Skip to content
LogoLogo

Signing

The DDO as a verifiable credential

Because the DDO lives off chain, something has to make it tamper-evident. nautilus signs it as a JWT Verifiable Credential before storing it, and the asset's issuer is whoever signed.

You do not have to configure this. The default works with nothing but the signer you already have.

The default: sign with the Ethereum key

Eip191VcSigner signs with the same key that pays for the transaction, using an alg: 'ETH-EIP191' header. Publishing therefore works with no SSI wallet anywhere in the picture, and the issuer is the signer's address.

// Nothing to configure — this is what you get.
const  = await .(, {
  : { : 'https://ocean-node.dev.pontus-x.eu' }
})

Issuing from a real DID

WaltIdVcSigner signs with a wallet-held key, so the issuer is a proper DID and the credential validates like any other VC.

const  = new ({ : 'https://wallet.example.org' })
 
// Web3 login returns a bearer token; the wallet, key and DID are listed with it.
const {  } = await .()
const [{ :  }] = await .()
const [] = await .(, )
const [{  }] = await .(, )
 
const  = await .(, {
  ,
  : new ({ 
    , 
    , 
    : .., 
    , 
     
  }) 
})

Pair this with setIssuer when you want the document's declared issuer to match.

What you get back

publish returns the credential alongside the rest of the result.

const {  } = await .()
 
?. // the compact JWT that was stored
?. // the DID or address that signed it

Inspecting a credential

decodeCredential reads the payload without verifying the signature — useful for debugging what was actually signed.

const  = () 
 
. // the DID
. // the issuer

Writing your own signer

class  implements DdoSigner {
  async (): <string> { 
    return 'did:web:example.org'
  }
 
  async (: <string, unknown>): <SignedCredential> { 
    return { : await (), : await this.() }
  }
}
 
declare function (: <string, unknown>): <string>

getIssuer() is asked first, and its answer is written onto the DDO before the document is validated, signed and returned — so PublishResponse.ddo.issuer always matches the signed claims. It must name the same identity sign() issues as.