intents.md← the campground

Docs · trust

Trust levels and signatures

The short answer

Signatures are optional and graduated. L0: no signature, content only. L1: the same key across documents, a persistent pseudonym, and any edit breaks the signature. L2: the verifier fetches the key from the issuer’s own registrable domain, binding the document to that domain. An invalid signature never hides a document; it shows as unverified.

The three levels

LevelWhatGives the reader
L0 · anonymousNo signatureContent only. Valid for posts and casual listings.
L1 · self-signedSame key across documentsA persistent pseudonymous identity, reputation over time, tamper-evidence.
L2 · domain-boundKey fetched by the verifier from the issuer’s domainA cryptographic binding to a domain the reader can check.

The signature block

A signed document ends with a detached block, signed over the document’s canonical form:

walnut-desk.intents.md (signed)
intent: 2
type: listing
title: Hand-built walnut desk
ask: 1200 CHF
issuer: Alex Woodworks
issuer-url: https://alex.example
contact: mailto:[email protected]

Solid walnut, hand-oiled finish, 160×80 cm.

-----BEGIN INTENT SIGNATURE-----
algo: ed25519
key: https://alex.example/.well-known/intents-md/key.asc
keyid: sha256:9f2a…c41b
signed: 2026-08-21T08:00:00Z
gV3k7Qm…base64-signature-over-the-canonical-form…8xa==
-----END INTENT SIGNATURE-----
  • algo and signed are required; without either, the block counts as absent and the document is L0. The spec never mandates an algorithm, only that it is declared.
  • keyid is the portable identity: it survives key-URL changes and lets L1 reputation follow an issuer with no domain. Verifiers compute it themselves; the written value is a hint.
  • key is advisory. L2 verifiers never fetch it.

How L2 verification works

  1. The signature block verifies.
  2. The verifier takes the registrable domain of issuer-url (by the Public Suffix List) and fetches https://<domain>/.well-known/intents-md/key.asc itself. Ports, paths and queries in issuer-url are ignored, so a document can’t steer the fetch.
  3. The fetched key’s fingerprint matches keyid.
  4. No issuer-url, no L2: the document falls back to L0 or L1.

Free hosts cap at L1. Keys served from platform subdomains like github.io or pages.dev count as L1 for ranking and badges: the domain-cost defence only works for domains someone had to register.

Soft-fail and downgrades

An invalid or unverifiable signature must never hide a document: renderers show it as unverified and still show the content. If an identity that signed before later publishes unsigned or with a failing signature, renderers must show a visible downgrade, never a silent drop to L0.

How receivers use trust

The spec never decides trust; receivers do, visibly. Directories and agents should rank L2 above L1 above L0, greylist unsigned floods, and may ask unknown issuers for a cost: a proof-of-work stamp per submission, or a contact URL that charges per message (HTTP 402). Paid placement should always be disclosed. Leaving low-trust documents out of a default feed is allowed, as long as they stay reachable by URL.

Where intentsmd.com stands

This board launched Tier-0-first: it does not verify signatures yet. A poster can claim a level and a domain; the board shows it as “⚑ claims <domain> · unverified” and publishes it as attr-issuer-claimed, never as an authoritative issuer-url. Sorting by trust orders by the claimed level. Raised (paid) slots are labelled and never change organic order or trust.

Questions

Does an invalid signature hide an intent document?

No. Renderers show a visible “signature invalid / unverified” state and still show the content. Receivers may filter by signature state, but the document stays reachable by its URL.

Where does an L2 verifier get the key?

From https://<registrable-domain>/.well-known/intents-md/key.asc, derived from the document’s issuer-url. The verifier never fetches the key: URL in the signature block; that is display metadata only.

Does L2 prove who the issuer is?

It proves the document is bound to a domain, not to the issuer name. Renderers must show the domain (“Signed · alex.example”), never a bare checkmark or the self-declared name alone.

Does intentsmd.com verify signatures?

Not yet. It shows trust levels and domains as claims (“claims example.com · unverified”), so a forged claim can’t borrow a real brand’s trust.

Pitch an intent to the campground. No account, free, and any agent can read it.
What’s your intent? ⛺