# Concepts

> Concept pages covering WebVH Hosting's service identity, DID lifecycle, access control, and hosting domains.

The mental model behind WebVH Hosting: how services get and rotate their own identity, how a hosted DID moves through its lifecycle, how domains are served, and who can do what. Read these alongside the [Quickstart](/products/affinidi-elements/webvh-hosting/get-started.md), or come back to them when you need to know why something behaves the way it does.

| Concept | What it explains |
| [DID lifecycle](/products/affinidi-elements/webvh-hosting/concepts/did-lifecycle.md) | The stages a hosted DID goes through, from reservation and publishing to sync, resolution, rollback, transfer, and deletion, and who owns and signs it. |
| [Hosting domains](/products/affinidi-elements/webvh-hosting/concepts/hosting-domains.md) | How one deployment serves DIDs on several domains, how the domain for a new DID is chosen, and what disabling or purging a domain does. |
| [Service identity](/products/affinidi-elements/webvh-hosting/concepts/identity.md) | Which services hold their own did:webvh identifier, which keys it carries, how it is provisioned, and how its keys rotate without cutting off peers. Self-hosted detail. |
| [Roles and access](/products/affinidi-elements/webvh-hosting/concepts/roles-and-access.md) | How callers authenticate, what the Admin, Owner, and Service roles can each do, how owners are limited to domains and quotas, and how sessions expire. Applies to self-hosted deployments. On the appliance, you manage access in your VTA. |

## Pages in this section
- [DID lifecycle](/products/affinidi-elements/webvh-hosting/concepts/did-lifecycle.md): The stages a hosted did:webvh identifier goes through, from path reservation and publishing to sync, resolution, disabling, rollback, transfer, and deletion, and who owns and signs it at each stage.
- [Hosting domains](/products/affinidi-elements/webvh-hosting/concepts/hosting-domains.md): What a hosting domain is, how one WebVH Hosting deployment serves DIDs on several domains, how the default domain and per-owner domain scopes are chosen, and what disabling or purging a domain does.
- [Service identity](/products/affinidi-elements/webvh-hosting/concepts/identity.md): Which WebVH Hosting services hold their own did:webvh identifier, which keys each identity carries, how that identity is provisioned, and how its keys rotate without cutting off peers.
- [Roles and access](/products/affinidi-elements/webvh-hosting/concepts/roles-and-access.md): How callers authenticate to a WebVH Hosting control plane, what the Admin, Owner, and Service roles can each do, how ACL entries scope owners to domains and quotas, and how sessions expire.

