The easiest way to create, manage and join open source communities.

A terminal tool for communities where membership is something you can prove. You hold your own identity, members vouch for each other with signed credentials, and every community sets its own rules for who gets in.

cargo install openvtc

An LF Decentralized Trust Labs project
Built by Affinidi with the First Person Cooperative

OpenVTC                 Account: alice@vta
Communities             [+] Join        (2) !
* Acme Robotics   o Active   since 2026-03-01   >
  Open Source WG  ~ Pending  requested 2d ago ! >
* City DAO        o Active   since 2025-11-12   >
  Old Guild       - Left     (read-only)        >
  Trial Net       x Rejected acknowledge?     ! >
↑↓ select  ⏎ open  s star  j join  a/d archive

The Communities hub, with example names.

get openvtc

  1. Install Rust

    OpenVTC needs Rust 1.95 or newer. Already have it? Run rustup update.

    curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh
  2. Install OpenVTC

    Builds and installs the openvtc binary from crates.io.

    cargo install openvtc
  3. Get a VTA

    Your Verifiable Trust Agent holds your keys and credentials. The easiest way to start is the VTA farm, which hosts one for development and testing. Keep its DID handy. Prefer to run your own? See below.

  4. Run setup, then launch

    The setup wizard connects OpenVTC to your VTA and protects your account. After that, openvtc opens the TUI.

    openvtc setup
    openvtc

get a vta

A VTA is your digital twin that you actually own. It keeps your keys, holds your credentials, presents only what you agree to, and can say no on your behalf. OpenVTC needs one to work.

easiest way to start

The VTA farm

The First Person VTA farm hosts a VTA for you in a few minutes. There's nothing to build and no server to run, so it's the quickest way to try OpenVTC for development and testing.

Open the VTA farm →

Want to operate your own VTA?

When you're ready to hold your real identity, run the VTA yourself. It's open source: build it from the verifiable-trust-infrastructure repo and run it on your own machine or server.

git clone https://github.com/OpenVTC/verifiable-trust-infrastructure
cd verifiable-trust-infrastructure
cargo run --locked --package vta-service --features setup -- setup

The setup wizard creates your VTA's keys and config. The cold-start guide covers the rest. Keep --locked: the workspace only builds with its pinned dependencies.

what is openvtc

OpenVTC stands for Open Verifiable Trust Communities. It is a command-line tool, with a full terminal UI, for joining and running communities where membership is something you can prove.

Today an open source project knows its contributors as a list of usernames on someone else's platform. With OpenVTC each person holds their own identifier and keys, members vouch for each other with signed credentials, and the community decides who belongs through rules everyone can check. Maintainers get a real answer to "who wrote this, and who vouches for them?" Contributors keep their reputation when they move between projects.

Members talk to each other and to their communities over two open, end-to-end encrypted protocols: DIDComm and the Trust Spanning Protocol (TSP) from Trust over IP. Both run between DIDs, so no central server sits in the middle of your conversations.

It follows the First Person Project model, and is part of LF Decentralized Trust Labs at the Linux Foundation.

  1. VTAVerifiable Trust Agent

    Your agent. It holds your keys and credentials, presents only what you agree to, and can say no on your behalf.

  2. VTCVerifiable Trust Community

    The community's service. It decides who belongs, issues membership and roles, and keeps its own governance.

  3. OpenVTCThe part you drive

    One account, many communities, from your terminal. Join, vouch, get vouched for, and sign your work.

the trust graph

Make the relationship the thing that carries proof.

nodes = identifiers you control

Not an account on someone's server. An identifier that resolves to your own public keys, that you hold, and that nobody can delete you out of.

edges = signed statements

"I am a member of this community." "I know this person." Each one signed by whoever makes the claim, and checkable by anyone who receives it.

Decentralized Trust Graph (DTG)

Put those nodes and edges together and you get a Decentralized Trust Graph: a graph of trust relationships between people, organisations, devices and AI agents in which every node and every edge can be verified. The DTG Credentials specification from the Trust over IP DTG Working Group defines the credential types that build it. OpenVTC uses them for everything a community does.

VRC
relationship · "we know each other", signed by both sides
VMC
membership · you belong to this community, and it agrees
VIC
invitation · lets a newcomer onboard
VPC
persona · links a persona to a relationship
VSC
statement · endorsements and witnessed edges
VDC
delegation · someone may act in your name, for set tasks
VAC
authority · what you may do, and you can hand on less

What it enables

  • Prove you belong without saying who you are. Zero-knowledge proofs of membership and personhood keep you uncorrelated across communities.

  • Know who is behind a commit. Follow the edges from a signature to the people who vouch for its author.

  • Give AI agents bounded authority. Delegate a narrow slice of what you can do, then take it back.

  • Check both questions. "Was this claim really made?" is a signature check anyone can run offline. "Is it still true?" is a live question for the community's trust registry.

Read the DTG spec →

why it's different

01

A community of two already works

The first wave of self-sovereign identity waited for someone to issue everyone a credential. OpenVTC starts from who you already know, so a community can begin with two people vouching for each other.

02

One account, many communities

Join a foundation, a working group and a side project from the same account. Each runs its own live session, so an outage in one never blocks the others.

03

A separate identity per community

Mint a fresh identity for each community you join, or reuse one on purpose. OpenVTC warns you when reuse would link you across communities.

04

Rules you can read and test

Joining, leaving and role changes run through the community's own policy. It denies by default and can be tried out in a simulator before it goes live.

05

DIDComm and TSP, side by side

Pick the transport per relationship. Both are open standards with end-to-end encryption and sender authentication, and OpenVTC shows your TSP relationships next to your DIDComm ones.

06

Sign your git commits with your DID

did-git-sign signs commits with the same identity your community already trusts, so a signature leads back to a person someone vouches for.

Also: your terminal, your colours. Built-in themes, plus import from Omarchy, Neovim, base16, Alacritty, Kitty and Ghostty. Try a few at the bottom of this page.

the verifiable trust infrastructure (vti)

OpenVTC is one tool in a wider open source ecosystem: the Verifiable Trust Infrastructure (VTI). Agents, communities and the clients that drive them all speak the same DIDs, DIDComm, TSP and DTG credentials, so you can mix them freely.

terminal

OpenVTC

The community member's tool: join communities, vouch and get vouched for, manage identities, all from a terminal UI.

cargo install openvtc
OpenVTC/openvtc →
browser

VTA browser plugin

Manage your VTA from the browser and sign in to sites as your DID with a passkey. Your DID's private keys never leave the VTA, and it reaches a private VTA over DIDComm through a mediator.

beta Open testing. Not in the Chrome Web Store yet: install from source as an unpacked extension.

OpenVTC/vta-browser-plugin →
terminal

PNM CLI

Personal Network Manager. Manage one personal VTA from the command line, with a simple non-interactive setup. Good for scripts and servers.

cargo install pnm-cli
pnm-cli →
terminal

CNM CLI

Community Network Manager. The operator's tool for a VTA: authentication, key management, access control and multi-community support.

cargo install cnm-cli
cnm-cli →
mobile wallet

Keyring

A portable, privacy-preserving identity wallet. Prove device ownership with on-device biometrics, verify relationships phone to phone, and share identity data without a third party. Built on the same DTG credential specifications as OpenVTC.

By Harvard's Applied Technology Lab. beta Open testing via Google Play and TestFlight.

QR code: Keyring for Android on Google Play
Android
QR code: Keyring for iOS on TestFlight
iOS
Project page → Repository →
git

did-git-sign

Sign git commits with your DID's Ed25519 key, held in your VTA. The same identity your community trusts, on every commit.

How it works →

for community owners

Run your open source community on your own terms. OpenVTC gives you the tools; you decide how they're used.

Run your own community

Membership, governance, permissions and roles in one place, all expressed as verifiable credentials on the trust graph. Share administration across several admins, with optional M-of-N approval for policy changes.

works withGitHubCodebergForgejo

Data rooms and shared memory

Give the community a data room: a shared space that both your developers and their AI tools can read and write, with access granted by credential. A room has its own DID and can move to a new host without reissuing anything.

Humans and AI agents, each with their own policy

People and AI agents are separate entities, each with its own identity. You set what each one may do, and an agent only ever gets a narrow slice of the authority of the person it works for.

You set the rules for joining

Joining runs through your community's policy, so you decide what it takes to get in, from truly open to highly protected. Change the rules any time; every change is signed and can be rolled back.

  1. open to all
  2. invitation
  3. admin approval
  4. member vetting
  5. hidden vetters (ZKP)
Start your own community →

security & privacy

Secure and private for the developer and for the community, built on self-sovereign identity principles.

post-quantum

Ready for quantum computers

Credentials can carry ML-DSA post-quantum signatures alongside Ed25519, and TSP adds an optional hybrid ML-KEM-768 + X25519 mode. Signatures made today stay trustworthy tomorrow.

zero-knowledge

Predicate Credential System

Prove that k different members have vouched for you without revealing which members they were. The community can count the vouches; nobody can tell who made them. This is what powers hidden-vetter admission.

OpenVTC/predicate-credential-system →

For developers

  • You hold your keys. Your identity lives in your own VTA, not in a platform account.

  • Nobody can follow you around. A separate identity per community stops anyone linking your memberships together.

  • Share only what's asked. Selective disclosure, a consent record for every disclosure, and an agent that cannot be asked to list everything it holds.

  • Endorsements are yours. An endorsement is a signed credential you carry, so your reputation moves with you between projects.

For communities

  • Fully independent. Each community runs its own service with its own identity, policy and governance. There is no central operator to depend on.

  • Endorsement permissions. Your policy decides who may endorse what, and what an endorsement unlocks, from a contributor role to commit rights.

  • Vetting you can count. Existing members vet newcomers and sign vetting statements. The community checks there are enough without publishing who vouched for whom.

  • Governance on the record. Every policy change goes into an append-only signed log, with rollback and optional M-of-N approval.

$ openvtc --what-next

This is just the beginning.

your identity. your community. your data. your code.

Own those four and everything built on top of them is yours to decide: who you work with, what you share, which agents act for you, and what your community becomes. OpenVTC is the first piece. Come build the rest.