Internals
DID documents, derivation proofs, and explicit verification boundaries.
Documents and verification methods
DidDocument stores verification_method, authentication, optional assertion/key-agreement/capability lists, controller, services and timestamps. These are public fields. Enable the hierarchical feature to use the key-derivation and document-creation helpers. Construct a cryptographic root with DidDocument::create_root_document(did, verifying_key); there is no DidDocument::new(did) or VerificationMethod::ed25519 builder.
VerificationMethod records its ID, controller, key type, optional multibase/JWK key and optional DerivationProof2025. Service endpoints are document data; parsing does not contact them.
Hierarchical identity flow
derive_child_key produces a child signing key and encoded public key. create_derivation_proof signs JSON containing the encoded child public key and derivation path. Parent and child DID strings are separate proof metadata, not fields in that signed payload. verify_derivation_proof takes the parent and child verifying keys explicitly; verify_derivation_chain_documents validates a supplied ordered chain. Load the required parent documents and apply your application's trust-root policy before accepting a chain.
DidError variants are MissingPrefix, UnsupportedNamespace, Malformed, InvalidSemver, and InvalidUuid. Unsupported input is an error; no DidError::Format variant exists. Use Display/to_string() for canonical formatted identifiers, since as_str() exposes the stored method-specific representation.
Source reference
Exact declarations and source provenance · Package features and manifest.