Skip to Content
Draft · Draft for review. Not published yet; content may change.
How Visitors Check

How Visitors Check

A creds page doesn’t ask visitors to trust creds. When someone opens your page, their own browser fetches your signed page and checks it. This happens every time the page is opened, and no creds server checks anything on the visitor’s behalf.

What the browser checks

Say someone opens creds.id/@alice:

  1. It looks up the name. The browser asks the creds.id name directory which public key alice belongs to (https://creds.id/.well-known/nostr.json?name=alice). It also asks whether the name was moved or released (https://creds.id/id/history?name=alice). A moved name sends the visitor to the new name.
  2. It fetches the signed page. The page is downloaded from public Nostr relays. The browser checks the signature on every event a relay returns and uses the newest valid one.
  3. It checks the page’s own signature. Alice’s page is signed with her identity key, and the browser verifies that signature. It also checks that the page names the Nostr key the directory returned. If it doesn’t, the page is not shown at all.
  4. It checks the name from both sides. The browser fetches the public Nostr profile of that key. @alice gets a green check only if that profile claims alice@creds.id and names the same identity as the page.

If any step fails, the row doesn’t get a green check.

The share sheet in the app also makes two links that don’t use the name:

LinkWhat the browser checks
creds.id/#nostr:npub1… (published short link)It fetches the page published by that Nostr key, verifies the signatures, and checks that the page names that key.
creds.id/#… (full offline link)The whole signed page is inside the link. The browser verifies the signature without making any network request. A green check here means the page is intact and signed by the identity shown; it says nothing about any account.

What each state means

Every check on a page is in one of four states:

StateHow it looksWhat it means
VerifiedGreen checkThe check passed just now, in this browser.
StaleOrangeThe check couldn’t finish right now, for example because the relays didn’t answer. This says nothing about the account itself. Try again later.
RevokedRedThe browser saw a clear signal that the proof is gone.
DeclaredGrey, shown like an ordinary linkA one-way claim: the page says it, but the other side doesn’t confirm it.

A one-way claim never gets a green check. This is the most important rule in creds.

Which rows can get a green check

The row that can get a green check is the identity the page was opened by: @alice on creds.id/@alice, the Nostr key on a published short link, or the signing identity on a full offline link.

Other identities listed on the page are shown as Declared. Links in the link list are ordinary links, with no check.

Inside a check

Tap a row to open it. The panel shows:

  • Who can re-check: “Signature checked here”.
  • This check: “Verified in your browser”.
  • Evidence: the raw claim, exactly as it appears in the signed page.
  • Signed by this identity’s key, with the time the page was signed. That is when the owner signed the page, not when the visitor’s browser checked it.

How often checks run

Every time the page is opened. The page doesn’t keep earlier results, so a reload checks everything again. If a lookup fails, the page offers a Retry button.

In the app, the checks on your own page run again when you open the Page tab, at most every 15 minutes unless you signed a new version of your page in the meantime. Contacts whose pages you saved are refreshed when you open the app or return to it, at most every 6 hours and up to 30 contacts at a time.

What a check still relies on

A check in the visitor’s browser removes the need to trust creds, but it still relies on public infrastructure:

  • The name directory maps alice to a key and can say that a name moved or was released. It cannot give a row a green check by itself: the key’s own Nostr profile must agree.
  • Relays store and return the signed page. If no relay returns it, the page can’t be shown.