Quickstart
Go from zero to sovereign messaging in under 5 minutes. By the end of this guide, you'll have a decentralised identity, a webhook endpoint, and your first sealed envelope delivered.
Before you start
You'll need:
- →An Arcform account (free tier available)
- →A server or endpoint to receive webhooks (e.g. ngrok for local dev)
- →cURL, JavaScript, or Python to make API calls
Activate your identity
One POST request creates a sovereign DID, generates an API key, and returns your fingerprint. No wallet setup, no key management — Arcform handles everything.
curl -X POST https://arcform-api.com/v1/did/activate \
-H "Content-Type: application/json" \
-d '{ "label": "My First Identity" }'Register a webhook
Tell DID.comms where to deliver incoming sealed envelopes. You'll receive an HMAC secret for signature verification.
curl -X POST https://arcform-api.com/v1/webhooks/register \
-H "Content-Type: application/json" \
-H "Authorization: Bearer YOUR_TOKEN" \
-H "X-DID-API-Key: ak_YOUR_KEY" \
-d '{
"url": "https://yourapp.com/webhooks/didcomms",
"events": ["envelope.received"]
}'Send your first message
Send a sealed envelope to any DID.comms identity. The message is encrypted, metadata is stripped, and delivery is verified — all in one call.
curl -X POST https://arcform-api.com/v1/channel/send \
-H "Content-Type: application/json" \
-H "Authorization: Bearer YOUR_TOKEN" \
-H "X-DID-API-Key: ak_YOUR_SENDER_KEY" \
-d '{
"to": "ak_RECIPIENT_KEY",
"message": "Hello — this is a sealed envelope"
}'What happens behind the scenes
Key isolation
Your signing keys are generated, encrypted, and stored by Arcform's sovereign wallet. You never see or handle raw cryptographic material.
Metadata stripping
Every envelope has its metadata stripped and sealed before routing. This is an immutable platform behaviour — not a toggle.
Mediator routing
Envelopes are routed through sovereign relay nodes. Each hop is logged for auditability, but payload content is never stored.
Verify your delivery
Confirm the envelope was delivered with full integrity. The /v1/verify endpoint is public — no auth required. You'll get a proof-of-transit object with integrity flags, identity verdict, and routing confirmation.
curl -X POST https://arcform-api.com/v1/verify \
-H "Content-Type: application/json" \
-d '{"envelope_hash": "YOUR_ENVELOPE_HASH"}'