Skip to content

SDK overview

DNSid has open-source Go, TypeScript, and Python SDKs (Apache-2.0), the core of the Developer Kit. Each covers the same core surface - verify DNSid domains, sign HTTP requests, and mint DNSid JWTs. The Go module (github.com/dnsid-ai/dnsid-go) is the reference implementation for protocol behavior.

Full API references: Go · TypeScript · Python.

Terminal window
go get github.com/dnsid-ai/dnsid-go
  • Go 1.26.6+ - single module with oidc, httpsig, webbotauth, jose, log, and log/c2sptlog packages, plus the separately tagged key/aws submodule for AWS KMS.
  • TypeScript - Node.js 22+, dual ESM/CJS builds. @dnsid-ai/transport is the Node DNS/HTTPS transport; the root SDK is runtime-neutral. Capability-specific packages (registry, OIDC, transparency log, AWS KMS keys) install separately - each guide page names the package its snippets need.
  • Python 3.11+ - a single dnsid package; the [aws] extra adds AWS KMS support.

Use an identity manager to verify peers and act as your own identity. Load an identity provisioned with dnsid from the CLI’s files, or supply configuration and keys yourself.

The dnsid CLI stores the identity’s publication settings and key files in its config directory. The SDK reads ~/.dnsid/config.json, follows its current-domain pointer to the per-domain config when present, and loads the matching key. Pass a directory to use a different location.

// Import github.com/dnsid-ai/dnsid-go/config.
idm, err := config.IdentityManagerFromDnsid(ctx, "", dnsid.Config{}, config.Dependencies{})
if err != nil {
log.Fatal(err)
}

For DNSid Local, run your code under dnsid local run or load dnsid local env into your shell and use the environment constructor. It reads the identity, key location, DNS, CA, and log policy from the CLI’s DNSID_* exports. See the local quickstart for runnable examples. For an identity loaded from CLI files, configure trust for its lifecycle log before verifying domains.

All three SDKs accept a config shape - Config in Go, DnsidConfig in TypeScript and Python - with these sections:

  • identity - your own publication settings: domain, governance identifier, log reference, and status URL. Omit it for a verification-only manager.
  • verification - status re-check interval, DNSSEC mode, and the counterparty allowlist. The zero value is spec-strict.
  • transport - custom DNS server and CA bundle for the SDK-managed resolver and fetcher.

Pair the config with a key provider (local file-backed keys, AWS KMS, or your own implementation) to act as the identity. Publishing requires a status URL and the identity’s lifecycle-log reference. Use the reference assigned by your log; the sample stream ID below is illustrative. Generate a fresh, opaque stream ID for each C2SP identity instance:

kp, err := dnsid.LoadOrCreateLocalKeyProvider("keys.json", dnsid.JoseAlgEdDSA)
if err != nil {
log.Fatal(err)
}
idm, err := dnsid.NewIdentityManager(dnsid.Config{
Identity: &dnsid.IdentityConfig{
Domain: "agent.example",
GovernanceID: "example.com",
LogRef: "c2sp-tlog:public:https://log.example.com#EREREREREREREREREREREQ",
StatusURL: "https://agent.example/.well-known/dnsid/status.json",
},
}, kp)
if err != nil {
log.Fatal(err)
}

These examples set up an identity and its key. Verification also needs a trusted reader for the lifecycle log named by the record’s lr= reference. Publish self-managed records covers the entity key and ek/ku URLs needed to publish draft 01 records. A verify-only manager doesn’t need a key of its own (Verify a domain).

TypeScript and Python accept a deployment JSON file through createNodeIdentityManagerFromFile('dnsid.json') or identity_manager_from_file("dnsid.json"). The file can contain dnsid, logTrust, and registry sections; an identity also needs a key provider passed to the constructor.

To combine sources, load each separately, merge the results, and construct the manager. If two sources set the same field, the one merged last wins; fields it leaves unset retain their earlier values. Log trust is replaced as a whole. The constructor applies defaults and validates the result. Go supports environment and CLI-directory loading.

The three SDKs cover the same capabilities but package them differently: Go is one module with subpackages, TypeScript is one npm package per capability (install what you use), and Python is one package with everything included.

CapabilityGoTypeScriptPython
Verification, records, keyscore module@dnsid-ai/sdk + @dnsid-ai/transportdnsid
OIDC tokensoidc@dnsid-ai/oidcincluded
HTTP Message Signatures (RFC 9421)httpsig@dnsid-ai/http-signaturesincluded
Web Bot Authwebbotauth@dnsid-ai/web-bot-authincluded
JOSE (DNSid JWTs)jose@dnsid-ai/joseincluded
Registry clientcore module@dnsid-ai/registryincluded
C2SP transparency loglog/c2sptlog@dnsid-ai/log-c2sp-tlogdnsid.c2sp_tlog
AWS KMS keyskey/aws submodule@dnsid-ai/key-awsdnsid[aws] extra
GCP KMS keys-@dnsid-ai/key-gcp-

Each guide page names the package its snippets need; the full per-language surface is in the API references.