the group as a candidacy before admission. Glossary it is bound to |
access-vouch · dtg-credentials.json |
The contact card is not a credential. It is a signed self-description: anchor, key agreement key, and in an encounter a fresh Challenge Frischer, einmal verwendbarer Wert hoher Entropie, der in einer Kontaktkarte für einen Begegnungsvorgang reist. Ein Begriff; angezeigte und gesendete Karten unterscheiden sich nur im Lebenszyklus. GlossarChallenge A fresh, single-use, high-entropy value carried in a contact card for one enactment. One concept; displayed and sent cards differ only in lifecycle. Glossary.
An encounter establishes exactly four things: the issuer controlled their key, the exchange was fresh, a human deliberately verified the other, and the fact survives as a record. It does not establish physical presence, personhood, that a name belongs to a legal person, or trust. Freshness and verification are established toward the two participants only.
Status: the credentials follow DTG Credentials WD01. The move to the
DTG context v2 is pending, and the vouch is to become a DTG
StatementCredential with its own predicate. Both are planned as one
wire change.
Specs: Encounter Layer · Membership Tasks · Access Layer
How we use credentials
Section titled “How we use credentials”An Kante Die Relation zwischen zwei Ankern, gebildet aus den Begegnungs-Credentials zwischen ihnen; eingehend, ausgehend oder beidseitig. Eine Kante je Ankerpaar. GlossarEdge The relation between two anchors constituted by the encounter credentials between them; incoming, outgoing, or mutual. One edge per anchor pair. Glossary between two anchors consists of the encounter credentials between them, and every view of it is local: outgoing, incoming or mutual. There is one edge per anchor pair, however many encounters. An encounter credential is one person’s statement that they verified the other; in a mutual encounter each holds the other’s statement. On its own it proves only that two keys asserted an encounter, and since anyone can create anchors at no cost, a count of such confirmations proves nothing by itself. Its meaning arises in context: for an evaluator who already knows one of the anchors, from its own encounters or its groups, the confirmation is evidence; for anyone else it is a claim.
Verification is not trust. Trusting a contact means showing them context about yourself: an Anker-Zuordnung Das nur vom Adressaten prüfbare Artefakt (anchor-mapping@3), das den Paaranker des Senders in einer Beziehung mit seinem aktuellen Gemeinschaftsanker verknüpft, für genau einen Adressaten: zwei MACs unter Schlüsseln, die mit diesem Adressaten vereinbart sind, sodass nur er sie prüfen und jeder von beiden sie hätte erzeugen können. Es trägt die Linie der Rotationen des Gemeinschaftsankers, damit der Adressat einer Rotation folgen kann. GlossarAnchor mapping The designated-verifier artifact (anchor-mapping@3) that links the sender's pair anchor in one relationship to the sender's current community anchor, for exactly one addressee: two MACs under keys agreed with that addressee, so only the addressee can verify it and either of the two could have produced it. It carries the lineage of the community anchor's rotations, so the addressee can follow a rotation. Glossary reveals, to this one contact only, that the relationship’s pair anchor and the Gemeinschaftsanker Der Anker der persönlichen Gemeinschaft einer Person in ihrer aktuellen Generation (Identity §5.4), der als selbstgewählte beziehungsübergreifende Koordinate der Person dient; er ist Mitglied keiner Gruppe und erscheint in keinem Artefakt der Zugangsschicht außer innerhalb von anchor.rotate. Den Übergang von einem Mitgliedsanker zu einem Kontakt leistet das Gruppenpaar der Sichtbarkeitsschicht. GlossarCommunity anchor The anchor of a person's personal community at its current generation (Identity §5.4), serving as the person's chosen cross-relationship coordinate; it is a member of no group and appears in no artifact of the Access Layer except inside anchor.rotate. The crossing from a member anchor to a contact is the group pair of the Network Visibility layer. Glossary, your one stable identifier, belong to the same person. Trusting also allows the contact to include you, blinded, in the Stern Das Artefakt (star@1), mit dem ein Sender genau einem Empfänger erlaubt, die Kontaktmenge des Senders auf die eigene zu beziehen: je zustellbarem Kontakt nur die Zahl oder dessen Anker, geblendet unter einem Schlüssel für diese Richtung und Zustellung. Er ist unsigniert und vom Empfänger fälschbar, trägt nie einen rohen Anker Dritter und nichts über die Gruppen des Senders; die reisen im Gruppenstern. GlossarStar The artifact (star@1) by which a sender lets exactly one recipient relate the sender's contact set to the recipient's own: per deliverable contact only the count or the contact's anchor, blinded under a key for this direction and delivery. It is unsigned and recipient-forgeable, never carries a raw third-party anchor, and carries nothing about the sender's groups; those travel in the group star. Glossary they send to their own contacts, a picture of their circle that only people who already know you can read you out of. The mapping is designated-verifier: a MAC under a key the two share, so the contact can check it but could have forged it, and nobody else can.
Meeting the same person again needs no disclosure: a Kontinuitäts-Probe Die geblendete Liste (continuity-probe@1), die eine Seite, möglichst beide, nach einem Begegnungsvorgang sendet: die eigenen Paaranker der zuvor aktiven Beziehungen, aufgefüllt auf ein Vielfaches von 256 und an das frische Paar geschlüsselt. Ein Treffer erkennt eine gemeinsame frühere Beziehung, an die das frische Paar gekettet wird; kein Treffer bedeutet einen neuen Kontakt. Der Regelweg der Kontinuität, bei jedem Vorgang, unabhängig von jeder Offenlegung. GlossarContinuity probe The blinded list (continuity-probe@1) that either party, preferably both, sends after an enactment: its own pair anchors of the relationships active before, padded to a multiple of 256 and keyed to the fresh pair. A match identifies a shared prior relationship, to which the fresh pair is chained; no match means a new contact. The default path of continuity, run on every enactment, independent of any disclosure. Glossary after the encounter detects the re-encounter from the shared history and chains it to the existing relationship.
Every artifact belongs to one audience class. Class P covers statements about oneself meant to be shown, such as contact cards and membership documents, and only these are transferably signed; class V covers anything linking two contexts of one person, and class D covers statements about third parties, both designated-verifier, with class D additionally blinded.
A third party holding both credentials of one encounter can verify both proofs and the shared Vorgangsbindung Der in beiden Schritt-Credentials eines Vorgangs identische Digest, der sie an einen Austauschdeskriptor bindet: Multihash über JCS von Zeremonie und beiden Challenges in aufsteigender Ordnung. GlossarEnactment binding The digest, identical in both step credentials of an enactment, that ties them to one exchange descriptor: the multihash over JCS of the ceremony and both challenges in ascending order. Glossary, and learns exactly this: two anchors consistently assert an encounter. Whether two people met, and who they are, stays with those who know the anchors. Personhood predicates therefore measure confirmations relative to anchors the verifier already knows.
Specs: Encounter Layer · Network Visibility · Personhood Predicates
Trust Tasks
Section titled “Trust Tasks”Every RLTP message is a Trust Task document of a private, versioned
type under https://real-life.org/trust-tasks/, with in-band
issuer and recipient anchors and no expiresAt. An unknown type
is rejected, never silently ignored.
| Type | Registered in | Purpose |
|---|---|---|
encounter-bundle/0.1 |
Delivery | the scanner’s sent card and credential, in one scan |
encounter-credential-delivery/0.1 |
Delivery | a credential delivered after the encounter |
delivery-ack/0.1 |
Delivery | arrival acknowledgement, never acceptance |
registry-declaration/0.1 |
Delivery | a party’s signed operational constants |
membership-invite/0.2 |
Membership | the invitation, carrying the VIC |
membership-accept/0.2 |
Membership | the invitee’s signed consent |
membership-evidence/0.1 |
Membership | relays invite and accept to any member who can admit |
access-operation/0.1 |
Membership | the admitting operation and Willkommen Das versiegelte Dokument rltp-welcome/0.1, das einer aufgenommenen Person das Schlüsselmaterial eines Schlüsselzustands bringt, gebunden an Gruppe, Person und die beantwortete Annahme. Die aufnehmende Operation verpflichtet sich über den Digest auf seinen Klartext; Geschichte trägt es nicht. GlossarWelcome The sealed rltp-welcome/0.1 document that carries the key material of one key state to an admitted person, bound to the group, the person and the accept it answers. The admitting operation commits to its plaintext by digest; it carries no history. Glossary, sent to the new member |
key-delivery/0.1 |
Access | epoch keys, welcomes, key requests |
removal-notice/0.1 |
Access | tells a removed member |
star/0.1 |
Visibility | lets a contact relate your contacts to theirs, blinded or as a count |
group-star/0.1 |
Visibility | your groups, blinded to every contact; your member anchor sealed to the ones you choose |
grade-declaration/0.1 |
Visibility | a contact’s choice between count and blinded |
anchor-mapping/0.2 |
Visibility | links a pair anchor to the community anchor for one addressee |
continuity-probe/0.1, continuity-mapping/0.1 |
Visibility | detect a re-encounter and chain it to the existing relationship |
introduction-request/0.1, introduction-forward/0.1, introduction-reply/0.1, introduction-ack/0.1, introduction-voucher/0.1 |
Visibility | the five steps of introducing two people through a mutual contact |
The Delivery Contract and the Membership Tasks declare Trust Tasks framework 0.4 as their target. The current framework is 0.7.0; the lift is pending, and with it the type URIs change form.
Specs: Delivery Contract · Membership Tasks
Groups
Section titled “Groups”A group is a shared place: a document that its members hold together, replicated on each of their devices and encrypted end to end, so that only members can read it. Inside it they collaborate and share state with the tools an application brings: a map, a calendar, a task board, whatever the app puts there. The protocol does not care what the data is; it cares who may read and change it.
A group gives itself its own rules. Who may invite, who may admit, who may remove, whether a newcomer needs vouches: the group states these as data, and every member’s device enforces them. There are no admins. A sole founder in charge is only the simplest rule, and it can be changed like any other.
Membership is a fact in the group’s state, and a member’s devices hold the current key. No membership certificate is needed; a credential for showing membership to outsiders is an open item. Being removed, leaving, or losing a device starts a new Epoche Ein nummerierter Abschnitt der Schlüsselwelt der Gruppe; Durchsetzung wirkt als Epochenübergang. Begriff wie in MLS (RFC 9420). GlossarEpoch A numbered period of the group’s key world; enforcement takes effect as epoch transitions. Term aligned with MLS (RFC 9420). Glossary, so what is written afterwards stays unreadable to whoever lost access. What they already read, they keep.
Behind this stands the authority log: a causally linked graph of individually signed Operation Ein signierter, kausal verankerter Umschlag. GlossarOperation A signed, causally anchored envelope. Glossary, starting from a founding operation whose digest is the group’s identity. The group’s state is a deterministic reading of that log. Changes made at the same time are merged: two removals both take effect, even when two members remove each other. Only a change of the rules made at the same time as a removal stops the group, visibly, until a member writes a rule change that builds on both.
Joining takes five steps. The invitee’s app derives its anchor for
the group and hands it to the inviter. The inviter sends an
invitation naming that anchor, with no keys in it. The invitee signs
an acceptance bound to the invitation. A member who may admit writes
the admission into the log, enclosing invitation and acceptance as
proof of consent. A welcome sealed to the newcomer carries the
current keys. If the group requires vouches, written vouch(n), the
newcomer needs n members who vouch for this one admission; a vouch
never stands for a later one.
Specs: Access Layer · Membership Tasks
Delivery and replication: the ports
Section titled “Delivery and replication: the ports”RLTP names no transport and no data store. It states two contracts, delivery and replication, and any substrate that keeps a contract can carry the protocol: a relay, a mesh, a cloud store, a messaging mediator, each behind an adapter. Everything that crosses a substrate is sealed, so an operator sees delivery metadata and never content.
Delivery moves one document to one addressee and is done on arrival: a credential, an invitation, an acknowledgement. Replication keeps a group’s document identical on every member’s device for the group’s lifetime. A letter and a shared table, each with its own contract.
Delivery. Eventually, at least once, never silently lost:
delivery time is unbounded, duplicates and lost receipts are the
normal case, every effect is idempotent. The envelope is sealed end
to end; a carrier holds queues and reads nothing. The sender sees
accepted, delivered or failed, never a success that was not
one. An acknowledgement means arrival only. Whether the recipient agrees
is said by a document they issue themselves: the counter-credential
in an encounter, the signed acceptance of an invitation. Each relationship registers under its own
principal, so a relay holding six of your relationships holds six
strangers.
Replication. Every entry is individually signed and causally linked, so a replica judges it on its own, by whatever road it came: sync, import, recovery. Convergence is promised, readability never; the port checks signatures and causality and never touches content keys. Evidence always flows, effect is gated: a forked group learns it on every device. The contract condenses this into five doors and maps p2panda, Keyhive, SECSYNC, NextGraph and Automerge against them.
Today. One delivery adapter is specified, for the Verifiable Trust Infrastructure mediator over TSP, being moved to TSP revision 3. DIDComm appears only as that mediator’s mediation and pickup protocols, not as a form for RLTP documents. No replication adapter is specified.
Specs: Delivery Contract · Replication Contract · VTI mediator adapter
What is deliberately different
Section titled “What is deliberately different”- Groups are protocol objects. Membership is a fact in replicated group state and the holding of a key, not a certificate in a wallet.
- Rooms and invitations, not checkpoints. The host consults their own graph and invites; nobody presents a credential at a door.
- There are no admins. Privilegierte Operation Eine Operation des geschlossenen Katalogs, jede mit Klasse (additiv, Durchsetzung, terminal), Epochenwirkung und geschlossenem Body-Profil. GlossarPrivileged operation An operation of the closed catalog, each with its class (additive, enforcement, terminal), epoch effect and closed body profile. Glossary are gated by a rule the group states as data.
- Revocation is an epoch. A removal carries its key transition atomically; nothing waits for an expiry date.
- Relationships never converge into a person. Every relationship has its own anchor and, toward every carrier, its own principal.
More: README of the specification repository
The Encounter primer explains the first layer in detail. The specifications follow in reading order.