Identity & evidence

A name you can carry. Evidence that can be checked.

Clio is building open, portable identity and evidence foundations so contributor credit does not depend on one platform. The code exists; production deployment is not yet live.

Status: source foundation, not deployed. Local DID/OIDC and Clio Local Evidence v1 components exist in the repository, but Clio does not yet operate a production sign-in, public DID resolver, external anchor, or DOI registration service. No Maatara affiliation or endorsement is claimed.

Contributor identity

Clio mints and owns the contributor layer.

Where possible, Clio will mint contributor did:web identities and control the associated keys, with clear recovery, rotation, and revocation rules. ORCID can remain a linked scholarly credential.

Sign-in adapters

Practical access, clear boundaries.

Google, Microsoft, and a generic Maatara OIDC adapter are implementation foundations in source, not live login promises. Authentication and contributor identity remain separate layers.

Clio Local Evidence v1

Tamper-evident history, not a claim of Veritas.

Clio’s local evidence component signs and chains record commitments for later checking. It is Clio Local Evidence v1, distinct from the Maatara Veritas protocol; external anchoring is planned, not yet live.

Maatara strategy

Preferred dependency, earned through gates.

Clio’s preferred hard-dependency target is Maatara after portable SDKs, licensing, conformance, security, and support gates are agreed. Maatara-hosted identity or Veritas services remain optional.

Proposed flow

Identity, record, evidence.

The implementation sequence is deliberately staged so the public promise never gets ahead of the working system.

01

Mint or link

Link ORCID or an OIDC account, then mint a Clio-controlled DID after key-management and recovery controls are ready.

02

Sign the event

Bind contributor intent, the original submission, and the normalized record through a versioned provenance package.

03

Anchor the digest

Publish a verifiable commitment through an independent external anchor only after the resolver, retention policy, and conformance tests exist.

What we will publish before launch

A protocol is only portable when other people can inspect it.

  • Threat model, key custody, recovery, rotation, and account-linking policy.
  • Open identity and Clio Local Evidence v1 schemas with versioning and test vectors.
  • Maatara SDK licensing, conformance, security, and support commitments before a hard dependency.
  • Resolver, retention, deletion, correction, and accessibility policy.
  • Dataset DOI integration is planned; DOI registration is disabled in the current foundation.