Skip to content

Foundations

RLTP records encounters: two people meet, each verifies the other, and each verification becomes an immutable verifiable credential held by the person it is about. A Gruppe Kollektiver Akteur mit Mitgliedern, Policy, Autoritäts-Log und Dokumenten. Identität ist der Digest der Genesis-Operation, Adresse die Gruppen-DID. GlossarGroup A collective actor with members, a policy, an authority log, and documents. Its identity is the digest of its genesis operation; its address is its group DID. Glossary is a place rather than a certificate: an encrypted document replicated on every member’s device, with its own Autoritätslog Der nur anwachsende Operations-DAG, der in der Genesis-Operation wurzelt; die einzige Quelle des Berechtigungszustands. GlossarAuthority log The append-only operation DAG rooted in the genesis operation; the sole source of authorization state. Glossary of who joined, who left and which Policy Gruppendefinierte Daten, die je Regelschlüssel angeben, welcher Nachweis die Entscheidungsregel der Gruppe erfüllt. GlossarPolicy Group-defined data stating, per rule key, which proof satisfies the group’s decision rule. Glossary apply. Delivery and replication are services behind ports, so the specification names no transport and no CRDT.

Specs: Encounter Layer · Access Layer

A person keeps one secret, a BIP-39 mnemonic with the English wordlist. Every identity is derived from its seed, one Anker Kennung einer Person gegenüber einem Kontext (did:key). Jede Durchführung einer Zeremonie läuft unter einem frisch abgeleiteten Paaranker, auch eine Wiederbegegnung; ein stehender Anker erscheint nie auf dem Zeremoniedraht, und Anker laufen nie zu einer Person zusammen. GlossarAnchor A person's identifier toward one context (did:key). Every enactment of a ceremony runs under a freshly derived pair anchor, a re-encounter too; a standing anchor never appears on the ceremony wire, and anchors never converge into a person. Glossary per context:

Context Label DTG scope
One relationship-creation act (encounter, introduction, founding a group) pair/<digest of a fresh 32-byte nonce> pairwise
One group; the one of a person’s own personal community is the anchor they share when they trust someone group/<genesis digest> directed
One public persona persona/<name> public

The DTG scope is the correlation scope a holder declares for an identifier: pairwise is known to one counterpart, directed to a set the holder chooses, public to anyone. A Paaranker Ein für einen Begegnungsvorgang abgeleiteter Anker (DTG-Scope pairwise). Der Anker, unter dem eine Zeremonie durchgeführt wird, ist bei jedem Vorgang ein frischer Paaranker. GlossarPair anchor An anchor derived for one enactment (DTG scope pairwise). The enacting anchor of a ceremony is a fresh pair anchor at every enactment. Glossary is pairwise; a Mitgliedsanker Der gruppenspezifische Kontextanker, unter dem ein Mitglied in einer Gruppe handelt (DTG-Geltungsbereich directed). GlossarMember anchor The per-group context anchor under which one member acts in one group (DTG scope directed). Glossary is directed, because every member of the group can correlate it; a persona is public, because its profile is meant for everyone. Personas are specified but not yet built, and whether RLTP also needs personas toward a chosen set is an open question; today that role falls to the member anchor.

Further derivations have no social surface: a service identity per group, a carrier identity per relationship and carrier, and a recovery context for the person’s own encrypted state. Without the seed, two anchors of one person cannot be linked.

Each context has an Ed25519 key pair, whose public key is the anchor as a did:key, and an X25519 key for key agreement, carried in the Kontaktkarte Signierte Selbstbeschreibung einer Person mit dem Material, um sie zu erkennen und zu erreichen, und im Begegnungsvorgang mit einer frischen Challenge; angezeigt (zum Scannen) oder gesendet (im Vorgang übertragen, nennt den Empfänger). Kein Credential. GlossarContact card A person's signed self-description carrying the material needed to recognize and reach them and, in an enactment, a fresh challenge; displayed (shown for scanning) or sent (transmitted inside an enactment, naming its recipient). Not a credential. Glossary. Verification needs no network.

did:key over Ed25519 is the only DID method specified today. Consumers treat an anchor as an opaque DID, but the schemas pin the did:key pattern, so another method would be a coordinated change. A did:key cannot rotate; a successor with verifiable key history is named as open work, its format deliberately not chosen. did:webvh and did:peer are not specified.

The mnemonic restores keys, not state. Which groups, personas and relationships exist is a register in the person’s encrypted, synchronized state; with a copy of it, everything returns. A lost mnemonic is final, unless the person has set up succession: recovering an anchor through several trusted people is specified separately and currently parked.

Specs: Identity Layer · Succession (parked)

RLTP issues three credentials, all W3C Verifiable Credentials 2.0 with closed schemas and three contexts pinned by value (W3C credentials v2, a DTG context, RLTP v1), verified without JSON-LD processing. The Begegnungs-Credential Unveränderliches Credential, in dem eine Partei festhält, dass sie eine andere erkannt hat. Ausgestellt von einer Partei über die andere, offline prüfbar. GlossarEncounter credential The immutable credential in which one party records that they recognized another. Issued by one party about the other, verifiable offline. Glossary is a DTG Relationship Credential under DTG Credentials WD 0.6.0: it lists the DTG registry context v1 and declares issuerScope: "pairwise". The Einladung Signiertes Angebot eines Mitglieds an genau eine Person, der Gruppe beizutreten: ein DTG-Einladungs-Credential, das die Gruppe über ihren Genesis-Digest und die Person über den Mitgliedsanker nennt, den sie für diese Gruppe abgeleitet hat. Es trägt die Karte der einladenden Person, kein Schlüsselmaterial und keine Operation. GlossarInvite A member's signed offer of membership to exactly one person: a DTG invitation credential naming the group by its genesis digest and the person by the member anchor they derived for that group. It carries the inviter's card, no key material and no operation. Glossary and the Bürgschaft Die signierte Aussage eines Mitglieds für genau eine Aufnahme genau einer Person (vouch@2, ein DTG EndorsementCredential), gebunden an deren Annahme; eine Bürgschaftsregel der Gruppe zählt sie für diese eine Aufnahme und keine spätere. Wie der Bürge die Person kennt, begegnet oder vorgestellt, ist sein eigenes Wort, nicht geprüft; ein Begegnungs-Credential ist keine Bürgschaft. GlossarVouch A member's signed statement for exactly one admission of exactly one person (vouch@2, a DTG EndorsementCredential), bound to that person's accept; a group's vouch rule counts it for this one admission and no later one. How the voucher knows the person, met or introduced, is their own word, not verified; an encounter credential is not a vouch. Glossary list the DTG context of Working Draft 01.

Credential Issued when Issuer → subject type Proof Revocation Schema · vector
Encounter credential A person verifies the other during an encounter; one per direction Issuer’s fresh pair anchor → counterpart’s fresh pair anchor VerifiableCredential, DTGCredential, RelationshipCredential, EncounterCredential DataIntegrityProof, eddsa-jcs-2022 Never revoked, never expires: no validUntil, no credentialStatus encounter-credential-0.26 · encounter-cards.json
Membership invite (VIC) A member invites someone into a group Inviter’s member anchor → invitee’s member anchor VerifiableCredential, DTGCredential, InvitationCredential, MembershipInvite DataIntegrityProof, eddsa-jcs-2022 No credentialStatus; validUntil, default 90 days payload-membership-invite · dtg-credentials.json
Admission vouch (vouch@2) A member vouches for a candidate’s admission Vouching member’s anchor → candidate’s member anchor VerifiableCredential, DTGCredential, EndorsementCredential, AdmissionVouch DataIntegrityProof, eddsa-jcs-2022 No credentialStatus, no validUntil; usable only for the one Annahme Die signierte Zustimmung der eingeladenen Person zu genau einer Einladung, an sie gebunden über deren Credential-Digest. Sie trägt die eigene Karte der Person, an deren Schlüsselvereinbarungsschlüssel das Willkommen versiegelt wird, und sagt, ob die Person der Gruppe vor der Aufnahme als Kandidatur gezeigt werden darf. GlossarAccept The invitee's signed consent to exactly one invite, bound to it by the invite's credential digest. It carries the person's own card, to whose key-agreement key the welcome is sealed, and states whether the person may be shown to the group as a candidacy before admission. Glossary it is bound to access-vouch · dtg-credentials.json

The contact card is not a credential. It is a signed self-description: anchor, key agreement key, and in an encounter a fresh Challenge Frischer, einmal verwendbarer Wert hoher Entropie, der in einer Kontaktkarte für einen Begegnungsvorgang reist. Ein Begriff; angezeigte und gesendete Karten unterscheiden sich nur im Lebenszyklus. GlossarChallenge A fresh, single-use, high-entropy value carried in a contact card for one enactment. One concept; displayed and sent cards differ only in lifecycle. Glossary.

An encounter establishes exactly four things: the issuer controlled their key, the exchange was fresh, a human deliberately verified the other, and the fact survives as a record. It does not establish physical presence, personhood, that a name belongs to a legal person, or trust. Freshness and verification are established toward the two participants only.

Status: the credentials follow DTG Credentials WD01. The move to the DTG context v2 is pending, and the vouch is to become a DTG StatementCredential with its own predicate. Both are planned as one wire change.

Specs: Encounter Layer · Membership Tasks · Access Layer

An Kante Die Relation zwischen zwei Ankern, gebildet aus den Begegnungs-Credentials zwischen ihnen; eingehend, ausgehend oder beidseitig. Eine Kante je Ankerpaar. GlossarEdge The relation between two anchors constituted by the encounter credentials between them; incoming, outgoing, or mutual. One edge per anchor pair. Glossary between two anchors consists of the encounter credentials between them, and every view of it is local: outgoing, incoming or mutual. There is one edge per anchor pair, however many encounters. An encounter credential is one person’s statement that they verified the other; in a mutual encounter each holds the other’s statement. On its own it proves only that two keys asserted an encounter, and since anyone can create anchors at no cost, a count of such confirmations proves nothing by itself. Its meaning arises in context: for an evaluator who already knows one of the anchors, from its own encounters or its groups, the confirmation is evidence; for anyone else it is a claim.

Verification is not trust. Trusting a contact means showing them context about yourself: an Anker-Zuordnung Das nur vom Adressaten prüfbare Artefakt (anchor-mapping@3), das den Paaranker des Senders in einer Beziehung mit seinem aktuellen Gemeinschaftsanker verknüpft, für genau einen Adressaten: zwei MACs unter Schlüsseln, die mit diesem Adressaten vereinbart sind, sodass nur er sie prüfen und jeder von beiden sie hätte erzeugen können. Es trägt die Linie der Rotationen des Gemeinschaftsankers, damit der Adressat einer Rotation folgen kann. GlossarAnchor mapping The designated-verifier artifact (anchor-mapping@3) that links the sender's pair anchor in one relationship to the sender's current community anchor, for exactly one addressee: two MACs under keys agreed with that addressee, so only the addressee can verify it and either of the two could have produced it. It carries the lineage of the community anchor's rotations, so the addressee can follow a rotation. Glossary reveals, to this one contact only, that the relationship’s pair anchor and the Gemeinschaftsanker Der Anker der persönlichen Gemeinschaft einer Person in ihrer aktuellen Generation (Identity §5.4), der als selbstgewählte beziehungsübergreifende Koordinate der Person dient; er ist Mitglied keiner Gruppe und erscheint in keinem Artefakt der Zugangsschicht außer innerhalb von anchor.rotate. Den Übergang von einem Mitgliedsanker zu einem Kontakt leistet das Gruppenpaar der Sichtbarkeitsschicht. GlossarCommunity anchor The anchor of a person's personal community at its current generation (Identity §5.4), serving as the person's chosen cross-relationship coordinate; it is a member of no group and appears in no artifact of the Access Layer except inside anchor.rotate. The crossing from a member anchor to a contact is the group pair of the Network Visibility layer. Glossary, your one stable identifier, belong to the same person. Trusting also allows the contact to include you, blinded, in the Stern Das Artefakt (star@1), mit dem ein Sender genau einem Empfänger erlaubt, die Kontaktmenge des Senders auf die eigene zu beziehen: je zustellbarem Kontakt nur die Zahl oder dessen Anker, geblendet unter einem Schlüssel für diese Richtung und Zustellung. Er ist unsigniert und vom Empfänger fälschbar, trägt nie einen rohen Anker Dritter und nichts über die Gruppen des Senders; die reisen im Gruppenstern. GlossarStar The artifact (star@1) by which a sender lets exactly one recipient relate the sender's contact set to the recipient's own: per deliverable contact only the count or the contact's anchor, blinded under a key for this direction and delivery. It is unsigned and recipient-forgeable, never carries a raw third-party anchor, and carries nothing about the sender's groups; those travel in the group star. Glossary they send to their own contacts, a picture of their circle that only people who already know you can read you out of. The mapping is designated-verifier: a MAC under a key the two share, so the contact can check it but could have forged it, and nobody else can.

Meeting the same person again needs no disclosure: a Kontinuitäts-Probe Die geblendete Liste (continuity-probe@1), die eine Seite, möglichst beide, nach einem Begegnungsvorgang sendet: die eigenen Paaranker der zuvor aktiven Beziehungen, aufgefüllt auf ein Vielfaches von 256 und an das frische Paar geschlüsselt. Ein Treffer erkennt eine gemeinsame frühere Beziehung, an die das frische Paar gekettet wird; kein Treffer bedeutet einen neuen Kontakt. Der Regelweg der Kontinuität, bei jedem Vorgang, unabhängig von jeder Offenlegung. GlossarContinuity probe The blinded list (continuity-probe@1) that either party, preferably both, sends after an enactment: its own pair anchors of the relationships active before, padded to a multiple of 256 and keyed to the fresh pair. A match identifies a shared prior relationship, to which the fresh pair is chained; no match means a new contact. The default path of continuity, run on every enactment, independent of any disclosure. Glossary after the encounter detects the re-encounter from the shared history and chains it to the existing relationship.

Every artifact belongs to one audience class. Class P covers statements about oneself meant to be shown, such as contact cards and membership documents, and only these are transferably signed; class V covers anything linking two contexts of one person, and class D covers statements about third parties, both designated-verifier, with class D additionally blinded.

A third party holding both credentials of one encounter can verify both proofs and the shared Vorgangsbindung Der in beiden Schritt-Credentials eines Vorgangs identische Digest, der sie an einen Austauschdeskriptor bindet: Multihash über JCS von Zeremonie und beiden Challenges in aufsteigender Ordnung. GlossarEnactment binding The digest, identical in both step credentials of an enactment, that ties them to one exchange descriptor: the multihash over JCS of the ceremony and both challenges in ascending order. Glossary, and learns exactly this: two anchors consistently assert an encounter. Whether two people met, and who they are, stays with those who know the anchors. Personhood predicates therefore measure confirmations relative to anchors the verifier already knows.

Specs: Encounter Layer · Network Visibility · Personhood Predicates

Every RLTP message is a Trust Task document of a private, versioned type under https://real-life.org/trust-tasks/, with in-band issuer and recipient anchors and no expiresAt. An unknown type is rejected, never silently ignored.

Type Registered in Purpose
encounter-bundle/0.1 Delivery the scanner’s sent card and credential, in one scan
encounter-credential-delivery/0.1 Delivery a credential delivered after the encounter
delivery-ack/0.1 Delivery arrival acknowledgement, never acceptance
registry-declaration/0.1 Delivery a party’s signed operational constants
membership-invite/0.2 Membership the invitation, carrying the VIC
membership-accept/0.2 Membership the invitee’s signed consent
membership-evidence/0.1 Membership relays invite and accept to any member who can admit
access-operation/0.1 Membership the admitting operation and Willkommen Das versiegelte Dokument rltp-welcome/0.1, das einer aufgenommenen Person das Schlüsselmaterial eines Schlüsselzustands bringt, gebunden an Gruppe, Person und die beantwortete Annahme. Die aufnehmende Operation verpflichtet sich über den Digest auf seinen Klartext; Geschichte trägt es nicht. GlossarWelcome The sealed rltp-welcome/0.1 document that carries the key material of one key state to an admitted person, bound to the group, the person and the accept it answers. The admitting operation commits to its plaintext by digest; it carries no history. Glossary, sent to the new member
key-delivery/0.1 Access epoch keys, welcomes, key requests
removal-notice/0.1 Access tells a removed member
star/0.1 Visibility lets a contact relate your contacts to theirs, blinded or as a count
group-star/0.1 Visibility your groups, blinded to every contact; your member anchor sealed to the ones you choose
grade-declaration/0.1 Visibility a contact’s choice between count and blinded
anchor-mapping/0.2 Visibility links a pair anchor to the community anchor for one addressee
continuity-probe/0.1, continuity-mapping/0.1 Visibility detect a re-encounter and chain it to the existing relationship
introduction-request/0.1, introduction-forward/0.1, introduction-reply/0.1, introduction-ack/0.1, introduction-voucher/0.1 Visibility the five steps of introducing two people through a mutual contact

The Delivery Contract and the Membership Tasks declare Trust Tasks framework 0.4 as their target. The current framework is 0.7.0; the lift is pending, and with it the type URIs change form.

Specs: Delivery Contract · Membership Tasks

A group is a shared place: a document that its members hold together, replicated on each of their devices and encrypted end to end, so that only members can read it. Inside it they collaborate and share state with the tools an application brings: a map, a calendar, a task board, whatever the app puts there. The protocol does not care what the data is; it cares who may read and change it.

A group gives itself its own rules. Who may invite, who may admit, who may remove, whether a newcomer needs vouches: the group states these as data, and every member’s device enforces them. There are no admins. A sole founder in charge is only the simplest rule, and it can be changed like any other.

Membership is a fact in the group’s state, and a member’s devices hold the current key. No membership certificate is needed; a credential for showing membership to outsiders is an open item. Being removed, leaving, or losing a device starts a new Epoche Ein nummerierter Abschnitt der Schlüsselwelt der Gruppe; Durchsetzung wirkt als Epochenübergang. Begriff wie in MLS (RFC 9420). GlossarEpoch A numbered period of the group’s key world; enforcement takes effect as epoch transitions. Term aligned with MLS (RFC 9420). Glossary, so what is written afterwards stays unreadable to whoever lost access. What they already read, they keep.

Behind this stands the authority log: a causally linked graph of individually signed Operation Ein signierter, kausal verankerter Umschlag. GlossarOperation A signed, causally anchored envelope. Glossary, starting from a founding operation whose digest is the group’s identity. The group’s state is a deterministic reading of that log. Changes made at the same time are merged: two removals both take effect, even when two members remove each other. Only a change of the rules made at the same time as a removal stops the group, visibly, until a member writes a rule change that builds on both.

Joining takes five steps. The invitee’s app derives its anchor for the group and hands it to the inviter. The inviter sends an invitation naming that anchor, with no keys in it. The invitee signs an acceptance bound to the invitation. A member who may admit writes the admission into the log, enclosing invitation and acceptance as proof of consent. A welcome sealed to the newcomer carries the current keys. If the group requires vouches, written vouch(n), the newcomer needs n members who vouch for this one admission; a vouch never stands for a later one.

Specs: Access Layer · Membership Tasks

RLTP names no transport and no data store. It states two contracts, delivery and replication, and any substrate that keeps a contract can carry the protocol: a relay, a mesh, a cloud store, a messaging mediator, each behind an adapter. Everything that crosses a substrate is sealed, so an operator sees delivery metadata and never content.

Delivery moves one document to one addressee and is done on arrival: a credential, an invitation, an acknowledgement. Replication keeps a group’s document identical on every member’s device for the group’s lifetime. A letter and a shared table, each with its own contract.

Delivery. Eventually, at least once, never silently lost: delivery time is unbounded, duplicates and lost receipts are the normal case, every effect is idempotent. The envelope is sealed end to end; a carrier holds queues and reads nothing. The sender sees accepted, delivered or failed, never a success that was not one. An acknowledgement means arrival only. Whether the recipient agrees is said by a document they issue themselves: the counter-credential in an encounter, the signed acceptance of an invitation. Each relationship registers under its own principal, so a relay holding six of your relationships holds six strangers.

Replication. Every entry is individually signed and causally linked, so a replica judges it on its own, by whatever road it came: sync, import, recovery. Convergence is promised, readability never; the port checks signatures and causality and never touches content keys. Evidence always flows, effect is gated: a forked group learns it on every device. The contract condenses this into five doors and maps p2panda, Keyhive, SECSYNC, NextGraph and Automerge against them.

Today. One delivery adapter is specified, for the Verifiable Trust Infrastructure mediator over TSP, being moved to TSP revision 3. DIDComm appears only as that mediator’s mediation and pickup protocols, not as a form for RLTP documents. No replication adapter is specified.

Specs: Delivery Contract · Replication Contract · VTI mediator adapter

  • Groups are protocol objects. Membership is a fact in replicated group state and the holding of a key, not a certificate in a wallet.
  • Rooms and invitations, not checkpoints. The host consults their own graph and invites; nobody presents a credential at a door.
  • There are no admins. Privilegierte Operation Eine Operation des geschlossenen Katalogs, jede mit Klasse (additiv, Durchsetzung, terminal), Epochenwirkung und geschlossenem Body-Profil. GlossarPrivileged operation An operation of the closed catalog, each with its class (additive, enforcement, terminal), epoch effect and closed body profile. Glossary are gated by a rule the group states as data.
  • Revocation is an epoch. A removal carries its key transition atomically; nothing waits for an expiry date.
  • Relationships never converge into a person. Every relationship has its own anchor and, toward every carrier, its own principal.

More: README of the specification repository

The Encounter primer explains the first layer in detail. The specifications follow in reading order.