did:web:did.is
- Checks
- 4 confirmed · 3 not confirmed
- Method
- did:web
- Observed
- 2026-10-11 00:44Z
Verdict
Each dimension is evaluated independently. Nothing is averaged.
Verdict
Controlled by the operator of did.is; publishes Ed25519 verification keys.
- Origin verified via DIF configuration.
- No verifiable history.
- Organization not established.
Confirmed · 4
- The document is intact and really belongs to this identifier
- It publishes keys that can be used to check signatures
- It is linked to its website in both directions
- It was fetched over a valid, secure connection
Not confirmed · 3
- Whoever runs the hosting can change it — no key is needed
- Past versions cannot be proven
- Who is behind it in the real world is not confirmed
| Dimension | State | Evidence |
|---|---|---|
| Document integrity | established | Why Retrieved from did.is and its id equals the DID (SHA-256 08a92bc6643f…).
Reproduce with the APIcurl -s "https://did.is/api/v1/resolve/did%3Aweb%3Adid.is" | jq '.dimensions[] | select(.id == "integrity")' |
| Key material | established | Why 1 verification method validated (Ed25519).
Reproduce with the APIcurl -s "https://did.is/api/v1/resolve/did%3Aweb%3Adid.is" | jq '.dimensions[] | select(.id == "keys")' |
| Update authority | not established | Why not Whoever controls the web server and DNS for did.is can replace this document.
Reproduce with the APIcurl -s "https://did.is/api/v1/resolve/did%3Aweb%3Adid.is" | jq '.dimensions[] | select(.id == "control")' |
| Origin binding | established | Why Origin https://did.is verified via DIF Well-Known DID Configuration.
Reproduce with the APIcurl -s "https://did.is/api/v1/resolve/did%3Aweb%3Adid.is" | jq '.dimensions[] | select(.id == "origin")' |
| Transport security | established | Why TLS certificate for did.is issued by Let's Encrypt, valid until 2027-01-01 (82 days).
Reproduce with the APIcurl -s "https://did.is/api/v1/resolve/did%3Aweb%3Adid.is" | jq '.dimensions[] | select(.id == "transport")' |
| Verifiable history | not established | Why not did:web keeps no verifiable history; DID.is snapshots are observations, not proofs.
Reproduce with the APIcurl -s "https://did.is/api/v1/resolve/did%3Aweb%3Adid.is" | jq '.dimensions[] | select(.id == "history")' |
| Real-world identity | not established | Why not Organization not established. DID.is does not verify legal identity or ownership claims.
Reproduce with the APIcurl -s "https://did.is/api/v1/resolve/did%3Aweb%3Adid.is" | jq '.dimensions[] | select(.id == "organization")' |
curl -s "https://did.is/api/v1/resolve/did%3Aweb%3Adid.is" | jq '{verdict, dimensions: [.dimensions[] | {id, state, statement}]}'
# The nodes and edges behind it
curl -s "https://did.is/api/v1/graph/did%3Aweb%3Adid.is"The same request returns the same evidence. The verdict is never computed in this page; it comes from the API.
- DID.is reports evidence; it does not assign trust scores or verify legal identity.
- did:web is as trustworthy as the origin's DNS, hosting and TLS; there is no verifiable history.
- TLS evidence describes the certificate presented to DID.is at resolution time.
- Linked Data proofs that require RDF canonicalization (e.g. Ed25519Signature2020) are reported as unsupported, not valid.
Technical evidence
For developers and auditors. The summary above already reflects everything below.
Evidence graph
Select any plaque to open its forensic detail.
Evidence graph
Evidence graph as text
- did:web:did.is — resolves to (verified) → DID document
- did:web:did.is — located at (observed) → did.is
- TLS · Let's Encrypt — authenticates (verified) → did.is
- did.is — serves (observed) → DID document
- DID document — authentication · assertionMethod (declared) → #key-1
- DID document — service (declared) → LinkedDomains
- did.is — publishes (observed) → DID configuration
- #key-1 — signed (verified) → DID configuration
- DID configuration — links origin to DID (verified) → did:web:did.is
Telemetry
Each stage of the resolution with monotonic timings, as recorded by the resolver.
Telemetry
- DID syntax (DID Core §3.1)syntax.parse0.00 ms
method 'web' · 14 characters
- DID-to-HTTPS transformationmethod.web.transform0.01 ms
did:web:did.is → https://did.is/.well-known/did.json
- DNS resolution and address pinningegress.dns0.85 ms
did.is pinned to 172.67.199.233 (all answers public)
- TLS handshake and HTTP exchangeegress.fetch42.9 ms
GET https://did.is/.well-known/did.json → HTTP 200 · 678 bytes; leaf certificate did.is issued by Let's Encrypt
- JSON parsing and identity checkdocument.parse0.02 ms
678 bytes parsed; document id equals the requested DID; SHA-256 08a92bc6643f8d56
- DNS resolution and address pinningegress.dns0.68 ms
did.is pinned to 172.67.199.233 (all answers public)
- TLS handshake and HTTP exchangeegress.fetch43.2 ms
GET https://did.is/.well-known/did-configuration.json → HTTP 200 · 858 bytes; leaf certificate did.is issued by Let's Encrypt
- Domain linkage credential verification (DIF)linkage.verify0.21 ms
JWS EdDSA signature verified with Ed25519 key did:web:did.is#key-1
- Evidence assemblyevidence.assemble0.10 ms
7 dimensions · 7 graph nodes · verdict RESOLVED
Substrate
The raw material behind every statement above.
Substrate
- https://www.w3.org/ns/did/v1DID Core v1.0
- https://w3id.org/security/suites/jws-2020/v1JWS 2020 suite
None.
- JCS SHA-256
- cdaa6d003a72986c9881c8f5…
- id equals DID
- yes
Time machine
Observed snapshots and semantic differences between them.
Time machine
Loading observations…
Put it to work
Monitoring and private API access are paid; evidence on this page is never paywalled.
Put it to work
- A
Monitor changes
Get a signed webhook and a 30-day event history when keys, services or the document change. Checked hourly.
Watch this identifier → - B
Resolve from your app
Create a project and an API key. Private resolutions are metered, idempotent and never written to public history.
Create an API key → - C
Read the API
The same request this page made, as a standard W3C resolution or the DID.is evidence response.
Open the API reference →