Skip to content
DID.is
Identity dossierdid:webretrieved over HTTPS

did:web:identity.foundation

Checks
3 confirmed · 1 need attention · 3 not confirmed
Method
did:web
Observed
2026-10-11 00:01Z
W3C documentEvidence JSON
§1

Verdict

Each dimension is evaluated independently. Nothing is averaged.

Verdict

resolvedobserved 2026-10-11 00:01Z

Controlled by the operator of identity.foundation; publishes P-256 verification keys.

  • Origin linkage could not be evaluated.
  • No verifiable history.
  • Organization not established.

Confirmed · 3

  • The document is intact and really belongs to this identifier
  • It publishes keys that can be used to check signatures
  • It was fetched over a valid, secure connection

Needs attention · 1

  • No two-way link to a website was confirmed

Not confirmed · 3

  • Whoever runs the hosting can change it — no key is needed
  • Past versions cannot be proven
  • Who is behind it in the real world is not confirmed
Evidence for each check
DimensionStateEvidence
Document integrityestablished

Why

Retrieved from identity.foundation and its id equals the DID (SHA-256 ed807e81aac6…).

Proves
This is the document the origin served at resolution time.
Does not prove
That the document was not different before or will not change; did:web keeps no verifiable history.
Reproduce with the APIcurl -s "https://did.is/api/v1/resolve/did%3Aweb%3Aidentity.foundation" | jq '.dimensions[] | select(.id == "integrity")'
Key materialestablished

Why

1 verification method validated (P-256).

Proves
The published keys are well-formed points usable for their declared relationships.
Does not prove
Who holds the corresponding private keys.
Reproduce with the APIcurl -s "https://did.is/api/v1/resolve/did%3Aweb%3Aidentity.foundation" | jq '.dimensions[] | select(.id == "keys")'
Update authoritynot established

Why not

Whoever controls the web server and DNS for identity.foundation can replace this document.

Proves
Nothing cryptographic: did:web has no signed update mechanism.
Does not prove
That the current keys were authorised by the previous ones.
Reproduce with the APIcurl -s "https://did.is/api/v1/resolve/did%3Aweb%3Aidentity.foundation" | jq '.dimensions[] | select(.id == "control")'
Origin bindingindeterminate

Why not

Linkage proof format not supported: legacy Linked Data proof type 'JsonWebSignature2020' requires JSON-LD/RDF canonicalization, which DID.is does not implement

Proves
The DID's key signed a statement linking it to this exact origin (bidirectional binding).
Does not prove
Who operates the origin.
Reproduce with the APIcurl -s "https://did.is/api/v1/resolve/did%3Aweb%3Aidentity.foundation" | jq '.dimensions[] | select(.id == "origin")'
Transport securityestablished

Why

TLS certificate for identity.foundation issued by Google Trust Services, valid until 2026-12-27 (77 days).

Proves
The document came from a server holding a publicly-trusted certificate for the host.
Does not prove
That the server operator is the DID subject.
Reproduce with the APIcurl -s "https://did.is/api/v1/resolve/did%3Aweb%3Aidentity.foundation" | jq '.dimensions[] | select(.id == "transport")'
Verifiable historynot established

Why not

did:web keeps no verifiable history; DID.is snapshots are observations, not proofs.

Does not prove
What the document contained before this resolution.
Reproduce with the APIcurl -s "https://did.is/api/v1/resolve/did%3Aweb%3Aidentity.foundation" | jq '.dimensions[] | select(.id == "history")'
Real-world identitynot established

Why not

Organization not established. DID.is does not verify legal identity or ownership claims.

Does not prove
Who operates this identifier.
Reproduce with the APIcurl -s "https://did.is/api/v1/resolve/did%3Aweb%3Aidentity.foundation" | jq '.dimensions[] | select(.id == "organization")'
Reproduce this verdict
curl -s "https://did.is/api/v1/resolve/did%3Aweb%3Aidentity.foundation" | jq '{verdict, dimensions: [.dimensions[] | {id, state, statement}]}'

# The nodes and edges behind it
curl -s "https://did.is/api/v1/graph/did%3Aweb%3Aidentity.foundation"

The same request returns the same evidence. The verdict is never computed in this page; it comes from the API.

Limits of this verdict
  • DID.is reports evidence; it does not assign trust scores or verify legal identity.
  • did:web is as trustworthy as the origin's DNS, hosting and TLS; there is no verifiable history.
  • TLS evidence describes the certificate presented to DID.is at resolution time.
  • Linked Data proofs that require RDF canonicalization (e.g. Ed25519Signature2020) are reported as unsupported, not valid.

Technical evidence

For developers and auditors. The summary above already reflects everything below.

§2

Evidence graph

Select any plaque to open its forensic detail.

Evidence graph

SUBJECTdid:web:identity.foundationdid:webTLSTLS · Google Trust Servicesexpires in 77 daysORIGINidentity.foundationHTTPS originDOCUMENTDID documentJCS SHA-256 31af489e8f38…KEY#XXS7zTsbIIAxgNlYEX…P-256 · JsonWebKey2020SERVICELinkedVerifiablePresentationhttps://identity.foundation/.well…SERVICELinkedDomains["https://identity.foundation"]LINKAGEDID configurationunsupported proof
verifiedobserveddeclaredfailedDrag to pan · Ctrl/⌘ + scroll to zoom · Enter opens a node

Evidence graph as text

  • did:web:identity.foundation — resolves to (verified) → DID document
  • did:web:identity.foundation — located at (observed) → identity.foundation
  • TLS · Google Trust Services — authenticates (verified) → identity.foundation
  • identity.foundation — serves (observed) → DID document
  • DID document — authentication · assertionMethod (declared) → #XXS7zTsbIIAxgNlYEX…
  • DID document — service (declared) → LinkedVerifiablePresentation
  • DID document — service (declared) → LinkedDomains
  • identity.foundation — publishes (observed) → DID configuration
  • #XXS7zTsbIIAxgNlYEX… — signed (declared) → DID configuration
§3

Telemetry

Each stage of the resolution with monotonic timings, as recorded by the resolver.

Telemetry

  1. DID syntax (DID Core §3.1)
    syntax.parse
    0.00 ms

    method 'web' · 27 characters

  2. DID-to-HTTPS transformation
    method.web.transform
    0.03 ms

    did:web:identity.foundation → https://identity.foundation/.well-known/did.json

  3. DNS resolution and address pinning
    egress.dns
    28.6 ms

    identity.foundation pinned to 172.67.140.164 (all answers public)

  4. TLS handshake and HTTP exchange
    egress.fetch
    108 ms

    GET https://identity.foundation/.well-known/did.json → HTTP 200 · 1367 bytes; leaf certificate identity.foundation issued by Google Trust Services

  5. JSON parsing and identity check
    document.parse
    0.02 ms

    1367 bytes parsed; document id equals the requested DID; SHA-256 ed807e81aac6a391

  6. DNS resolution and address pinning
    egress.dns
    0.87 ms

    identity.foundation pinned to 104.21.70.240 (all answers public)

  7. TLS handshake and HTTP exchange
    egress.fetch
    61.8 ms

    GET https://identity.foundation/.well-known/did-configuration.json → HTTP 200 · 1135 bytes; leaf certificate identity.foundation issued by Google Trust Services

  8. Domain linkage credential verification (DIF)
    linkage.verify
    0.04 ms

    legacy Linked Data proof type 'JsonWebSignature2020' requires JSON-LD/RDF canonicalization, which DID.is does not implement

  9. Evidence assembly
    evidence.assemble
    0.18 ms

    7 dimensions · 8 graph nodes · verdict RESOLVED

§4

Substrate

The raw material behind every statement above.

Substrate

application/did
{
"@context": [
"https://www.w3.org/ns/did/v1"
"https://w3id.org/security/suites/jws-2020/v1"
"https://identity.foundation/.well-known/did-configuration/v1"
"https://identity.foundation/linked-vp/contexts/v1"
]
"assertionMethod": [
"did:web:identity.foundation#XXS7zTsbIIAxgNlYEXJ4y810GFeLkYdqfK3ChhoQn7c"
]
"authentication": [
"did:web:identity.foundation#XXS7zTsbIIAxgNlYEXJ4y810GFeLkYdqfK3ChhoQn7c"
]
"id": "did:web:identity.foundation"
"service": [
{}
{}
]
"verificationMethod": [
{}
]
}
@context
  • https://www.w3.org/ns/did/v1DID Core v1.0
  • https://w3id.org/security/suites/jws-2020/v1JWS 2020 suite
  • https://identity.foundation/.well-known/did-configuration/v1DIF Well Known DID Configuration
  • https://identity.foundation/linked-vp/contexts/v1DIF Linked VP
Structural warnings

None.

JCS SHA-256
31af489e8f3844fc1b21aea9…
id equals DID
yes
§5

Time machine

Observed snapshots and semantic differences between them.

Time machine

Loading observations…

Put it to work

  1. A

    Monitor changes

    Get a signed webhook and a 30-day event history when keys, services or the document change. Checked hourly.

    Watch this identifier →
  2. B

    Resolve from your app

    Create a project and an API key. Private resolutions are metered, idempotent and never written to public history.

    Create an API key →
  3. C

    Read the API

    The same request this page made, as a standard W3C resolution or the DID.is evidence response.

    Open the API reference →