Overview

What WebVH Hosting is, what you can do with it, how it works alongside your VTA, how you deploy it, and which guide to start from.

A did:webvh identifier is a DID whose full history lives in a signed log file, did.jsonl, served from a web address. Anyone can fetch that log and verify every change back to the DID’s creation, so the DID has to stay online at a stable URL for as long as it is in use.

WebVH Hosting is that stable home. Your VTA creates each DID, holds its keys, and signs every version of its log. The appliance checks each signed version, stores it, and serves it on its own domain.

With the Affinidi-hosted appliance, Affinidi runs the hosting infrastructure, and you work through Affinidi Portal and your VTA. Deploy on Affinidi Portal →

How a hosted DID maps to its URL

Every hosted DID encodes where it resolves: its domain and path form the public URL of its log.

Hosted DIDdid:webvh:Q1abc…:did.example.com:my-servicemethodself-certifying IDyour appliance's domainpath on the appliancePublic URL of its loghttps://did.example.com/my-service/did.jsonlAffinidi-hosted:the domain is the host of your appliance's WebVH URL in Affinidi Portal.

What you can do with WebVH Hosting

CapabilityWhat it means in practice
Publish DIDs at a stable public URLEach DID resolves at https://<domain>/<path>/did.jsonl, where the domain is your appliance’s and the path is one you choose or one the appliance generates.
Keep every version verifiableBefore storing a new version, the appliance validates the whole log: every signature, the hash chain between entries, and pre-rotation key rules. A log that fails is refused.
Host without holding keysThe appliance stores and serves signed logs only. Your VTA keeps every DID’s private keys, so creating, updating, and deleting a DID always goes through your VTA.
Serve human-readable namesWhen your VTA binds an agent name such as alice to a DID, the appliance reserves the name on its domain and redirects /@alice to the DID.
Serve DIDComm endpointsThe appliance serves whatever service endpoints your VTA writes into the DID document, such as your mediator for DIDComm messaging.

How it works

  1. Your VTA creates the DID. It generates the keys, builds the DID document, and signs the first log entry.
  2. The appliance publishes it. Your VTA reserves a path on the appliance and sends the signed log. The appliance validates it and stores it as the source of truth.
  3. Anyone resolves it. The appliance’s public edge serves the log at the DID’s URL, and resolvers verify it themselves.
  4. Updates follow the same path. Each update is a new signed log entry from your VTA. The appliance validates the longer log and serves the new version.
WebVH Hosting applianceYour VTAcreates and signsControl planevalidates and storesEdge serverserves the DIDAnyoneresolves and verifiessigned logsyncfetchesKeys stay with your VTA:it holds the keys and signs every version of the log.Every version is checked:the appliance validates each signed log before it stores and serves it.

WebVH Hosting splits this work between two services:

ServiceWhat it does
Control planeReceives signed logs from your VTA, validates and stores them, and syncs every change to the edge servers. It is the source of truth for every hosted DID.
Edge serverServes each DID’s log and agent-name redirects at the DID’s public URL. It serves only what the control plane has synced to it.

For the full sequence, including what the appliance checks and what deletion removes, see DID lifecycle.

Deployment options

OptionHow it works
Affinidi-hosted appliance (recommended)Affinidi provisions, runs, and maintains the appliance. It serves your DIDs on its own domain, shown as WebVH URL in Affinidi Portal.
Self-hostedYou build and run the open-source services on your own infrastructure, as a single unified daemon or as separate services.

How you work with the appliance

ToolWhat you use it for
Affinidi PortalCreate and activate the appliance, and find its Server DID and WebVH URL.
Personal Network Manager (PNM) CLIRegister the appliance with your Verifiable Trust Agent (VTA), then create, update, and delete DIDs and manage agent names.

Find your use case

If you need to…Start here
Set up a hosting applianceDeploy WebVH Hosting appliance
Connect the appliance to your VTA and publish your first DIDCreate your first hosted DID
Create, inspect, update, and delete DIDsCreate and manage DIDs
Give a DID a human-readable /@nameGive a DID a human-readable name
Let other parties send a DID DIDComm messagesMake a DID reachable over DIDComm
Fix a DID that does not resolveTroubleshoot DID resolution

Get started

Deploy on Affinidi Portal → to have Affinidi run the appliance for you.

To run the services on your own infrastructure instead, see Self-hosted (open source): unified daemon or Self-hosted (open source): standalone services.