Skip to content
DID.is
Identity dossierdid:webretrieved over HTTPS

did:web:did.is

Checks
4 confirmed · 3 not confirmed
Method
did:web
Observed
2026-10-11 00:44Z
W3C documentEvidence JSON
§1

Verdict

Each dimension is evaluated independently. Nothing is averaged.

Verdict

resolvedobserved 2026-10-11 00:44Z

Controlled by the operator of did.is; publishes Ed25519 verification keys.

  • Origin verified via DIF configuration.
  • No verifiable history.
  • Organization not established.

Confirmed · 4

  • The document is intact and really belongs to this identifier
  • It publishes keys that can be used to check signatures
  • It is linked to its website in both directions
  • It was fetched over a valid, secure connection

Not confirmed · 3

  • Whoever runs the hosting can change it — no key is needed
  • Past versions cannot be proven
  • Who is behind it in the real world is not confirmed
Evidence for each check
DimensionStateEvidence
Document integrityestablished

Why

Retrieved from did.is and its id equals the DID (SHA-256 08a92bc6643f…).

Proves
This is the document the origin served at resolution time.
Does not prove
That the document was not different before or will not change; did:web keeps no verifiable history.
Reproduce with the APIcurl -s "https://did.is/api/v1/resolve/did%3Aweb%3Adid.is" | jq '.dimensions[] | select(.id == "integrity")'
Key materialestablished

Why

1 verification method validated (Ed25519).

Proves
The published keys are well-formed points usable for their declared relationships.
Does not prove
Who holds the corresponding private keys.
Reproduce with the APIcurl -s "https://did.is/api/v1/resolve/did%3Aweb%3Adid.is" | jq '.dimensions[] | select(.id == "keys")'
Update authoritynot established

Why not

Whoever controls the web server and DNS for did.is can replace this document.

Proves
Nothing cryptographic: did:web has no signed update mechanism.
Does not prove
That the current keys were authorised by the previous ones.
Reproduce with the APIcurl -s "https://did.is/api/v1/resolve/did%3Aweb%3Adid.is" | jq '.dimensions[] | select(.id == "control")'
Origin bindingestablished

Why

Origin https://did.is verified via DIF Well-Known DID Configuration.

Proves
The DID's key signed a statement linking it to this exact origin (bidirectional binding).
Does not prove
Who operates the origin.
Reproduce with the APIcurl -s "https://did.is/api/v1/resolve/did%3Aweb%3Adid.is" | jq '.dimensions[] | select(.id == "origin")'
Transport securityestablished

Why

TLS certificate for did.is issued by Let's Encrypt, valid until 2027-01-01 (82 days).

Proves
The document came from a server holding a publicly-trusted certificate for the host.
Does not prove
That the server operator is the DID subject.
Reproduce with the APIcurl -s "https://did.is/api/v1/resolve/did%3Aweb%3Adid.is" | jq '.dimensions[] | select(.id == "transport")'
Verifiable historynot established

Why not

did:web keeps no verifiable history; DID.is snapshots are observations, not proofs.

Does not prove
What the document contained before this resolution.
Reproduce with the APIcurl -s "https://did.is/api/v1/resolve/did%3Aweb%3Adid.is" | jq '.dimensions[] | select(.id == "history")'
Real-world identitynot established

Why not

Organization not established. DID.is does not verify legal identity or ownership claims.

Does not prove
Who operates this identifier.
Reproduce with the APIcurl -s "https://did.is/api/v1/resolve/did%3Aweb%3Adid.is" | jq '.dimensions[] | select(.id == "organization")'
Reproduce this verdict
curl -s "https://did.is/api/v1/resolve/did%3Aweb%3Adid.is" | jq '{verdict, dimensions: [.dimensions[] | {id, state, statement}]}'

# The nodes and edges behind it
curl -s "https://did.is/api/v1/graph/did%3Aweb%3Adid.is"

The same request returns the same evidence. The verdict is never computed in this page; it comes from the API.

Limits of this verdict
  • DID.is reports evidence; it does not assign trust scores or verify legal identity.
  • did:web is as trustworthy as the origin's DNS, hosting and TLS; there is no verifiable history.
  • TLS evidence describes the certificate presented to DID.is at resolution time.
  • Linked Data proofs that require RDF canonicalization (e.g. Ed25519Signature2020) are reported as unsupported, not valid.

Technical evidence

For developers and auditors. The summary above already reflects everything below.

§2

Evidence graph

Select any plaque to open its forensic detail.

Evidence graph

SUBJECTdid:web:did.isdid:webTLSTLS · Let's Encryptexpires in 82 daysORIGINdid.isHTTPS originDOCUMENTDID documentJCS SHA-256 cdaa6d003a72…KEY#key-1Ed25519 · JsonWebKey2020SERVICELinkedDomainshttps://did.is/LINKAGEDID configurationverified
verifiedobserveddeclaredfailedDrag to pan · Ctrl/⌘ + scroll to zoom · Enter opens a node

Evidence graph as text

  • did:web:did.is — resolves to (verified) → DID document
  • did:web:did.is — located at (observed) → did.is
  • TLS · Let's Encrypt — authenticates (verified) → did.is
  • did.is — serves (observed) → DID document
  • DID document — authentication · assertionMethod (declared) → #key-1
  • DID document — service (declared) → LinkedDomains
  • did.is — publishes (observed) → DID configuration
  • #key-1 — signed (verified) → DID configuration
  • DID configuration — links origin to DID (verified) → did:web:did.is
§3

Telemetry

Each stage of the resolution with monotonic timings, as recorded by the resolver.

Telemetry

  1. DID syntax (DID Core §3.1)
    syntax.parse
    0.00 ms

    method 'web' · 14 characters

  2. DID-to-HTTPS transformation
    method.web.transform
    0.01 ms

    did:web:did.is → https://did.is/.well-known/did.json

  3. DNS resolution and address pinning
    egress.dns
    0.85 ms

    did.is pinned to 172.67.199.233 (all answers public)

  4. TLS handshake and HTTP exchange
    egress.fetch
    42.9 ms

    GET https://did.is/.well-known/did.json → HTTP 200 · 678 bytes; leaf certificate did.is issued by Let's Encrypt

  5. JSON parsing and identity check
    document.parse
    0.02 ms

    678 bytes parsed; document id equals the requested DID; SHA-256 08a92bc6643f8d56

  6. DNS resolution and address pinning
    egress.dns
    0.68 ms

    did.is pinned to 172.67.199.233 (all answers public)

  7. TLS handshake and HTTP exchange
    egress.fetch
    43.2 ms

    GET https://did.is/.well-known/did-configuration.json → HTTP 200 · 858 bytes; leaf certificate did.is issued by Let's Encrypt

  8. Domain linkage credential verification (DIF)
    linkage.verify
    0.21 ms

    JWS EdDSA signature verified with Ed25519 key did:web:did.is#key-1

  9. Evidence assembly
    evidence.assemble
    0.10 ms

    7 dimensions · 7 graph nodes · verdict RESOLVED

§4

Substrate

The raw material behind every statement above.

Substrate

application/did
{
"@context": [
"https://www.w3.org/ns/did/v1"
"https://w3id.org/security/suites/jws-2020/v1"
]
"assertionMethod": [
"did:web:did.is#key-1"
]
"authentication": [
"did:web:did.is#key-1"
]
"id": "did:web:did.is"
"service": [
{}
]
"verificationMethod": [
{}
]
}
@context
  • https://www.w3.org/ns/did/v1DID Core v1.0
  • https://w3id.org/security/suites/jws-2020/v1JWS 2020 suite
Structural warnings

None.

JCS SHA-256
cdaa6d003a72986c9881c8f5…
id equals DID
yes
§5

Time machine

Observed snapshots and semantic differences between them.

Time machine

Loading observations…

Put it to work

  1. A

    Monitor changes

    Get a signed webhook and a 30-day event history when keys, services or the document change. Checked hourly.

    Watch this identifier →
  2. B

    Resolve from your app

    Create a project and an API key. Private resolutions are metered, idempotent and never written to public history.

    Create an API key →
  3. C

    Read the API

    The same request this page made, as a standard W3C resolution or the DID.is evidence response.

    Open the API reference →