A terminal tool for communities where membership is something you can prove. You hold your own identity, members vouch for each other with signed credentials, and every community sets its own rules for who gets in.
An LF Decentralized Trust Labs project
Built by Affinidi with the First Person Cooperative
OpenVTC Account: alice@vta Communities [+] Join (2) !
* Acme Robotics o Active since 2026-03-01 > Open Source WG ~ Pending requested 2d ago ! > * City DAO o Active since 2025-11-12 > Old Guild - Left (read-only) > Trial Net x Rejected acknowledge? ! >
↑↓ select ⏎ open s star j join a/d archive
The Communities hub, with example names.
OpenVTC needs Rust 1.95 or newer. Already have it? Run rustup update.
curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | shBuilds and installs the openvtc binary from crates.io.
cargo install openvtcYour Verifiable Trust Agent holds your keys and credentials. The easiest way to start is the VTA farm, which hosts one for development and testing. Keep its DID handy. Prefer to run your own? See below.
The setup wizard connects OpenVTC to your VTA and protects your account. After that, openvtc opens the TUI.
openvtc setupopenvtcA VTA is your digital twin that you actually own. It keeps your keys, holds your credentials, presents only what you agree to, and can say no on your behalf. OpenVTC needs one to work.
The First Person VTA farm hosts a VTA for you in a few minutes. There's nothing to build and no server to run, so it's the quickest way to try OpenVTC for development and testing.
When you're ready to hold your real identity, run the VTA yourself. It's open source: build it from the verifiable-trust-infrastructure repo and run it on your own machine or server.
git clone https://github.com/OpenVTC/verifiable-trust-infrastructurecd verifiable-trust-infrastructurecargo run --locked --package vta-service --features setup -- setupThe setup wizard creates your VTA's keys and config. The cold-start guide covers the rest. Keep --locked: the workspace only builds with its pinned dependencies.
OpenVTC stands for Open Verifiable Trust Communities. It is a command-line tool, with a full terminal UI, for joining and running communities where membership is something you can prove.
Today an open source project knows its contributors as a list of usernames on someone else's platform. With OpenVTC each person holds their own identifier and keys, members vouch for each other with signed credentials, and the community decides who belongs through rules everyone can check. Maintainers get a real answer to "who wrote this, and who vouches for them?" Contributors keep their reputation when they move between projects.
Members talk to each other and to their communities over two open, end-to-end encrypted protocols: DIDComm and the Trust Spanning Protocol (TSP) from Trust over IP. Both run between DIDs, so no central server sits in the middle of your conversations.
It follows the First Person Project model, and is part of LF Decentralized Trust Labs at the Linux Foundation.
Your agent. It holds your keys and credentials, presents only what you agree to, and can say no on your behalf.
The community's service. It decides who belongs, issues membership and roles, and keeps its own governance.
One account, many communities, from your terminal. Join, vouch, get vouched for, and sign your work.
Make the relationship the thing that carries proof.
Not an account on someone's server. An identifier that resolves to your own public keys, that you hold, and that nobody can delete you out of.
"I am a member of this community." "I know this person." Each one signed by whoever makes the claim, and checkable by anyone who receives it.
Put those nodes and edges together and you get a Decentralized Trust Graph: a graph of trust relationships between people, organisations, devices and AI agents in which every node and every edge can be verified. The DTG Credentials specification from the Trust over IP DTG Working Group defines the credential types that build it. OpenVTC uses them for everything a community does.
Prove you belong without saying who you are. Zero-knowledge proofs of membership and personhood keep you uncorrelated across communities.
Know who is behind a commit. Follow the edges from a signature to the people who vouch for its author.
Give AI agents bounded authority. Delegate a narrow slice of what you can do, then take it back.
Check both questions. "Was this claim really made?" is a signature check anyone can run offline. "Is it still true?" is a live question for the community's trust registry.
The first wave of self-sovereign identity waited for someone to issue everyone a credential. OpenVTC starts from who you already know, so a community can begin with two people vouching for each other.
Join a foundation, a working group and a side project from the same account. Each runs its own live session, so an outage in one never blocks the others.
Mint a fresh identity for each community you join, or reuse one on purpose. OpenVTC warns you when reuse would link you across communities.
Joining, leaving and role changes run through the community's own policy. It denies by default and can be tried out in a simulator before it goes live.
Pick the transport per relationship. Both are open standards with end-to-end encryption and sender authentication, and OpenVTC shows your TSP relationships next to your DIDComm ones.
did-git-sign signs commits with the same identity your community already trusts, so a signature leads back to a person someone vouches for.
Also: your terminal, your colours. Built-in themes, plus import from Omarchy, Neovim, base16, Alacritty, Kitty and Ghostty. Try a few at the bottom of this page.
OpenVTC is one tool in a wider open source ecosystem: the Verifiable Trust Infrastructure (VTI). Agents, communities and the clients that drive them all speak the same DIDs, DIDComm, TSP and DTG credentials, so you can mix them freely.
The community member's tool: join communities, vouch and get vouched for, manage identities, all from a terminal UI.
cargo install openvtcManage your VTA from the browser and sign in to sites as your DID with a passkey. Your DID's private keys never leave the VTA, and it reaches a private VTA over DIDComm through a mediator.
beta Open testing. Not in the Chrome Web Store yet: install from source as an unpacked extension.
OpenVTC/vta-browser-plugin →Personal Network Manager. Manage one personal VTA from the command line, with a simple non-interactive setup. Good for scripts and servers.
cargo install pnm-cliCommunity Network Manager. The operator's tool for a VTA: authentication, key management, access control and multi-community support.
cargo install cnm-cliA portable, privacy-preserving identity wallet. Prove device ownership with on-device biometrics, verify relationships phone to phone, and share identity data without a third party. Built on the same DTG credential specifications as OpenVTC.
By Harvard's Applied Technology Lab. beta Open testing via Google Play and TestFlight.
Sign git commits with your DID's Ed25519 key, held in your VTA. The same identity your community trusts, on every commit.
How it works →Run your open source community on your own terms. OpenVTC gives you the tools; you decide how they're used.
Membership, governance, permissions and roles in one place, all expressed as verifiable credentials on the trust graph. Share administration across several admins, with optional M-of-N approval for policy changes.
Give the community a data room: a shared space that both your developers and their AI tools can read and write, with access granted by credential. A room has its own DID and can move to a new host without reissuing anything.
People and AI agents are separate entities, each with its own identity. You set what each one may do, and an agent only ever gets a narrow slice of the authority of the person it works for.
Joining runs through your community's policy, so you decide what it takes to get in, from truly open to highly protected. Change the rules any time; every change is signed and can be rolled back.
Secure and private for the developer and for the community, built on self-sovereign identity principles.
Credentials can carry ML-DSA post-quantum signatures alongside Ed25519, and TSP adds an optional hybrid ML-KEM-768 + X25519 mode. Signatures made today stay trustworthy tomorrow.
Prove that k different members have vouched for you without revealing which members they were. The community can count the vouches; nobody can tell who made them. This is what powers hidden-vetter admission.
OpenVTC/predicate-credential-system →You hold your keys. Your identity lives in your own VTA, not in a platform account.
Nobody can follow you around. A separate identity per community stops anyone linking your memberships together.
Share only what's asked. Selective disclosure, a consent record for every disclosure, and an agent that cannot be asked to list everything it holds.
Endorsements are yours. An endorsement is a signed credential you carry, so your reputation moves with you between projects.
Fully independent. Each community runs its own service with its own identity, policy and governance. There is no central operator to depend on.
Endorsement permissions. Your policy decides who may endorse what, and what an endorsement unlocks, from a contributor role to commit rights.
Vetting you can count. Existing members vet newcomers and sign vetting statements. The community checks there are enough without publishing who vouched for whom.
Governance on the record. Every policy change goes into an append-only signed log, with rollback and optional M-of-N approval.
$ openvtc --what-next
your identity. your community. your data. your code.
Own those four and everything built on top of them is yours to decide: who you work with, what you share, which agents act for you, and what your community becomes. OpenVTC is the first piece. Come build the rest.