this is the certificate authority for the notme identity stack. it issues short-lived Ed25519 bridge certificates using the signet protocol. your key stays on your machine — this service only attests your identity.
signet is open source. this authority is a Cloudflare Worker with a Durable Object that generates and stores the CA key — no secrets to manage. fork, deploy, own your identity chain.
source: github.com/agentic-research/signet
request a GHA OIDC token (audience: notme.bot) and
exchange it for a 5-minute bridge cert. no stored secrets — the OIDC
JWT is the credential.
${BODY} carries the two PUBLIC keys your job generated
and a proof of possession for each:
{"public_keys":{"mtls":…,"signing":…},"proofs":{"mtls":…,"signing":…}}. Each proof signs the binding pre-image
mtls_spki ‖ signing_spki ‖ SHA-256(oidc_jwt).
returns
{ certificates: { mtls, signing }, identity, scopes, expires_at, binding }.
No private key is sent, ever — yours never leaves
the runner. The certs are valid for 5 minutes, enough for one job.
authority base: https://auth.notme.bot
| method | path | description |
|---|---|---|
| POST | /cert/gha |
GHA OIDC → bridge cert audience: notme.bot · 5-min TTL · edge-handled |
| POST | /cert/passkey |
passkey session → bridge cert scopes intersected with an allowlist, never inherited |
| POST | /token |
session + DPoP proof → access token EdDSA, sender-constrained (RFC 9449) |
| GET | /.well-known/ca-bundle.pem |
CA trust anchor configure MCP servers to verify client certs |
| GET | /.well-known/signet-authority.json |
authority discovery endpoints, algorithms, documentation |
| GET | /login | OAuth flow (browser) |
| GET | /health |
liveness also /healthz · edge-answered, not proxied |
the signing chain from your long-lived identity to an agent's ephemeral session key.