ARCFORM

API SERVICES

Architecture

Sovereign infrastructure documentation — every layer explained by its architectural purpose

Platform Identity

Sovereign Transportier™ — Canonical definition

A Sovereign Transportier™ is a neutral, sealed, zero-retention transport layer that carries identity, credentials, proofs, governance signals, and attestations between independent trust ecosystems, while providing deterministic audit evidence without becoming the identity provider, credential issuer, wallet, verifier, or trust authority.

Arcform is the first Sovereign Transportier™. The platform abstracts DID creation, activation, key management, and envelope construction into a walletless, developer-first model powered by Arcform's internal company wallet. Developers interact with a single Sovereign Proxy endpoint; Arcform orchestrates the entire identity and messaging lifecycle behind the scenes. For every DIDComm action, Arcform — not the developer — is the cryptographic actor of record.

SOVEREIGN PROXY CONTRACT: Clients never pass raw DIDs or keys. They use aliases; Arcform resolves them internally. All compliance burden rests with Arcform's infrastructure.

Read full Proxy Contract

Category

Sovereign Transportier™

Model

Walletless DID

Protocol

DIDComm v2

Flagship

Arcform MPC

DID Activation Layer

Generates, activates, and publishes decentralised identifiers for each API key using Arcform's internal sovereign wallet.

Keypair CreatorKey Store (Encrypted)DID GeneratorDID ActivatorDID Document PublisherAPI Key → DID Mapper

Envelope Engine

Constructs DIDComm envelopes, encrypts payloads, signs with Ed25519 keys, and minimises metadata before routing.

Envelope BuilderMetadata MinimiserSigner + EncrypterOnion Router

Mediator Layer

Routes encrypted envelopes through sovereign hops with zero metadata leakage, ensuring delivery integrity.

Mediator ServiceQueue + Retry LogicHop Resolver

Sovereign Proxy (API Surface)

A single endpoint through which all DIDComm operations are performed by Arcform's internal company wallet, never by the client. For every DIDComm action, Arcform — not the developer — is the cryptographic actor of record.

POST /v1/channel/send (Sovereign Proxy)Identity ResolverDID Rejection GateDelivery Receipt Generator

Verification Layer

Multi-layer proof-of-transit verification combining integrity checks, identity verdict resolution, and governance signer set validation. Five-boundary caching architecture for industrial-scale throughput.

Bubble Engine (verify/fetch/expire)Proof Checksum ValidatorIdentity Verdict ResolverSigner Set ResolutionBatch Paralleliser (50 hashes)Verdict Cache

Governance Layer

Control plane for decentralised identity governance. Typed governance signals (proposal, vote, attestation, instruction), M-of-N threshold signing via SignerSet entities, and conditional XRPL anchoring.

SignerSet RegistryThreshold EnforcerSignal Type RouterKeyLineage TrackerZKP Migration Path

Alert & Observability Layer

Real-time event-driven alert pipeline. Entity automations detect governance changes and route structured Slack alerts to four domain-specific channels within seconds of the triggering event.

slackEntityAlert (Context Extractor)slackAlert (Formatter)#arcform-governance#arcform-ledger#arcform-audit#arcform-attributes

Browser Verification Layer

Chrome extension providing local-first verification, offline audit trails via IndexedDB, and live governance alerts via chrome.alarms polling — a companion for developers consuming the API.

Canonical Hasher (Web Crypto)Local Audit Spine (IndexedDB)MeshNode P2P RegistryAttestation HUDAlert Polling Pipeline

Dashboard Layer

Developer-facing interface for API key management, usage monitoring, and plan selection.

API Key ManagerUsage DashboardPlan SelectorBilling Engine

DID Activation Flow

End-to-end sequence executed on API key creation

1

API Key Created

System generates api_key_id

2

Generate Keypair

Ed25519 signing + X25519 encryption keys created, stored encrypted

3

Generate DID

DID string + DID Document template + key references constructed

4

Activate DID

Sovereign wallet registers and anchors DID on-chain

5

Publish DID Document

Public keys, service endpoints, and routing metadata published

6

Map API Key → DID

api_key_id → did → keypair_id mapping stored

7

Return to Developer

Developer sees API key and usage counter — no DIDs, no keys, nothing cryptographic