Environments
Start with DNSid Local on your machine, then publish an identity on a domain you own when other people need to verify it. Both use the same record format and verification calls.
The two environments
Section titled “The two environments”1. Local: on your machine, disposable
Section titled “1. Local: on your machine, disposable”DNSid Local is a Docker Compose network on your machine: a local DNS zone (test), a TLS proxy with its own local CA, a registry service, and a local lifecycle log. You get the full register-publish-verify loop with no account, no real DNS, and nothing leaving your machine. Start here with the DNSid Local quickstart.
2. Your own domain: public and self-managed
Section titled “2. Your own domain: public and self-managed”A self-managed identity lives on a domain you control. You publish the signed _dnsid record in your DNS, host the JWKS and status endpoints, and sign the record with your own entity key. Counterparties can verify it using your published record and a trust policy for its lifecycle log, without an account. Publish self-managed records walks through it from code, and Give an agent an identity covers the record, its lifecycle, and the registration states.
Side by side
Section titled “Side by side”| Aspect | Local | Your own domain |
|---|---|---|
| Runs on | Your machine (Docker) | Your DNS, TLS, and hosting |
| Account required | None | None |
| Agent domain | alice.test (local zone) | An FQDN you own |
| DNS | Local CoreDNS | Public DNS, yours |
| TLS and JWKS | Local CA, local proxy | You host |
| Who can verify | Processes pointed at your local network | Anyone on the internet |
environment value | testnet | As registered |
| Set up with | dnsid local up | dnsid CLI or SDKs |
Same calls, different sources
Section titled “Same calls, different sources”Run your local service with dnsid local run or load dnsid local env into your shell. The environment constructor reads the agent’s identity, key location, and local DNS, CA, and log policy. For a domain provisioned with the CLI, the directory constructor reads the identity and keys from ~/.dnsid. Pass a directory explicitly if your CLI files live elsewhere, and configure trust for the log you use.
// Import github.com/dnsid-ai/dnsid-go/config.idm, err := config.IdentityManagerFromEnvironment(ctx, nil, dnsid.Config{}, config.Dependencies{})if err != nil { log.Fatal(err)}fmt.Println("acting as:", idm.Domain())import { createNodeIdentityManagerFromEnvironment } from '@dnsid-ai/sdk/node';
const idm = await createNodeIdentityManagerFromEnvironment();from dnsid import identity_manager_from_environment
manager = identity_manager_from_environment()For the CLI-directory constructor in each language, see Create an identity manager. Use the manager for verification and signed requests.