# Overview

> What WebVH Hosting is, what you can do with it, how it works alongside your VTA, how you deploy it, and which guide to start from.

A [did:webvh](https://didwebvh.info/latest/specification/) identifier is a DID whose full history lives in a signed log file, did.jsonl, served from a web address. Anyone can fetch that log and verify every change back to the DID’s creation, so the DID has to stay online at a stable URL for as long as it is in use.

WebVH Hosting is that stable home. Your VTA creates each DID, holds its keys, and signs every version of its log. The appliance checks each signed version, stores it, and serves it on its own domain.

With the Affinidi-hosted appliance, Affinidi runs the hosting infrastructure, and you work through Affinidi Portal and your VTA. [Deploy on Affinidi Portal →](/products/affinidi-elements/webvh-hosting/get-started/webvh-affinidi-portal.md)

## How a hosted DID maps to its URL

Every hosted DID encodes where it resolves: its domain and path form the public URL of its log.

## What you can do with WebVH Hosting

| Capability | What it means in practice |
| Publish DIDs at a stable public URL | Each DID resolves at https://<domain>/<path>/did.jsonl, where the domain is your appliance’s and the path is one you choose or one the appliance generates. |
| Keep every version verifiable | Before storing a new version, the appliance validates the whole log: every signature, the hash chain between entries, and pre-rotation key rules. A log that fails is refused. |
| Host without holding keys | The appliance stores and serves signed logs only. Your VTA keeps every DID’s private keys, so creating, updating, and deleting a DID always goes through your VTA. |
| Serve human-readable names | When your VTA binds an agent name such as alice to a DID, the appliance reserves the name on its domain and redirects /@alice to the DID. |
| Serve DIDComm endpoints | The appliance serves whatever service endpoints your VTA writes into the DID document, such as your mediator for DIDComm messaging. |

## How it works

- Your VTA creates the DID. It generates the keys, builds the DID document, and signs the first log entry.

- The appliance publishes it. Your VTA reserves a path on the appliance and sends the signed log. The appliance validates it and stores it as the source of truth.

- Anyone resolves it. The appliance’s public edge serves the log at the DID’s URL, and resolvers verify it themselves.

- Updates follow the same path. Each update is a new signed log entry from your VTA. The appliance validates the longer log and serves the new version.

WebVH Hosting splits this work between two services:

| Service | What it does |
| Control plane | Receives signed logs from your VTA, validates and stores them, and syncs every change to the edge servers. It is the source of truth for every hosted DID. |
| Edge server | Serves each DID’s log and agent-name redirects at the DID’s public URL. It serves only what the control plane has synced to it. |

For the full sequence, including what the appliance checks and what deletion removes, see [DID lifecycle](/products/affinidi-elements/webvh-hosting/concepts/did-lifecycle.md).

## Deployment options

| Option | How it works |
| Affinidi-hosted appliance (recommended) | Affinidi provisions, runs, and maintains the appliance. It serves your DIDs on its own domain, shown as WebVH URL in Affinidi Portal. |
| Self-hosted | You build and run the open-source services on your own infrastructure, as a single unified daemon or as separate services. |

## How you work with the appliance

| Tool | What you use it for |
| Affinidi Portal | Create and activate the appliance, and find its Server DID and WebVH URL. |
| Personal Network Manager (PNM) CLI | Register the appliance with your [Verifiable Trust Agent (VTA)](/products/affinidi-elements/vta.md), then create, update, and delete DIDs and manage agent names. |

## Find your use case

| If you need to… | Start here |
| Set up a hosting appliance | [Deploy WebVH Hosting appliance](/products/affinidi-elements/webvh-hosting/get-started/webvh-affinidi-portal.md) |
| Connect the appliance to your VTA and publish your first DID | [Create your first hosted DID](/products/affinidi-elements/webvh-hosting/get-started/create-your-first-did.md) |
| Create, inspect, update, and delete DIDs | [Create and manage DIDs](/products/affinidi-elements/webvh-hosting/webvh-management/did-management.md) |
| Give a DID a human-readable /@name | [Give a DID a human-readable name](/products/affinidi-elements/webvh-hosting/webvh-management/agent-names.md) |
| Let other parties send a DID DIDComm messages | [Make a DID reachable over DIDComm](/products/affinidi-elements/webvh-hosting/webvh-management/didcomm-endpoint.md) |
| Fix a DID that does not resolve | [Troubleshoot DID resolution](/products/affinidi-elements/webvh-hosting/webvh-management/troubleshoot-resolution.md) |

## Get started

[Deploy on Affinidi Portal →](/products/affinidi-elements/webvh-hosting/get-started/webvh-affinidi-portal.md) to have Affinidi run the appliance for you.

To run the services on your own infrastructure instead, see [Self-hosted (open source): unified daemon](/products/affinidi-elements/webvh-hosting/get-started/daemon-unified.md) or [Self-hosted (open source): standalone services](/products/affinidi-elements/webvh-hosting/get-started/standalone-distributed.md).
