mfid is the did:mfid v1 DID method/profile package.
Status: 1.0 preview. 0.9.0 reflects our assessment that the v1 design has
reached its baseline shape; minor adjustments are still possible before 1.0
based on community feedback and real-world use, and 1.0 will freeze the
API/protocol, with later versions extending it while keeping compatibility.
mfid provides a DID profile for identities owned by control of active owner private keys, typically generated and held by user devices or authenticators, without requiring a central registry. The identifier is derived from the genesis owner key, while the current trusted state is proven by a DID document and proof-chain verified together.
An mfid profile can rotate owner keys without changing its DID. A DID document is trusted only when it verifies against its proof-chain. Applications can build registration and authorization flows on top of mfid, while product-specific policy remains outside the DID method core.
mfid v1 is intended to serve as a personal security root for a user's network of owner devices. It is not intended to be used as a public identifier across applications or third-party services.
did:mfid:<mfid>v1 identifier derivation and DID document creation.- A narrow DID Core-compatible document profile using
JsonWebKey2020andpublicKeyJwk. - Method-specific proof-chain creation, append, and verification.
- Deterministic JSON and hash helpers used by the v1 profile.
- Owner proof verification for
jwk.signandwebauthn.get. - JSON schema snapshots and cross-implementation test vectors.
- Product registration policy, bootstrap artifacts, grants, sessions, and UI.
- Resolver hosting, registry writes, and network transport.
For API usage, read the runnable example below — it covers document creation, genesis proof-chain creation, and profile verification end to end. See docs/api.md for the full helper list.
The runnable minimal example creates a P-256 owner key, creates an mfid DID document, signs the genesis document proof, creates a proof-chain, and verifies the resulting profile.
npm run example:minimalThe command prints a JSON object with verified: true, the generated DID,
document hash, and proof-chain head hash.
To also print the generated profile before the verification result:
MFID_EXAMPLE_PRINT_PROFILE=1 npm run example:minimalSource: examples/minimal.mjs.
Specification:
Reference:
Considerations: