Portable, offline-verifiable identity for AI agents: DID, challenges, attestations, bundles.
Portable, offline-verifiable identity for AI agents. An agent's DID is the hash of a genesis
document holding an Ed25519 key; worlds sign attestations about it; anyone verifies the bundle
offline — no server, registry or chain. Draft v0.1, wire format sigelo/0; nothing is stable before v1.0.
Site: sigelo.io (llms.txt). MCP server: sigelo-mcp
(io.github.csigelo/sigelo). Why an agent would use it: WHY.md.
Built and operated by an AI agent (Claude, did:sigelo:zDRrj7eGWXQtmzPUKF3zPDjhUkH7FebKRGj8rf96SdoLa) under a human owner, csigelo. No third party has audited it yet.
QUICKSTART.md (seven steps), or plug in through
integrations/ (MCP server, Claude Code plugin, configs for other harnesses).accept/ — challenge(did, ctx) and
accept(challenge, answer, bundle) for node, Python and Go; sh accept/test.sh runs them.
Live example: world/.SPEC.md and test-vectors.json;
check yours with sigelo-verify --conformance test-vectors.json --impl <your command> (go/).Requirements: Node ≥ 22.18, Go ≥ 1.27; optional age (root ceremony) and monero-wallet-rpc
(keeper). Linux, macOS, Windows on x86_64 and arm64 (docs-test/PORTABILITY.md);
on Windows file modes such as 0600 are ignored, so keep secret files under your own profile.
In CI order (.github/workflows/conformance.yml); each line ends in ALL PASS.
(cd ts && npm ci && npx tsc) # TypeScript library → ts/dist
(cd ts && node dist/gen_vectors.js | diff -u ../test-vectors.json -) # vectors reproduce: no output
(cd ts && node dist/test.js)
(cd adapters/moadim && npm ci && npm test)
(cd spend && npm ci && npm test) # needs ts/dist
(cd integrations/mcp && npm test)
(cd go && gofmt -l . && go vet ./... && go test ./... -v)
(cd go && CGO_ENABLED=0 go build ./cmd/sigelo-verify && ./sigelo-verify --conformance ../test-vectors.json)
node schema/check.mjs
release/build.sh /tmp/rel && release/pack-test.sh /tmp/rel # 5 npm tarballs, sigelo-verify ×5, SHA256SUMS
Without age the ceremony's real-age check SKIPs; without monero-wallet-rpc on 127.0.0.1:38083
the live-wallet sections SKIP.
claims is world-defined and
untrusted (never instructions to an LLM); admission says what entry cost (open, invite, payment, stake).MONERO.md).Threats in scope and out: THREAT-MODEL.md.
| Path | What |
|---|---|
ts/ | TypeScript library: keygen, attest, bind, rotate, verify; Monero primitives, root-seed derivation, sigelo-offline |
go/ | reference verifier, one dependency, static sigelo-verify |
spend/ | the keeper: agents pay through sigelo-wallet without holding a Monero key |
adapters/1f916/ | world side for 1f916.ai, 99 lines |
adapters/moadim/ | agent side for moadim, 77 lines (Monero half separate) |
adapters/hermes/ | Hermes Agent: 9 lines of config.yaml |
kit/ | recovery kit: ceremony, printed procedures, drills |
site/ | sigelo.io, generated from these documents |
A world integration over 100 lines or one dependency is a design bug: file an issue.
MIT.
Source-derived launch command. Check the maintainer’s required arguments and credentials before running:
npx -y sigelo-mcpMerge this template into ~/Library/Application Support/Claude/claude_desktop_config.json. Keep existing servers. Add any arguments, credentials, and permissions required by the maintainer; this template has not been install-tested.
{
"mcpServers": {
"io-github-csigelo-sigelo": {
"command": "npx",
"args": [
"-y",
"sigelo-mcp"
]
}
}
}Restart Claude Desktop completely for changes to take effect. Confirm the server appears connected in the client’s tool list, then try a read-only example from its documentation.
Claude Desktop setup referencesigelo works with any MCP-compatible client. Copy the config snippet from the Configuration section above and add it to the file shown for your client, then restart the application.
~/Library/Application Support/Claude/claude_desktop_config.jsonRestart Claude Desktop completely for changes to take effect.~/.cursor/mcp.jsonRestart Cursor for changes to take effect..vscode/mcp.jsonReload VS Code window for changes to take effect.~/.codeium/windsurf/mcp_config.jsonRestart Windsurf for changes to take effect..mcp.jsonSave at the project root, then start Claude Code in that project and review the MCP server approval prompt. Keep real credentials out of shared files.