DID.COMMSDOCS

Core Concepts

Understanding the architectural principles behind DID.comms. These aren't features you opt into — they're invariants that define the platform.

DID Namespace Isolation

DID.comms identities live under the did:comms: namespace, architecturally separate from Arcform's internal did:arcform: namespace.

This separation means your developer-facing identities are isolated from Arcform's infrastructure DIDs. Each API key maps to exactly one did:comms: identity — no ambiguity, no cross-namespace collisions.

When you call /v1/did/activate, the system creates a did:comms: identifier, generates a DID Document, and maps your api_key_id to the DID. You interact with api_key_id aliases — never raw DIDs.

Sovereign Proxy Contract

For every DIDComm action, Arcform — not the developer — is the cryptographic actor of record.

This is the fundamental architectural decision that makes DID.comms different. Your application never generates keys, signs envelopes, or resolves DIDs. Arcform's internal sovereign wallet performs all cryptographic operations on your behalf.

The Proxy Contract enforces four hard rules: key isolation (no client-side key access), cryptographic authority (Arcform signs everything), wallet orchestration (Arcform's wallet funds all on-chain operations), and audit immutability (every action is logged with a checksum).

Strip & Seal (Immutable Privacy)

Metadata stripping and payload sealing are always on. There is no toggle, no flag, no opt-out.

When you send an envelope, Arcform strips all identifying metadata from the routing path before delivery. The payload is encrypted end-to-end using X25519-XSalsa20-Poly1305. Envelope logs record hashes, byte counts, and latency — never payload content.

This is not a feature — it's an architectural invariant. Every response includes metadata_policy: 'stripped_and_sealed' as proof.

Walletless DID Model

DID.comms provides sovereign identity without requiring developers or their users to manage wallets or keys.

Traditional DID systems require each participant to hold a cryptographic wallet, manage key rotation, and fund on-chain transactions. DID.comms eliminates this entirely. Arcform's company wallet handles all on-chain anchoring, key storage, and lifecycle management.

The result: developers get sovereign-grade identity guarantees with a standard REST API. No wallet SDKs, no seed phrases, no gas fees.

M-of-N Threshold Governance

Organizational DIDs can be governed by multiple signers using threshold-based quorum via the SignerSet entity.

Each signer set defines a threshold (M), a list of authorised signers (N), and a temporal validity window. When an envelope is verified, the identity verdict resolution checks whether the sender was an authorised signer in the active set at send-time. Unauthorised signers receive a degraded verdict.

Signer set versioning is immutable — when the quorum changes, a new SignerSet record is created and the previous one is marked superseded. This preserves the full governance history for time-anchored verification.

Real-Time Alert Boundaries

Governance events are surfaced in real time via four dedicated Slack channels, each mapped to a specific domain of the sovereign data model.

Entity automations watch for changes across SignerSet, KeyLineage, AuditLog, Attribute, EnvelopeLog, and Delegation records. When a qualifying event occurs, a two-function pipeline extracts the context, determines severity, and delivers a structured Block Kit message to the correct channel within seconds.

The four boundary channels — #arcform-governance, #arcform-ledger, #arcform-audit, and #arcform-attributes — provide domain isolation with noise filtering. Audit alerts only fire on warning/critical severity. Ledger alerts only fire on anchor_status transitions. No polling, no dashboards — events arrive where the team already works.

Browser-Local Verification

The Arcform Chrome Skill extends the verification layer into the browser — proof checksums are computed locally via Web Crypto API, never touching the network.

The extension maintains a Local Audit Spine (IndexedDB) for offline verdict storage, a MeshNode P2P registry for cross-portal consensus, and a chrome.alarms-based polling pipeline that surfaces governance alerts in the browser toolbar.

This is the developer companion for the API: verify envelopes from any web page, audit verdicts offline, and receive critical governance alerts without leaving the browser. Zero dependencies, zero data collection, Manifest V3.