did:web:identity.foundation
- Checks
- 3 confirmed · 1 need attention · 3 not confirmed
- Method
- did:web
- Observed
- 2026-10-11 00:01Z
Verdict
Each dimension is evaluated independently. Nothing is averaged.
Verdict
Controlled by the operator of identity.foundation; publishes P-256 verification keys.
- Origin linkage could not be evaluated.
- No verifiable history.
- Organization not established.
Confirmed · 3
- The document is intact and really belongs to this identifier
- It publishes keys that can be used to check signatures
- It was fetched over a valid, secure connection
Needs attention · 1
- No two-way link to a website was confirmed
Not confirmed · 3
- Whoever runs the hosting can change it — no key is needed
- Past versions cannot be proven
- Who is behind it in the real world is not confirmed
| Dimension | State | Evidence |
|---|---|---|
| Document integrity | established | Why Retrieved from identity.foundation and its id equals the DID (SHA-256 ed807e81aac6…).
Reproduce with the APIcurl -s "https://did.is/api/v1/resolve/did%3Aweb%3Aidentity.foundation" | jq '.dimensions[] | select(.id == "integrity")' |
| Key material | established | Why 1 verification method validated (P-256).
Reproduce with the APIcurl -s "https://did.is/api/v1/resolve/did%3Aweb%3Aidentity.foundation" | jq '.dimensions[] | select(.id == "keys")' |
| Update authority | not established | Why not Whoever controls the web server and DNS for identity.foundation can replace this document.
Reproduce with the APIcurl -s "https://did.is/api/v1/resolve/did%3Aweb%3Aidentity.foundation" | jq '.dimensions[] | select(.id == "control")' |
| Origin binding | indeterminate | Why not Linkage proof format not supported: legacy Linked Data proof type 'JsonWebSignature2020' requires JSON-LD/RDF canonicalization, which DID.is does not implement
Reproduce with the APIcurl -s "https://did.is/api/v1/resolve/did%3Aweb%3Aidentity.foundation" | jq '.dimensions[] | select(.id == "origin")' |
| Transport security | established | Why TLS certificate for identity.foundation issued by Google Trust Services, valid until 2026-12-27 (77 days).
Reproduce with the APIcurl -s "https://did.is/api/v1/resolve/did%3Aweb%3Aidentity.foundation" | jq '.dimensions[] | select(.id == "transport")' |
| Verifiable history | not established | Why not did:web keeps no verifiable history; DID.is snapshots are observations, not proofs.
Reproduce with the APIcurl -s "https://did.is/api/v1/resolve/did%3Aweb%3Aidentity.foundation" | jq '.dimensions[] | select(.id == "history")' |
| Real-world identity | not established | Why not Organization not established. DID.is does not verify legal identity or ownership claims.
Reproduce with the APIcurl -s "https://did.is/api/v1/resolve/did%3Aweb%3Aidentity.foundation" | jq '.dimensions[] | select(.id == "organization")' |
curl -s "https://did.is/api/v1/resolve/did%3Aweb%3Aidentity.foundation" | jq '{verdict, dimensions: [.dimensions[] | {id, state, statement}]}'
# The nodes and edges behind it
curl -s "https://did.is/api/v1/graph/did%3Aweb%3Aidentity.foundation"The same request returns the same evidence. The verdict is never computed in this page; it comes from the API.
- DID.is reports evidence; it does not assign trust scores or verify legal identity.
- did:web is as trustworthy as the origin's DNS, hosting and TLS; there is no verifiable history.
- TLS evidence describes the certificate presented to DID.is at resolution time.
- Linked Data proofs that require RDF canonicalization (e.g. Ed25519Signature2020) are reported as unsupported, not valid.
Technical evidence
For developers and auditors. The summary above already reflects everything below.
Evidence graph
Select any plaque to open its forensic detail.
Evidence graph
Evidence graph as text
- did:web:identity.foundation — resolves to (verified) → DID document
- did:web:identity.foundation — located at (observed) → identity.foundation
- TLS · Google Trust Services — authenticates (verified) → identity.foundation
- identity.foundation — serves (observed) → DID document
- DID document — authentication · assertionMethod (declared) → #XXS7zTsbIIAxgNlYEX…
- DID document — service (declared) → LinkedVerifiablePresentation
- DID document — service (declared) → LinkedDomains
- identity.foundation — publishes (observed) → DID configuration
- #XXS7zTsbIIAxgNlYEX… — signed (declared) → DID configuration
Telemetry
Each stage of the resolution with monotonic timings, as recorded by the resolver.
Telemetry
- DID syntax (DID Core §3.1)syntax.parse0.00 ms
method 'web' · 27 characters
- DID-to-HTTPS transformationmethod.web.transform0.03 ms
did:web:identity.foundation → https://identity.foundation/.well-known/did.json
- DNS resolution and address pinningegress.dns28.6 ms
identity.foundation pinned to 172.67.140.164 (all answers public)
- TLS handshake and HTTP exchangeegress.fetch108 ms
GET https://identity.foundation/.well-known/did.json → HTTP 200 · 1367 bytes; leaf certificate identity.foundation issued by Google Trust Services
- JSON parsing and identity checkdocument.parse0.02 ms
1367 bytes parsed; document id equals the requested DID; SHA-256 ed807e81aac6a391
- DNS resolution and address pinningegress.dns0.87 ms
identity.foundation pinned to 104.21.70.240 (all answers public)
- TLS handshake and HTTP exchangeegress.fetch61.8 ms
GET https://identity.foundation/.well-known/did-configuration.json → HTTP 200 · 1135 bytes; leaf certificate identity.foundation issued by Google Trust Services
- Domain linkage credential verification (DIF)linkage.verify0.04 ms
legacy Linked Data proof type 'JsonWebSignature2020' requires JSON-LD/RDF canonicalization, which DID.is does not implement
- Evidence assemblyevidence.assemble0.18 ms
7 dimensions · 8 graph nodes · verdict RESOLVED
Substrate
The raw material behind every statement above.
Substrate
- https://www.w3.org/ns/did/v1DID Core v1.0
- https://w3id.org/security/suites/jws-2020/v1JWS 2020 suite
- https://identity.foundation/.well-known/did-configuration/v1DIF Well Known DID Configuration
- https://identity.foundation/linked-vp/contexts/v1DIF Linked VP
None.
- JCS SHA-256
- 31af489e8f3844fc1b21aea9…
- id equals DID
- yes
Time machine
Observed snapshots and semantic differences between them.
Time machine
Loading observations…
Put it to work
Monitoring and private API access are paid; evidence on this page is never paywalled.
Put it to work
- A
Monitor changes
Get a signed webhook and a 30-day event history when keys, services or the document change. Checked hourly.
Watch this identifier → - B
Resolve from your app
Create a project and an API key. Private resolutions are metered, idempotent and never written to public history.
Create an API key → - C
Read the API
The same request this page made, as a standard W3C resolution or the DID.is evidence response.
Open the API reference →