creds
creds is a public page where visitors can check every green check themselves.
Put your name, links and accounts on one page at creds.id/@you. When you verify an account, it gets a green check. Anyone who opens your page can check it in their own browser. They don’t have to trust creds, and they don’t need an app or an account.
How it works
- Your identity starts on your phone. The app creates your identity on your device from a 24-word recovery phrase. Your page is signed with that identity’s key.
- Your page is signed and public. The app publishes your signed page to public Nostr relays. creds.id shows it to visitors at
creds.id/@you. - Checks run in the visitor’s browser. Every time someone opens your page, their browser fetches it, verifies the signatures, and checks each binding from both sides. See How visitors check.
- A one-way claim never gets a green check. If you only say you own an account, and the account doesn’t say it back, it is shown as a plain claim.
Local-first, not serverless
creds is local-first: your identity and your data start on your phone. That doesn’t mean there is no server. Your public page still has to reach visitors over the network. It is served by creds.id, stored on public Nostr relays, and some checks read public DNS, Ethereum or Bluesky servers. The creds.id name directory maps names like @you to identity keys. Privacy & security lists what goes where.
Words we use
| Word | Meaning |
|---|---|
| verify | You attach a green check to one of your accounts for the first time. |
| re-verify | You redo a verification after it lapses. |
| check | A visitor’s browser, or your app, confirms that a green check still holds. |
| green check | The mark next to an account that passed its check. Only two-way bindings can get one. |
| declared | A claim the page makes that the other side doesn’t confirm. It never gets a green check. |
Where to go next
- Getting started: make your page in the app or in your browser.
- Verify your accounts: the ways to get a green check.
- How visitors check: what happens when someone opens your page.
- Privacy & security: what stays on your phone and what is public.