Liir for developers
You opened the page source and found words nobody explained.
Doors, knocks, Liirlits, custody, attestation, agents. Here are the five
of them, in plain words, and then where the code and the doors are.
1 · The name and the mark
A Liir is a name at liir.net. david@liir.net is one.
Its public document sits at https://liir.net/david/did.json:
the keys, with their history, and the claims that name has published.
No key and no header are needed to read it.
The mark is a Liirlit. It is the name drawn as rings of beads by a
public codec: liir.js, function
encode(name, tier, armor, realm), then drawMark.
Every mark on this site is drawn live in the browser from the name.
Nothing about a person is in the mark but the name.
2 · The key
Sign-in is a passkey. WebAuthn. There is no password anywhere.
Registration offers ES256 and Ed25519 only. RSA is refused, because a
Windows Hello passkey holding an RSA key cannot hand out the vault
secret at sign-in.
The vault's daily key is derived from the passkey's PRF extension. A
key that lives on a phone or in a browser's passkey store follows the
person. A key held on one machine stays on that machine. Second keys are
let into the vault from the account page.
3 · Mail and doors
Every letter between two Liirs, and every letter from a Liir to the
outside, leaves through a private address called a door. One door per
relationship.
word-word-word-00000@liir.net
A first letter to a Liir you are not paired with arrives as a knock. It
lands in the Knocks room, and the reader decides whether to open.
A worn nameplate, word-0000, is a face over the door. The
reader shows the nameplate. The door stays under “Show
headers”.
An outside sender gets a doorway bound to that sender's domain or
address. Close the doorway and that mail stops.
The mail server is Stalwart. The app speaks JMAP to it, same origin, at
/jmap. The wire for mail apps is mail.liir.net: IMAP 993, submission 465, POP3 995, all
reachable from outside. No door hands a person a mail password, so those ports
serve paired devices once device pairing ships.
4 · The vault
Sealed on the client. The server holds ciphertext and arithmetic: the
per-item cap, the plan's ceiling, soft delete.
The root key is wrapped twice. Under the passkey's PRF secret, for the
day. Under three recovery cards, any two of which open it, for the bad
day.
The server never holds a readable byte, and there is no server-side
decrypt path. That is the design, not a setting.
5 · Agents
An agent creates its own Liir through its own ceremony, at its own
host. There is no human signup form in that path. The agent answers one
question, names itself, and is born at liir.tv. The person who runs the
agent holds the recovery cards, as operator. The first agent born this
way is named Fable, at fable@liir.tv.
Pairing with a person starts with a short key the person mints.
word-word-00
Nothing is accepted until the person presses accept with the person's
own key. Then both sides sign a private statement: operates
on one side, operated_by on the other. The format is
liir-attest/1 over RFC 8785 canonical JSON, proved with
WebAuthn or Ed25519, and stamped with a registry time receipt,
liir-proof-time/1.
Publishing a statement is a separate act. Powers, which we call grants,
are designed and not built yet.
Where things are
- The registry's public doors.
GET /<name>/did.json
for a name's document. GET /.well-known/liir-registry.json
for the registry's signing key. POST /api/claim/check {handle}
to ask whether a name is free. It refuses names that put liir or thiir
beside official, support, admin, staff, security, or billing.
- The mark codec.
https://liir.net/liir.js. Pages load it
under a hashed name. In the repo the file is net/liir.js.
- Mail.
mail.liir.net, IMAP 993, submission 465, POP3 995, and JMAP at
https://liir.net/jmap.
- What is built and what is only designed. The repo carries a list of
every truth the site must show, checked against the live site.
- Words at /glossary. How it works for people
at /how. Agents at /agents.
Every door listed here answers a plain fetch, with no key
and no account.