Skip to content

Quickstart: DNSid Local

DNSid Local is a complete DNSid network that runs in Docker on your machine: DNS, TLS, a registry, and a transparency log. You can register agents, publish signed _dnsid records, and verify them—without an account, without owning a domain, and without anything leaving your laptop. It ships with the dnsid CLI as part of the Developer Kit.

dnsid local up starts a Docker Compose network with three core services:

  • A CoreDNS server that is authoritative for the local zone test, so _dnsid TXT records resolve for local processes.
  • A Caddy HTTPS proxy with a locally generated CA, so agent JWKS and status URLs are served over TLS.
  • A registry service on 127.0.0.1:7755 that implements the DNSid registry API, with a local lifecycle log behind it.

Everything DNSid Local generates—keys, certificates, zone files, state—lives under ~/.dnsid-local, so it is easy to inspect and easy to throw away.

  • The dnsid CLI on your PATH—see Install the CLI.
  • Docker running, with Docker Compose.
Terminal window
dnsid local up

The first run pulls the registry image and generates the local CA, DNS zones, and proxy config under ~/.dnsid-local.

Say your agent is a local service on port 3001. Register it as alice:

Terminal window
dnsid local agent ensure alice --upstream http://localhost:3001

Short names expand under the local zone, so alice becomes alice.test. This one command generates an Ed25519 keypair for the agent, registers it with the local registry, issues a TLS certificate, and routes https://alice.test through the local proxy to your service. It prints the agent’s DNSID_* environment exports when it finishes. The agent is now VERIFIED: registered and accepted, but its record is not published yet.

Alternatively, wrap your dev process and let the CLI do all of it—start the network if needed, ensure the identity, and inject the environment:

Terminal window
dnsid local run alice --port 3001 -- sh -c 'echo "running with agent: $DNSID_AGENT_NAME"'

Load the agent’s environment into your shell, then countersign the agent’s transparency-log ISSUANCE:

Terminal window
eval "$(dnsid local env alice)"
dnsid log issue --domain alice.test
dnsid status --domain alice.test

dnsid log issue asks the local registry to prepare the ISSUANCE event, signs it with the agent’s key, and submits it to the local transparency log. That is the step that binds the key to the identity and publishes the signed _dnsid TXT record in the local zone. dnsid status should now show READY; while the ISSUANCE is still pending it names this command as the next step. The Claude Agent SDK plugin performs this step automatically when an agent session starts.

With the agent’s environment still loaded from step 4, use the same record commands you would use against any DNSid domain:

Terminal window
dnsid record inspect --domain alice.test --output pretty
dnsid record verify --domain alice.test

You can also query the local DNS directly with ordinary tools:

Terminal window
dig @127.0.0.1 -p 7753 _dnsid.alice.test TXT

The same check from your own service, in the language you use. Run each example under dnsid local run or after eval "$(dnsid local env alice)". The SDK reads the local DNS server, CA bundle, and log policy from DNSID_*; verification checks the agent’s transparency log as well as its record. On your own domain, configure trust for the log you use—see Transparency log.

Terminal window
go mod init verify && go get github.com/dnsid-ai/dnsid-go
main.go
package main
import (
"context"
"fmt"
"log"
"time"
dnsid "github.com/dnsid-ai/dnsid-go"
"github.com/dnsid-ai/dnsid-go/config"
)
func main() {
ctx, cancel := context.WithTimeout(context.Background(), 15*time.Second)
defer cancel()
idm, err := config.IdentityManagerFromEnvironment(ctx, nil, dnsid.Config{}, config.Dependencies{})
if err != nil {
log.Fatal(err)
}
verified, err := idm.VerifyDomain(ctx, "alice.test")
if err != nil {
log.Fatalf("invalid: %v", err)
}
fmt.Println(verified.Domain(), verified.Status().State)
}

Run go mod tidy after creating main.go. go get only resolves the root package, and tidy adds what the config package needs.

Terminal window
go mod tidy
go run .
# alice.test ACTIVE
  • dnsid local agent list—show registered agents.
  • dnsid local agent ensure <name> --upstream <url>—add or update an agent; safe to rerun.
  • dnsid log issue --domain <fqdn>—countersign a newly registered agent’s ISSUANCE so its record is published and it reaches READY.
  • dnsid local env [name]—print base or per-agent environment exports, as --format shell, dotenv, or json.
  • dnsid local down—stop the containers, keeping state.
  • dnsid local reset --hard—stop everything and delete ~/.dnsid-local state.

Publish on a domain you own when others need to verify your agent. Publish self-managed records covers the record, JWKS, and status endpoints. The SDK can load an identity provisioned with the CLI from ~/.dnsid; see Create an identity manager. Environments covers local and public setup.