Join your first trust community.
FirstPerson.dev is the test community for the Verifiable Trust Infrastructure stack. Pick a laptop or a phone, run your own Verifiable Trust Agent on VTA Farm, and send a join request to the test community. Six steps, five to ten minutes.
How do you want to drive your VTA?
Pick one. The steps below adapt to your choice. You can always come back and do the other path later.
From download to join request, end to end.
Steps 3 and 5 are the same on both paths. Steps 1, 2, 4, and 6 show instructions for the path you picked above. The laptop path follows the developer tutorial, which has the long version.
-
Download your tools.
Grab the tools for the path you picked. Laptop users need two binaries. Phone users need one app.
On your laptoppnmis the Personal Network Manager. It links your machine to your VTA.openvtcis the terminal client you use to create personas and join communities. Both are single static binaries for x86-64 Linux. Save them in the same directory.On a Mac? There are macOS builds of pnm and openvtc too.
Or build from source
Both tools are Rust workspaces on GitHub.
pnmlives in the Verifiable Trust Infrastructure repo as thepnm-clipackage.openvtchas its own repo. You need a recent stable Rust toolchain from rustup, plus the usual C build dependencies on Debian or Ubuntu:clang cmake pkg-config libssl-dev libdbus-1-dev.# pnm, from the VTI workspace (always pass --locked) git clone https://github.com/OpenVTC/verifiable-trust-infrastructure.git cd verifiable-trust-infrastructure cargo build --package pnm-cli --release --locked # binary: target/release/pnm
# openvtc git clone https://github.com/OpenVTC/openvtc.git cd openvtc cargo build --package openvtc --release # binary: target/release/openvtc # or, to skip hardware token support and its dependencies: # cargo build --package openvtc --release --no-default-features
Copy both binaries into one directory and carry on with step 2. If you build them yourself, the
chmodstep is already done.On your phoneKeyring is the mobile agent. It holds the device key that proves you control your VTA, approves requests, and joins communities by scanning QR codes. The iOS build ships through TestFlight. The Android build is on Google Play.
Opening these links on a laptop? VTA Farm shows the same links as QR codes in step 4, so you can scan them with your phone there.
-
Get the tools ready.
A minute of setup before anything talks to a VTA.
On your laptopOpen a terminal in the directory where you saved the binaries and make them executable. They are unsigned, but they come directly from us.
chmod +x pnm openvtc # macOS only: clear the quarantine flag on the unsigned binaries # xattr -d com.apple.quarantine pnm # xattr -d com.apple.quarantine openvtc ./pnm --help ./openvtc --help
Both commands should print usage text.
pnmkeeps its session in your desktop keyring (GNOME Keyring, KWallet, or KeePassXC over Secret Service), so make sure one is unlocked. Everything below runs the binaries as./pnmand./openvtcfrom this directory. Add it to yourPATHif you prefer.On your phoneInstall Keyring and open it once so it can finish its first-run setup and generate the device key it will use to talk to your VTA. Allow camera access when asked. You will scan two QR codes later: one to pair with your VTA, one to join the community.
Allow notifications if you want to be told when something is waiting for you. They only say that something is waiting. You approve inside Keyring, and joining a community asks for Face ID or a fingerprint, so make sure the phone has one set up.
-
Create a VTA Farm account.
On your phoneDo this step and the next one in a browser on a laptop or desktop, not on the phone. In step 4, VTA Farm shows a QR code that you scan with Keyring, so the code has to be on a screen other than the phone you are scanning with.
Only have a phone? You can still do it. Create the account in the phone's browser instead. In step 4, choose Connect to PNM rather than Connect to Keyring, so VTA Farm shows an Admin DID box, and copy the VTA DID from the page. In Keyring, open the My Agent tab, tap Set up a new agent, then Paste, and paste the VTA DID. Keyring shows the phone's owner code. Copy it into the Admin DID box in VTA Farm and click Provision agent. Keep Keyring open. It finishes connecting on its own.
Your Verifiable Trust Agent runs on VTA Farm, a managed cluster that hosts personal VTAs for the test community. You need an account there before you can create one.
- Open vtafarm.firstperson.dev and sign up.
- Complete the passkey prompt. VTA Farm uses passkeys instead of passwords. On Linux there is no built-in passkey store, and a fingerprint reader will not work here, so use one of these: a hardware security key over USB or NFC, your phone through the QR code that a Chromium-based browser offers (Bluetooth on both devices), or a password manager extension that stores passkeys, such as Bitwarden, 1Password, Proton Pass, or KeePassXC. On a phone or a Mac, the built-in passkey prompt works as is.
- Land in the portal. You will log in with the same passkey next time.
-
Spin up a VTA and link it to your tool.
In the VTA Farm portal, click Create VTA. Enter a name, leave the default image selected, and click Create session. When the VTA is up, VTA Farm shows its VTA DID and asks how you want to connect: Connect to PNM or Connect to Keyring.
On your laptopChoose Connect to PNM and copy the VTA DID. Then, in your terminal:
./pnm setup
- Choose Connect to an existing non-TEE VTA.
- Enter the same name you gave the VTA in VTA Farm.
- Paste the VTA DID.
PNM prints a line like
vta import-did --did did:key:z6Mk… --role admin. Copy just thedid:key:…value, paste it into the Admin DID box in VTA Farm, and click Provision agent. Wait for Agent is online.Check the link from your terminal:
./pnm health
The checks against the VTA, the mediator, and the DIDComm and TSP trust pings should all pass. Now bind
openvtcto the same VTA:./openvtc -p alice setup
Use any profile name instead of
alice. Press Enter on Get Started, paste the VTA DID on Key Management, and press Enter. OpenVTC shows apnm contexts create … --admin-expires 1hcommand. Press F2 to copy it, run it in a second terminal with./pnmin front, then return and press Enter. Once it reports the VTA bootstrapped, press S to skip hardware token linking for now, since this is a trial run, then set an unlock code on Profile Security or skip it for testing, and press Enter on Setup Complete. The dashboard's VTA Service panel should show your VTA DID with an Authenticateddid:key.On your phoneDo this in the VTA Farm tab on your laptop. The QR code is tied to your login and your VTA, so it has to be your own code on a screen you can point the phone at.
Choose Connect to Keyring and click Generate Keyring QR code. The code is good for a few minutes. If it expires, click Generate replacement QR code.
- In Keyring, open the My Agent tab, tap Set up a new agent, then Scan. The Scan tab works too.
- Scan the code on the VTA Farm page. Keyring shows the agent, the site the code came from, and the agent's address. Tap Connect this phone.
- Watch VTA Farm. It moves from Waiting for confirmation in Keyring to Keyring confirmation received. Setting up your VTA while it adds your phone as the administrator and restarts the VTA.
- When VTA Farm says Your device is connected to this VTA through Keyring, you are linked. Keep Keyring open until then.
Save the VTA DID. It identifies your agent everywhere. On the laptop path you paste it twice, into
pnmand intoopenvtc. -
Get the community DID from the test VTC.
The test Verifiable Trust Community publishes its DID on its home page at first.openvtc.net. That DID is the only thing you need to find the community. Your tool works out the route to it on its own.
- Open first.openvtc.net.
- Find the Community DID card. It shows the DID as text with a Copy button, and as a QR code labeled Scan with Keyring.
- Laptop: click Copy. Phone: leave the page open, you will scan it in the next step. If you are reading the page on the phone itself, copy the DID instead.
Nothing on that card is secret. The DID is public by design, which is why it can sit in a QR code on a web page.
-
Send a join request.
A join request asks the community to admit a persona, a fresh
did:webvhidentity your VTA mints just for this community. The test community accepts open requests, so you do not need an invitation. An admin still has to approve you.On your laptopIn the OpenVTC dashboard, select Communities in the menu and press j.
- Paste the community DID and press Enter.
- On Where should this community live?, press Enter to accept A context of its own. OpenVTC mints a new persona in a new VTA sub-context named after the community.
- If you are asked about an invitation, arrow down to Join without it — send an open request and press Enter.
The community appears in your list as Pending. The persona DID is shown on the progress page. Save it: it is how the admin finds your request in their queue.
On your phoneIn Keyring, open the Scan tab and scan the Scan with Keyring QR code on the test VTC's home page. If you are on the phone itself, paste the community DID you copied instead.
- Keyring shows the community it found. Check that it is the test community at
first.openvtc.net, then confirm with Face ID or a fingerprint. - Keyring asks your VTA to mint a persona for this community and sends an open join request under it.
- The community shows as pending in Keyring until an admin approves it.
Save the persona DID. One persona per community is the rule. Nothing links it to your VTA's primary DID or to personas you use anywhere else, so do not reuse it.
An admin approves you, and credentials land in your agent.
Your request sits in the test community's admin queue under your persona DID. When an admin approves it, your VTA receives two credentials: a membership credential (VMC) that proves you are a member, and a role credential (VEC) that says what you can do there. In OpenVTC they appear under My Credentials. In Keyring they appear with the community.
On the phone path, you can add a computer later. Set up openvtc as in the laptop path, then in Keyring go to My devices, tap Add another device, and paste the key the terminal app shows you.
Want the long version, or to run your own VTA instead of using VTA Farm? The developer tutorial covers both.