manifesto
Identity should belong to the people it identifies.
For twenty years, being a customer online meant handing an email address to every business you touched and hoping they didn't leak it. Then came AI agents, and now bots hand your email address to every business you've never touched, hoping they don't block it. The whole game — who's who, who consented to what, which agent acts on whose behalf — runs on trust we haven't earned.
about-us.md is the business-side surface of a small, opinionated fix.
The Agentic Web
Four cooperating surfaces, one shape:
about-me.md
The personal flagship. Your canonical public presence, machine-readable, self-signed.
username.md
Claim a handle. Publish keys. Delegate agents. Sign consent. The user-owned side of the web.
finger.md
Machine-readable presence and agent handshake. The protocol layer beneath both sides.
about-us.md
Verify the customer at your door. Enforce delegated-agent scope. Keep signed receipts. This site.
sink.md
The personal context vault. Where a customer's history lives so their agent can carry it.
preferences.sh
The portable preferences layer. Consent, opt-in, communication cadence — one place, signed.
Three convictions
- Keys, not accounts. The internet already has an identity primitive that works (public-key crypto). Accounts are a business primitive. Let businesses have accounts; let people have keys.
- Agents are first-class. Every human will delegate to several AI agents this decade. Your infrastructure needs to answer "which agent, whose customer, what scope" — not "is it a bot y/n."
- Consent is a signed artifact, not a checkbox. When something goes wrong (fraud, dispute, regulator), the party holding the signed receipt wins. Give customers and businesses both a way to hold receipts.
Why this compounds
Every user side (username.md, about-me.md) that adopts the handshake makes every business side (about-us.md) more valuable, and vice versa. The network effect isn't monopolist — it's just a wire format that becomes more useful the more parties speak it.
We're not trying to be the identity provider. We're trying to make identity provider-shaped things interchangeable. If we succeed, this whole website is boring plumbing within five years — which is exactly what identity infrastructure should be.
What we won't do
- Sell customer data. The business only ever sees signed intent envelopes. We don't sit in the request path.
- Lock in issuers. Any business can self-host verify + issue. Sovereign issuers are a first-class deployment shape, not an upsell.
- Roll our own crypto. Ed25519 + JWKS + short-lived signed envelopes. Boring on purpose.
- Fight government IDV. KYC has its place. We slot in beside it, not against it.
The pitch, in one paragraph
Your inbox is a sewer because your identity layer is email. Your bot-detection is broken because it classifies traffic instead of verifying it. Your consent story is "we swear the box was checked." about-us.md replaces all three with one primitive: a signed intent envelope from a verifiable handle, with scope and expiry. Wire it in beside what you already run. Refunds get faster. Recovery gets stronger. Bots get sorted. Auditors get quieter. Customers get their agency back.