Prime Identity  ·  Proof  ·  Check a DID

Check any DID

Resolve it, read its keys, verify its signature, and test whether its key is anchored in DNSSEC. Everything runs in your browser.

Try:
Other organizations:

      What the levels mean

      LevelWhat it proves
      1. ResolvesThe identifier is well formed and its DID document can be retrieved, and the document says it belongs to this DID.
      2. Usable keysThe document lists at least one public key in a form this checker can read.
      3. Signed documentThe document carries a Data Integrity proof (eddsa-jcs-2022) that verifies, and hasn't expired. For did:key this is not needed: the identifier is the key.
      4. Anchored in DNSSECFor did:web: the domain publishes the DID and its key in DNSSEC-signed _did records (IETF draft-carter-high-assurance-dids-with-dns). Google and Cloudflare both return the same records, both validate them, the chain of keys links back to the DNS root, and the key on the website matches the key in DNS. The website alone can then no longer lie about who the identity is.

      A Prime Identity (PrID) is built to reach all four levels. Most DIDs in use today stop at level 1 or 2. That doesn't make them invalid; it tells you how much you're trusting the web server that hosts them.

      How the check works, and what it trusts

      Your browser fetches the DID document directly from its host and asks two public resolvers, Google Public DNS (8.8.8.8) and Cloudflare (1.1.1.1), over DNS-over-HTTPS. Every DNS answer must be DNSSEC-validated by both, and the two must agree record for record. The checker then follows the chain of DNSSEC keys from the IANA root trust anchor down to the identity's zone, and does every signature check itself with your browser's built-in cryptography.

      What it relies on: that Google and Cloudflare verify the DNSSEC signatures correctly (that is what their "validated" flag attests), and that they aren't both wrong the same way at once. The key-chain linkage back to the root is recomputed here, independently of them. Nothing you enter is sent to us: this page has no server side and no analytics.

      Supported identifiers

      Some web servers don't allow browsers to read their DID document from another site (no CORS header). When that happens the page says so. It is a setting on that server, not proof that the DID is invalid.

      prdid.com demonstration identities (demo, gestalt, tribernachi, lydian) are demonstrations with throwaway keys, not production PrIDs.