Weave documentation
Rust referencel1fe-did

l1fe-did · crate

Source declarations, signatures and documentation for crate.

Reviewed implementation boundary: Derivation proofs sign the child public key and derivation path; parent and child DID strings remain separate metadata outside that signed payload. Callers supply verifying keys and trust-root policy. See /libraries/l1fe-did/internals.

Source: sigil/weave/l1feid/l1fe-did/src/lib.rs. SHA-256: 08f4c7616e0db26f683ca5de58786c867fa32530f485722dc134bede65cacd76.

This reference follows declared source modules, retains conditional attributes, and includes public declarations and implementation methods. Private-module re-exports and trait resolution require the compiler; this is a source reference, not a claim that every listed item is a root import. Function bodies and constant values are omitted.

::DidKind

All asset kinds recognised by L1fe.

#[derive(Debug, Clone, PartialEq, Eq, Hash, Serialize, Deserialize)]
pub enum DidKind {
    Zer0Plugin,
    Zer0Service,
    Aut0Tool,
    Aut0Workflow,
    AgentManifest,
    AgentInstance,
    HumanRoot,
    MultiHumanRoot,
    AutonomousOrganization,
    Agent,
    Tool,
    Workflow,
}

Source line: 59.

::Did

Parsed DID representation

#[derive(Debug, Clone, PartialEq, Eq, Hash, Serialize, Deserialize)]
pub struct Did {
pub kind: DidKind,
/// Asset name or slug (always lower-kebab-case). Empty for AgentInstance.

pub name: Option<String>,
/// Semantic version when the DID is versioned (plugins, services, tools, workflows, manifests)

pub version: Option<Version>,
/// UUID portion for instance DIDs

pub uuid: Option<Uuid>,
/// Method-specific ID for L1feOS DIDs

pub method_specific_id: String
}

Source line: 76.

::DidError

#[derive(Debug, Error, PartialEq, Eq)]
pub enum DidError {
    #[error("DID must start with 'did:' prefix")]
    MissingPrefix,
    #[error("Unsupported DID namespace")]
    UnsupportedNamespace,
    #[error("Malformed DID format")]
    Malformed,
    #[error("Invalid semantic version: {0}")]
    InvalidSemver(String),
    #[error("Invalid UUID: {0}")]
    InvalidUuid(String),
}

Source line: 89.

::Did::new_agent_instance

Convenience helper to create a brand-new Agent Instance DID with a random UUID v4.

pub fn new_agent_instance() -> Self;

Source line: 175.

::Did::to_bytes

pub fn to_bytes(&self) -> Result<[u8; 32], DidError>;

Source line: 186.

::Did::parse

Parse a DID string

pub fn parse(did_str: &str) -> Result<Self, DidError>;

Source line: 197.

::Did::method_specific_id

Get the method-specific identifier

pub fn method_specific_id(&self) -> &str;

Source line: 202.

::Did::as_str

Get the DID as a string

pub fn as_str(&self) -> &str;

Source line: 207.

::DidDocument

DID Document representation

#[derive(Debug, Clone, Serialize, Deserialize, PartialEq)]
pub struct DidDocument {
/// The DID this document describes

pub id: Did,
/// Verification methods for the DID

pub verification_method: Vec<VerificationMethod>,
/// Authentication methods

pub authentication: Vec<String>,
/// Assertion methods

pub assertion_method: Option<Vec<String>>,
/// Key agreement methods

pub key_agreement: Option<Vec<String>>,
/// Capability invocation methods

pub capability_invocation: Option<Vec<String>>,
/// Capability delegation methods

pub capability_delegation: Option<Vec<String>>,
/// Controller of this DID

pub controller: Option<String>,
/// Services associated with this DID

pub service: Option<Vec<Service>>,
/// Alternative names for this DID

pub also_known_as: Option<Vec<String>>,
/// Creation timestamp

pub created: Option<DateTime<Utc>>,
/// Last update timestamp

pub updated: Option<DateTime<Utc>>
}

Source line: 214.

::DidDocument::controller

Get the controller of this DID document

pub fn controller(&self) -> Option<&String>;

Source line: 268.

::VerificationMethod

Verification method for a DID

#[derive(Debug, Clone, Serialize, Deserialize, PartialEq)]
pub struct VerificationMethod {
/// ID of the verification method

pub id: String,
/// Controller of this verification method

pub controller: String,
/// Type of the verification method

#[serde(rename = "type")]
pub key_type: String,
/// Public key in multibase format

pub public_key_multibase: Option<String>,
/// Public key in JWK format

pub public_key_jwk: Option<serde_json::Value>,
/// Derivation proof (L1FE-HDDID v1) - only present if this key was derived from a parent

#[serde(skip_serializing_if = "Option::is_none")]
pub proof: Option<DerivationProof2025>
}

Source line: 275.

::VerificationMethod::public_key_multibase

Get the public key multibase

pub fn public_key_multibase(&self) -> Option<&String>;

Source line: 294.

::VerificationMethod::derivation_proof

Get the derivation proof if present

pub fn derivation_proof(&self) -> Option<&DerivationProof2025>;

Source line: 299.

::Service

Service endpoint for a DID

#[derive(Debug, Clone, Serialize, Deserialize, PartialEq)]
pub struct Service {
/// ID of the service

pub id: String,
/// Type of the service

#[serde(rename = "type")]
pub service_type: String,
/// Service endpoint URL

pub service_endpoint: String
}

Source line: 306.

::DerivationProof2025

DerivationProof2025 - Cryptographic proof that a child DID was derived from a parent DID Implements L1FE-HDDID v1 specification for verifiable hierarchical DID derivation See docs/L1FE-HDDID-v1.md for full specification

#[derive(Debug, Clone, Serialize, Deserialize, PartialEq, Eq)]
pub struct DerivationProof2025 {
#[serde(rename = "type")]
pub proof_type: String,
pub parent_did: String,
pub child_did: String,
pub derivation_path: String,
pub algorithm: String,
pub public_key_multibase: String,
pub signature: String
}

Source line: 320.

::DerivationProof2025::new

pub fn new(
        parent_did: String,
        child_did: String,
        derivation_path: String,
        public_key_multibase: String,
        signature: String,
    ) -> Self;

Source line: 332.

::DidDocument::add_derivation_proof

Add derivation proof to a verification method Updates the verification method with the derivation proof per L1FE-HDDID v1 spec

pub fn add_derivation_proof(
        &mut self,
        verification_method_id: &str,
        proof: DerivationProof2025,
    ) -> Result<(), DidError>;

Source line: 354.

::DidDocument::derivation_path

Get derivation path if this DID was derived from a parent Returns the derivation path from the first verification method with a proof

pub fn derivation_path(&self) -> Option<&str>;

Source line: 370.

::DidDocument::parent_did

Get the parent DID if this DID was derived from a parent

pub fn parent_did(&self) -> Option<&str>;

Source line: 377.

::DidDocument::derivation_proofs

Get all derivation proofs in this document

pub fn derivation_proofs(&self) -> Vec<&DerivationProof2025>;

Source line: 384.

::DidDocument::is_derived

Check if this DID was derived from a parent (has derivation proof)

pub fn is_derived(&self) -> bool;

Source line: 392.

hierarchical::derive_child_key

Derive a child key from a parent key using L1FE-HDDID v1 specification Implements Ed25519-HKDF-SHA256 with Blake2b salt as per L1FE-HDDID v1 spec

Algorithm (per L1FE-HDDID v1 §4.1)

IKM  = parent_private_key (32 bytes)
salt = blake2b(parent_public_key)
info = UTF8Bytes(derivation_path)
okm  = HKDF(SHA256, IKM, salt, info, L=32)
child_private_key = okm
child_public_key  = Ed25519(child_private_key)

Arguments

  • parent_key - The parent signing key (e.g., HMR key for org, org key for agent)
  • derivation_path - Derivation path (must start with / and contain only [a-z0-9\-])

Returns

A new child signing key and its corresponding did:key DID

#[cfg(feature = "hierarchical")]
pub fn derive_child_key(
        parent_key: &SigningKey,
        derivation_path: &str,
    ) -> Result<(SigningKey, String), DidError>;

Source line: 593.

hierarchical::derive_did_from_public_key

Derive a did:key from an Ed25519 public key (can be called client-side)

#[cfg(feature = "hierarchical")]
pub fn derive_did_from_public_key(vk: &VerifyingKey) -> Result<String, DidError>;

Source line: 634.

hierarchical::create_derivation_proof

Create a DerivationProof2025 for a child key (L1FE-HDDID v1 §6)

#[cfg(feature = "hierarchical")]
pub fn create_derivation_proof(
        parent_key: &SigningKey,
        parent_did: &str,
        child_key: &SigningKey,
        child_did: &str,
        derivation_path: &str,
    ) -> Result<DerivationProof2025, DidError>;

Source line: 646.

hierarchical::verify_derivation_proof

Verify a DerivationProof2025 (L1FE-HDDID v1 §6.3 - Reverse Derivation) This allows verification of derivation relationships using only public keys and the proof.

Verification Steps (per spec §6.3)

  1. Verify Ed25519 signature using parent public key
  2. Verify child public key matches the proof's declared public key
  3. (Optional) Re-derive child key from parent to verify derivation (requires parent private key)

Returns

Ok(true) if signature and public key match are valid, Ok(false) otherwise

#[cfg(feature = "hierarchical")]
pub fn verify_derivation_proof(
        parent_public_key: &VerifyingKey,
        child_public_key: &VerifyingKey,
        proof: &DerivationProof2025,
    ) -> Result<bool, DidError>;

Source line: 693.

hierarchical::verify_derivation_with_parent_key

Verify derivation using parent private key (full cryptographic verification) This confirms both the signature AND that the child key was actually derived from the parent

Returns

Ok(true) if child key was derived from parent using the given path

#[cfg(feature = "hierarchical")]
pub fn verify_derivation_with_parent_key(
        parent_key: &SigningKey,
        child_public_key: &VerifyingKey,
        derivation_path: &str,
    ) -> Result<bool, DidError>;

Source line: 751.

hierarchical::verify_derivation_chain_documents

Verify a complete derivation chain (HMR → AO → Agent) This recursively verifies all proofs in a hierarchy

Arguments

  • documents - Vector of DID Documents in derivation order (root first)

Returns

Ok(true) if all proofs are valid, Ok(false) if any proof is invalid

Example

# #[cfg(feature = "hierarchical")]
# {
use l1fe_did::{DidDocument, Did, DidKind};
use ed25519_dalek::SigningKey;

// Build a derivation chain
let root_key = SigningKey::from_bytes(&[0u8; 32]);
let root_did = Did::from_str("did:l1fe:hmr:user-123")?;
let derivations = vec![
    ("/org-acme".to_string(), DidKind::AutonomousOrganization),
];
let chain = DidDocument::build_derivation_chain(root_did, &root_key, derivations)?;

// Extract documents
let documents: Vec<DidDocument> = chain.into_iter().map(|(_, doc)| doc).collect();

// Verify the chain
assert!(hierarchical::verify_derivation_chain_documents(&documents)?);
# }

Note

This is a simplified version that assumes all documents are provided. In production, you'd fetch parent documents from a resolver.

#[cfg(feature = "hierarchical")]
pub fn verify_derivation_chain_documents(documents: &[DidDocument]) -> Result<bool, DidError>;

Source line: 799.

pub use hierarchical::*;

#[cfg(feature = "hierarchical")]
pub use hierarchical::*;

Source line: 866.

::DidDocument::create_derived_document

Create a DID Document for a derived child DID (L1FE-HDDID v1 §7) This creates a complete DID Document with derivation proof embedded in the verification method

Arguments

  • child_did - The child DID (e.g., did:l1fe:ao:org-456def)
  • child_public_key - The child's public key
  • parent_did - The parent DID (e.g., did:l1fe:hmr:user-abc123)
  • derivation_path - The derivation path used (e.g., /org-456def)
  • proof - The DerivationProof2025 proving the derivation

Returns

A complete DID Document ready for publication to DHT

Example

use l1fe_did::{DidDocument, DerivationProof2025};
use ed25519_dalek::VerifyingKey;

let child_did = Did::from_str("did:l1fe:ao:org-456def")?;
let parent_did = "did:l1fe:hmr:user-abc123";
let proof = create_derivation_proof(...)?;

let doc = DidDocument::create_derived_document(
    child_did,
    child_vk,
    parent_did,
    "/org-456def",
    proof
)?;
#[cfg(feature = "hierarchical")]
pub fn create_derived_document(
        child_did: Did,
        child_public_key: VerifyingKey,
        parent_did: &str,
        _derivation_path: &str,
        proof: DerivationProof2025,
    ) -> Result<Self, DidError>;

Source line: 904.

::DidDocument::create_root_document

Create a root DID Document (for HMR/MHR - no parent) This creates a DID Document for a root key that is not derived from any parent

Arguments

  • did - The root DID
  • public_key - The root public key

Returns

A complete DID Document for the root DID

#[cfg(feature = "hierarchical")]
pub fn create_root_document(did: Did, public_key: VerifyingKey) -> Result<Self, DidError>;

Source line: 954.

::DidDocument::verify_derivation_chain

Verify the derivation chain for this DID Document Recursively verifies all derivation proofs up to the root

Returns

Ok(true) if all proofs in the chain are valid, Ok(false) if any proof is invalid

Note

This requires access to parent DID Documents. In a full implementation, this would fetch parent documents from a resolver.

#[cfg(feature = "hierarchical")]
pub fn verify_derivation_chain(&self) -> Result<bool, DidError>;

Source line: 999.

::DidDocument::verify_derivation_chain_documents

Verify a complete derivation chain (HMR → AO → Agent) This recursively verifies all proofs in a hierarchy

Arguments

  • documents - Vector of DID Documents in derivation order (root first)

Returns

Ok(true) if all proofs are valid, Ok(false) if any proof is invalid

Example

# #[cfg(feature = "hierarchical")]
# {
use l1fe_did::{DidDocument, Did, DidKind};
use ed25519_dalek::SigningKey;

// Build a derivation chain
let root_key = SigningKey::from_bytes(&[0u8; 32]);
let root_did = Did::from_str("did:l1fe:hmr:user-123")?;
let derivations = vec![
    ("/org-acme".to_string(), DidKind::AutonomousOrganization),
];
let chain = DidDocument::build_derivation_chain(root_did, &root_key, derivations)?;

// Extract documents
let documents: Vec<DidDocument> = chain.into_iter().map(|(_, doc)| doc).collect();

// Verify the chain
assert!(DidDocument::verify_derivation_chain_documents(&documents)?);
# }

Note

This is a simplified version that assumes all documents are provided. In production, you'd fetch parent documents from a resolver.

#[cfg(feature = "hierarchical")]
pub fn verify_derivation_chain_documents(documents: &[DidDocument]) -> Result<bool, DidError>;

Source line: 1056.

::DidDocument::build_derivation_chain

Build a complete derivation chain from a root DID This is a helper for creating the full hierarchy: HMR → AO → Agent

Arguments

  • root_did - The root DID (HMR)
  • root_key - The root signing key
  • derivations - Vector of (path, child_did_type) tuples

Returns

Vector of (DID, DidDocument) pairs for each level in the hierarchy

Example

let derivations = vec![
    ("/org-acme".to_string(), DidKind::AutonomousOrganization),
    ("/agent-analyst".to_string(), DidKind::Agent),
];
let chain = DidDocument::build_derivation_chain(root_did, root_key, derivations)?;
#[cfg(feature = "hierarchical")]
pub fn build_derivation_chain(
        root_did: Did,
        root_key: &SigningKey,
        derivations: Vec<(String, DidKind)>,
    ) -> Result<Vec<(Did, DidDocument)>, DidError>;

Source line: 1126.

On this page