Carry your standing, not your data
An agent arriving at Mages City presents the count and the root; the City re-derives the key's κ, its identifier and the signed record, and never sees the items.
The Star is a picture — a content-addressed geometric figure — that holds your keys, the relationships others have signed with you, and the walks you have taken through a body of knowledge. Any verifier can re-derive every claim in it from the bytes. No verifier can forge one. You choose what folds into the picture that crosses to someone else.
Two sentences travel with it everywhere: appearance is not identity — a visible Star grants nothing — and the geometry is a reading, never an authority.
prior chains lineage; unknown fields survive the round trip. Three independent verifiers agree byte for byte, one of them written by another house from the published rule.521 bytesdisclosed to a verifier by a Hold presentation, where the no-proof route discloses 2,529 and the Hold retains 6,478. Measured under a frozen verifier-requirements census, not argued. The counting rule →
An agent arriving at Mages City presents the count and the root; the City re-derives the key's κ, its identifier and the signed record, and never sees the items.
Choose a scheme and watch its bytes fold into the figure. The lab's contribution to the PQC migration conversation is a picture, and it is exact. Try it ↗
Two Stars learn their intersection and nothing more. Try it ↗
A presentation binds to a community's root; a second root is the test that two showings cannot be linked.
The Star as the identity surface an agent wears over its VTA, with capabilities narrowed to exactly what it does.
A reading is a name, a palette and a set of lit states — the tier at which a knowledge packet can be offered without its body.
The core artefact at the centre of the figure is the face a holder shows in one context; worlds wear a colour on the ring.
Disclosure debt, the dated boundary and the observer's fiber are measurements the figure can show and the lab can repeat.
The rooms boot as a content-addressed environment of their own. The standalone rooms ↗
Star ↗Lattice ↗Signatures ↗Sigil ↗Skye ↗
The key is minted at agentprivacy.ai/city, explored on Soulbis, and read at Mages City. The rooms are the instrument; the lab keeps the measurements; the City is the first verifier.
Inspect a local City Key, derive its κ and export a selected reading. No extension needed; the file never leaves this page.
Open the Star Key reader →Download a synthetic practice key
The reader does not verify identity or grant access. Its artwork is illustrative; compact JSON is not a proof.
Every item in the Hold is a signed relationship or a signed act toward one: a membership, a vouch, a relationship record, a trust task. The Star verifies each item locally, records its state — valid, invalid, unsupported, unavailable — and measures its bytes against the same budget the signatures room draws. The key carries only the root and the count. A verifier that receives the key learns how much is held and can check the root against a presentation; it learns nothing about who signed what.
The first verb of the runtime is relate, not add: an item enters only after it verifies, and a bearer cannot relate itself. present answers honestly that it is not available, and names what is missing.
Built on OpenVTC's verifiable trust infrastructure and the Trust over IP DTG credential and ZKP work; content addressing after UOR; the verify foot of the Hold re-implemented by the House of Archon. Updated 21 September 2026. The need profile → · Experiment history →