l1fe-did · crate
Source declarations, signatures and documentation for crate.
Reviewed implementation boundary: Derivation proofs sign the child public key and derivation path; parent and child DID strings remain separate metadata outside that signed payload. Callers supply verifying keys and trust-root policy. See /libraries/l1fe-did/internals.
Source: sigil/weave/l1feid/l1fe-did/src/lib.rs. SHA-256: 08f4c7616e0db26f683ca5de58786c867fa32530f485722dc134bede65cacd76.
This reference follows declared source modules, retains conditional attributes, and includes public declarations and implementation methods. Private-module re-exports and trait resolution require the compiler; this is a source reference, not a claim that every listed item is a root import. Function bodies and constant values are omitted.
::DidKind
All asset kinds recognised by L1fe.
#[derive(Debug, Clone, PartialEq, Eq, Hash, Serialize, Deserialize)]
pub enum DidKind {
Zer0Plugin,
Zer0Service,
Aut0Tool,
Aut0Workflow,
AgentManifest,
AgentInstance,
HumanRoot,
MultiHumanRoot,
AutonomousOrganization,
Agent,
Tool,
Workflow,
}Source line: 59.
::Did
Parsed DID representation
#[derive(Debug, Clone, PartialEq, Eq, Hash, Serialize, Deserialize)]
pub struct Did {
pub kind: DidKind,
/// Asset name or slug (always lower-kebab-case). Empty for AgentInstance.
pub name: Option<String>,
/// Semantic version when the DID is versioned (plugins, services, tools, workflows, manifests)
pub version: Option<Version>,
/// UUID portion for instance DIDs
pub uuid: Option<Uuid>,
/// Method-specific ID for L1feOS DIDs
pub method_specific_id: String
}Source line: 76.
::DidError
#[derive(Debug, Error, PartialEq, Eq)]
pub enum DidError {
#[error("DID must start with 'did:' prefix")]
MissingPrefix,
#[error("Unsupported DID namespace")]
UnsupportedNamespace,
#[error("Malformed DID format")]
Malformed,
#[error("Invalid semantic version: {0}")]
InvalidSemver(String),
#[error("Invalid UUID: {0}")]
InvalidUuid(String),
}Source line: 89.
::Did::new_agent_instance
Convenience helper to create a brand-new Agent Instance DID with a random UUID v4.
pub fn new_agent_instance() -> Self;Source line: 175.
::Did::to_bytes
pub fn to_bytes(&self) -> Result<[u8; 32], DidError>;Source line: 186.
::Did::parse
Parse a DID string
pub fn parse(did_str: &str) -> Result<Self, DidError>;Source line: 197.
::Did::method_specific_id
Get the method-specific identifier
pub fn method_specific_id(&self) -> &str;Source line: 202.
::Did::as_str
Get the DID as a string
pub fn as_str(&self) -> &str;Source line: 207.
::DidDocument
DID Document representation
#[derive(Debug, Clone, Serialize, Deserialize, PartialEq)]
pub struct DidDocument {
/// The DID this document describes
pub id: Did,
/// Verification methods for the DID
pub verification_method: Vec<VerificationMethod>,
/// Authentication methods
pub authentication: Vec<String>,
/// Assertion methods
pub assertion_method: Option<Vec<String>>,
/// Key agreement methods
pub key_agreement: Option<Vec<String>>,
/// Capability invocation methods
pub capability_invocation: Option<Vec<String>>,
/// Capability delegation methods
pub capability_delegation: Option<Vec<String>>,
/// Controller of this DID
pub controller: Option<String>,
/// Services associated with this DID
pub service: Option<Vec<Service>>,
/// Alternative names for this DID
pub also_known_as: Option<Vec<String>>,
/// Creation timestamp
pub created: Option<DateTime<Utc>>,
/// Last update timestamp
pub updated: Option<DateTime<Utc>>
}Source line: 214.
::DidDocument::controller
Get the controller of this DID document
pub fn controller(&self) -> Option<&String>;Source line: 268.
::VerificationMethod
Verification method for a DID
#[derive(Debug, Clone, Serialize, Deserialize, PartialEq)]
pub struct VerificationMethod {
/// ID of the verification method
pub id: String,
/// Controller of this verification method
pub controller: String,
/// Type of the verification method
#[serde(rename = "type")]
pub key_type: String,
/// Public key in multibase format
pub public_key_multibase: Option<String>,
/// Public key in JWK format
pub public_key_jwk: Option<serde_json::Value>,
/// Derivation proof (L1FE-HDDID v1) - only present if this key was derived from a parent
#[serde(skip_serializing_if = "Option::is_none")]
pub proof: Option<DerivationProof2025>
}Source line: 275.
::VerificationMethod::public_key_multibase
Get the public key multibase
pub fn public_key_multibase(&self) -> Option<&String>;Source line: 294.
::VerificationMethod::derivation_proof
Get the derivation proof if present
pub fn derivation_proof(&self) -> Option<&DerivationProof2025>;Source line: 299.
::Service
Service endpoint for a DID
#[derive(Debug, Clone, Serialize, Deserialize, PartialEq)]
pub struct Service {
/// ID of the service
pub id: String,
/// Type of the service
#[serde(rename = "type")]
pub service_type: String,
/// Service endpoint URL
pub service_endpoint: String
}Source line: 306.
::DerivationProof2025
DerivationProof2025 - Cryptographic proof that a child DID was derived from a parent DID Implements L1FE-HDDID v1 specification for verifiable hierarchical DID derivation See docs/L1FE-HDDID-v1.md for full specification
#[derive(Debug, Clone, Serialize, Deserialize, PartialEq, Eq)]
pub struct DerivationProof2025 {
#[serde(rename = "type")]
pub proof_type: String,
pub parent_did: String,
pub child_did: String,
pub derivation_path: String,
pub algorithm: String,
pub public_key_multibase: String,
pub signature: String
}Source line: 320.
::DerivationProof2025::new
pub fn new(
parent_did: String,
child_did: String,
derivation_path: String,
public_key_multibase: String,
signature: String,
) -> Self;Source line: 332.
::DidDocument::add_derivation_proof
Add derivation proof to a verification method Updates the verification method with the derivation proof per L1FE-HDDID v1 spec
pub fn add_derivation_proof(
&mut self,
verification_method_id: &str,
proof: DerivationProof2025,
) -> Result<(), DidError>;Source line: 354.
::DidDocument::derivation_path
Get derivation path if this DID was derived from a parent Returns the derivation path from the first verification method with a proof
pub fn derivation_path(&self) -> Option<&str>;Source line: 370.
::DidDocument::parent_did
Get the parent DID if this DID was derived from a parent
pub fn parent_did(&self) -> Option<&str>;Source line: 377.
::DidDocument::derivation_proofs
Get all derivation proofs in this document
pub fn derivation_proofs(&self) -> Vec<&DerivationProof2025>;Source line: 384.
::DidDocument::is_derived
Check if this DID was derived from a parent (has derivation proof)
pub fn is_derived(&self) -> bool;Source line: 392.
hierarchical::derive_child_key
Derive a child key from a parent key using L1FE-HDDID v1 specification Implements Ed25519-HKDF-SHA256 with Blake2b salt as per L1FE-HDDID v1 spec
Algorithm (per L1FE-HDDID v1 §4.1)
IKM = parent_private_key (32 bytes)
salt = blake2b(parent_public_key)
info = UTF8Bytes(derivation_path)
okm = HKDF(SHA256, IKM, salt, info, L=32)
child_private_key = okm
child_public_key = Ed25519(child_private_key)Arguments
parent_key- The parent signing key (e.g., HMR key for org, org key for agent)derivation_path- Derivation path (must start with/and contain only[a-z0-9\-])
Returns
A new child signing key and its corresponding did:key DID
#[cfg(feature = "hierarchical")]
pub fn derive_child_key(
parent_key: &SigningKey,
derivation_path: &str,
) -> Result<(SigningKey, String), DidError>;Source line: 593.
hierarchical::derive_did_from_public_key
Derive a did:key from an Ed25519 public key (can be called client-side)
#[cfg(feature = "hierarchical")]
pub fn derive_did_from_public_key(vk: &VerifyingKey) -> Result<String, DidError>;Source line: 634.
hierarchical::create_derivation_proof
Create a DerivationProof2025 for a child key (L1FE-HDDID v1 §6)
#[cfg(feature = "hierarchical")]
pub fn create_derivation_proof(
parent_key: &SigningKey,
parent_did: &str,
child_key: &SigningKey,
child_did: &str,
derivation_path: &str,
) -> Result<DerivationProof2025, DidError>;Source line: 646.
hierarchical::verify_derivation_proof
Verify a DerivationProof2025 (L1FE-HDDID v1 §6.3 - Reverse Derivation) This allows verification of derivation relationships using only public keys and the proof.
Verification Steps (per spec §6.3)
- Verify Ed25519 signature using parent public key
- Verify child public key matches the proof's declared public key
- (Optional) Re-derive child key from parent to verify derivation (requires parent private key)
Returns
Ok(true) if signature and public key match are valid, Ok(false) otherwise
#[cfg(feature = "hierarchical")]
pub fn verify_derivation_proof(
parent_public_key: &VerifyingKey,
child_public_key: &VerifyingKey,
proof: &DerivationProof2025,
) -> Result<bool, DidError>;Source line: 693.
hierarchical::verify_derivation_with_parent_key
Verify derivation using parent private key (full cryptographic verification) This confirms both the signature AND that the child key was actually derived from the parent
Returns
Ok(true) if child key was derived from parent using the given path
#[cfg(feature = "hierarchical")]
pub fn verify_derivation_with_parent_key(
parent_key: &SigningKey,
child_public_key: &VerifyingKey,
derivation_path: &str,
) -> Result<bool, DidError>;Source line: 751.
hierarchical::verify_derivation_chain_documents
Verify a complete derivation chain (HMR → AO → Agent) This recursively verifies all proofs in a hierarchy
Arguments
documents- Vector of DID Documents in derivation order (root first)
Returns
Ok(true) if all proofs are valid, Ok(false) if any proof is invalid
Example
# #[cfg(feature = "hierarchical")]
# {
use l1fe_did::{DidDocument, Did, DidKind};
use ed25519_dalek::SigningKey;
// Build a derivation chain
let root_key = SigningKey::from_bytes(&[0u8; 32]);
let root_did = Did::from_str("did:l1fe:hmr:user-123")?;
let derivations = vec![
("/org-acme".to_string(), DidKind::AutonomousOrganization),
];
let chain = DidDocument::build_derivation_chain(root_did, &root_key, derivations)?;
// Extract documents
let documents: Vec<DidDocument> = chain.into_iter().map(|(_, doc)| doc).collect();
// Verify the chain
assert!(hierarchical::verify_derivation_chain_documents(&documents)?);
# }Note
This is a simplified version that assumes all documents are provided. In production, you'd fetch parent documents from a resolver.
#[cfg(feature = "hierarchical")]
pub fn verify_derivation_chain_documents(documents: &[DidDocument]) -> Result<bool, DidError>;Source line: 799.
pub use hierarchical::*;
#[cfg(feature = "hierarchical")]
pub use hierarchical::*;Source line: 866.
::DidDocument::create_derived_document
Create a DID Document for a derived child DID (L1FE-HDDID v1 §7) This creates a complete DID Document with derivation proof embedded in the verification method
Arguments
child_did- The child DID (e.g.,did:l1fe:ao:org-456def)child_public_key- The child's public keyparent_did- The parent DID (e.g.,did:l1fe:hmr:user-abc123)derivation_path- The derivation path used (e.g.,/org-456def)proof- The DerivationProof2025 proving the derivation
Returns
A complete DID Document ready for publication to DHT
Example
use l1fe_did::{DidDocument, DerivationProof2025};
use ed25519_dalek::VerifyingKey;
let child_did = Did::from_str("did:l1fe:ao:org-456def")?;
let parent_did = "did:l1fe:hmr:user-abc123";
let proof = create_derivation_proof(...)?;
let doc = DidDocument::create_derived_document(
child_did,
child_vk,
parent_did,
"/org-456def",
proof
)?;#[cfg(feature = "hierarchical")]
pub fn create_derived_document(
child_did: Did,
child_public_key: VerifyingKey,
parent_did: &str,
_derivation_path: &str,
proof: DerivationProof2025,
) -> Result<Self, DidError>;Source line: 904.
::DidDocument::create_root_document
Create a root DID Document (for HMR/MHR - no parent) This creates a DID Document for a root key that is not derived from any parent
Arguments
did- The root DIDpublic_key- The root public key
Returns
A complete DID Document for the root DID
#[cfg(feature = "hierarchical")]
pub fn create_root_document(did: Did, public_key: VerifyingKey) -> Result<Self, DidError>;Source line: 954.
::DidDocument::verify_derivation_chain
Verify the derivation chain for this DID Document Recursively verifies all derivation proofs up to the root
Returns
Ok(true) if all proofs in the chain are valid, Ok(false) if any proof is invalid
Note
This requires access to parent DID Documents. In a full implementation, this would fetch parent documents from a resolver.
#[cfg(feature = "hierarchical")]
pub fn verify_derivation_chain(&self) -> Result<bool, DidError>;Source line: 999.
::DidDocument::verify_derivation_chain_documents
Verify a complete derivation chain (HMR → AO → Agent) This recursively verifies all proofs in a hierarchy
Arguments
documents- Vector of DID Documents in derivation order (root first)
Returns
Ok(true) if all proofs are valid, Ok(false) if any proof is invalid
Example
# #[cfg(feature = "hierarchical")]
# {
use l1fe_did::{DidDocument, Did, DidKind};
use ed25519_dalek::SigningKey;
// Build a derivation chain
let root_key = SigningKey::from_bytes(&[0u8; 32]);
let root_did = Did::from_str("did:l1fe:hmr:user-123")?;
let derivations = vec![
("/org-acme".to_string(), DidKind::AutonomousOrganization),
];
let chain = DidDocument::build_derivation_chain(root_did, &root_key, derivations)?;
// Extract documents
let documents: Vec<DidDocument> = chain.into_iter().map(|(_, doc)| doc).collect();
// Verify the chain
assert!(DidDocument::verify_derivation_chain_documents(&documents)?);
# }Note
This is a simplified version that assumes all documents are provided. In production, you'd fetch parent documents from a resolver.
#[cfg(feature = "hierarchical")]
pub fn verify_derivation_chain_documents(documents: &[DidDocument]) -> Result<bool, DidError>;Source line: 1056.
::DidDocument::build_derivation_chain
Build a complete derivation chain from a root DID This is a helper for creating the full hierarchy: HMR → AO → Agent
Arguments
root_did- The root DID (HMR)root_key- The root signing keyderivations- Vector of (path, child_did_type) tuples
Returns
Vector of (DID, DidDocument) pairs for each level in the hierarchy
Example
let derivations = vec![
("/org-acme".to_string(), DidKind::AutonomousOrganization),
("/agent-analyst".to_string(), DidKind::Agent),
];
let chain = DidDocument::build_derivation_chain(root_did, root_key, derivations)?;#[cfg(feature = "hierarchical")]
pub fn build_derivation_chain(
root_did: Did,
root_key: &SigningKey,
derivations: Vec<(String, DidKind)>,
) -> Result<Vec<(Did, DidDocument)>, DidError>;Source line: 1126.