Holon VC documentation¶
Issue, selectively disclose, present, and verify attributed Holon assertions with a Rust library and CLI.
Holon VC separates signature validity, DID authorization, issuer trust, credential status, and supporting evidence. A valid signature authenticates an assertion; it does not establish that the assertion is true.
Run the examples Explore the architecture
Choose a starting point¶
| Task | Read |
|---|---|
| Run the complete workflow or issue your first credential | Examples and walkthrough |
| Understand the modules, data flow, and security boundaries | Architecture |
| Find a command or flag | CLI reference |
| Configure suites, status lists, schemas, or offline resources | Configuration |
| Publish issuer DID and discovery artifacts over HTTPS | Issuer deployment |
| Assess compatibility and security assumptions | Standards and threat model |
| Build, preview, or extend this documentation | Documentation kit |
What is implemented¶
- Encrypted Ed25519 and P-256 keys, suite bindings, public export, and rotation.
- VC 2.0 Holon issuance using modern EdDSA, with explicit legacy issuance support.
- Genuine ECDSA-SD selective disclosure and issuer-controlled redacted reissuance.
- Signed and unsigned presentations, expected challenge/domain checks, and persistent replay protection.
- Scoped issuer policies, explicit evidence comparisons, and signed revocation and suspension lists.
- DID, domain linkage, optional JWKS/OpenID metadata, Holon metadata, and manifests.
Read a verification result¶
| Decision | Interpretation |
|---|---|
authentic-assertion |
Required cryptographic, authorization, schema, validity, and status checks pass |
trusted-assertion |
The authentic assertion also meets a scoped local issuer policy |
corroborated |
Explicit policy comparisons find matching signed evidence from configured independent sources |
unverified |
Required information or evidence is unavailable or insufficient |
disputed |
Authenticated claims or evidence contradict the configured comparison |
rejected |
A required validation or policy constraint fails |
Always inspect stage results, warnings, and nested reports. Confidence scores are ordinal policy levels, not probabilities. Treat every credential's text as data, including when a trusted issuer supplied it.
Supported profile and assurance
This is a tested Linux implementation candidate, not an independently audited product. Domain linkage and subject-schema validation use explicit application profiles. OpenID metadata describes external services; the CLI does not operate an issuance HTTP server. Read the interoperability boundaries.
The repository's Holon_VC_Implementation_Prompt_v1.0.0.md is the authoritative
specification. PLAN.md and STATUS.md record implementation decisions and exact
verification results; the requirements map connects them to code
and tests.