ORBIS.ID
You are on Anyone PUBorbis.id

ORBIS.ID · SEARCH

Every page this build knows about, in one list you can narrow.

This page does not call a model, an API, or a server. Every row below — every page, every glossary term, every register claim — is already in the document you are reading, computed once when this site was built. The box further down hides the rows that do not match; it makes nothing appear that was not here already.

This search box cannot log what you typed.

A search box that calls a server can go down, can be metered, and can log what you typed. This one cannot do any of those things, because it does not run anywhere but your own browser, over a list this build already committed to the page.

Narrow the whole index.

76 pages named across this site, 75 of them in this build · 18 glossary terms · 26 register rows.

Pages

Glossary terms

  • Conformance vector A fixed input with a known correct answer, published so that anyone can point their own implementation at it and see whether it behaves.
  • DID An identifier an organization controls itself, which publishes the public keys it signs with. did:web resolves to a document served under the organization's own domain.
  • Holder The person who carries the proof and decides, every single time, what to show and to whom.
  • Issuer The organization that signs a statement it already knew to be true: a bank, an employer, a university, a city.
  • OpenID4VCI The wire protocol a wallet uses to collect a credential from an issuer, and the metadata document that tells the wallet how.
  • OpenID4VP The wire protocol a checker uses to ask for one specific fact, and a wallet uses to answer with a proof of exactly that fact.
  • Proof A signed statement about a person, made by an organization that already knew the answer. The person carries it; anyone can check it; nobody can forge it.
  • Revocation The mechanism by which an organization withdraws a proof it issued, and by which any checker can find out that it did.
  • SD-JWT VC The credential format this cell issues: a signed token whose individual claims can each be withheld or revealed by the person holding it.
  • Selective disclosure Sending one field out of a signed document and leaving the rest behind, without breaking the signature on what you sent.
  • Tamper-evident A change to a signed document can be detected by anyone who checks it. It does not mean the document cannot be changed.
  • The cell The machine that issues, checks and publishes receipts. This site is the human origin; the cell is the machine one, and this site never copies a receipt from it.
  • The consent screen The screen a person sees before anything leaves their phone. It answers five questions: who is asking, what for, exactly what will be sent, what stays, and for how long.
  • The permissionless plane The set of endpoints on this machine that answer without an account, a key or a bill. Checking a proof lives entirely inside it.
  • The phone's security chip A separate piece of hardware inside a phone that can create a signing key and use it, but cannot hand the key out — not to an app, not to the manufacturer, not to us.
  • The register One row per capability: the claim, the state, the thing that proves it, how it was checked, when, and what a capability that does not work yet costs the reader today.
  • Trust anchor The step where a checker decides whether the organization that signed a proof is one it is prepared to believe. A valid signature by an unknown party is still a valid signature by an unknown party.
  • Verifier Anyone who needs to know one thing and checks the signed answer instead of collecting the underlying documents.

Register rows

  • A wallet a person installs from an app store. planned wallet-native
  • Attests the exact commit a running cell was built from live build-provenance
  • Delivers codes and alerts by SMS not-yet sms-delivery
  • Delivers sign-in codes, credential offers, and alerts by email not-yet email-delivery
  • Generates its OpenAPI document from the live route table, never hand-maintained live openapi
  • Isolates every tenant's data in the database itself, not in application code live tenant-isolation
  • Issues and verifies a one-time partner sign-in code partial partner-portal-signin
  • Keeps a tamper-evident, hash-chained audit log of privileged actions, including erasures live audit-trail
  • Lets a person hold an issued credential on their own device partial credential-holding
  • Lets a person or business be found in an opt-in directory not-yet directory
  • Lets an organization sign itself up without an operator not-yet org-signup
  • Proves cryptographically that this domain controls the DID it publishes not-yet domain-linkage
  • Publishes a resolvable did:web trust anchor live trust-anchor-did
  • Publishes a signed, standards-shaped status list a verifier can fetch and check live status-list-published
  • Publishes an RFC 9116 security.txt with a live contact and a rolling expiry live security-disclosure
  • Publishes deterministic vectors a third party can recompute offline to check their implementation against ours live conformance-vectors
  • Publishes OAuth authorization-server metadata for the pre-authorized-code grant live as-metadata
  • Publishes OpenID4VCI issuer metadata naming a live credential type live issuer-metadata
  • Publishes SD-JWT VC issuer metadata at its own well-known path live jwt-vc-issuer-metadata
  • Publishes the wallet-facing manifest for every credential type it can issue live type-manifest
  • Reports readiness per capability — db, signing, issuer identity, verifier identity — not one flattened boolean live readiness
  • Resolves a tenant's own DID document by slug live tenant-did-resolution
  • Runs a real QR sign-in ceremony for a holder account live qr-signin
  • Runs subject-erasure requests with an auditable, provable completion planned erasure
  • Serves a status list at the un-tenanted path as well as the tenant path live untenanted-status
  • Serves the whole verification plane without authentication, by construction rather than by policy live open-rail

What this box does not do.

This search reads route labels, glossary terms and aliases, and register claims — not the paragraph text of every page. A full-text index over every word this site has ever published is a different, larger thing, and the register has no row for it because it has not been built.

The register holds 17 live · 2 partial · 2 planned · 5 not yet.

1 of the 1 capabilities this page depends on have no row in the register yet, so this page will not print a state for them. They are named rather than dropped, because a slice that silently shortens itself is the same defect as a claim with no receipt.

  • full-text-site-search

The register route serves, but it carries no row for these yet. List what it does carry:

curl -s https://id.orbis.id/api/site/register | jq -r '.entries[].slug'

A search box that only searches titles is not lying. It just has to say so.

Straight answers.

Does this search read the words inside each page?
No — it searches page titles, glossary terms and their definitions, and register claims. It does not currently search the body paragraphs of every page; see the gap above.
Does typing here send a request anywhere?
No. Every row is already in this document; the box only hides the ones that do not match.

Do not trust us. Check us.