Your First Identity¶
Your identity in Kunuleco lives on your own node. It is a set of keys stored on your machine and protected by a password only you know. It is not rented from a platform or tied to an email address. Let's create it.
Mira typed slowly. She'd had usernames before — handles chosen in seconds, abandoned when platforms changed or communities soured. This felt different. She wasn't picking a brand. She was naming herself.
Create Your Account¶
On Urchin's welcome screen, enter a username and choose Create Identity. You set a username, a password and a theme.
The first time you sign in, Urchin runs a short guided tour, unless you untick Show tutorial on first login when
you create the account. The node
introduces itself, then has you run whoami to meet your identity, transport to see how you reach other nodes, and
look to see where you are. It explains the two input modes and names the commands for founding a Hall and bringing
people in. Type skip at any point to jump to the end. The tour runs once for each identity.
Without the tour, Urchin offers to back up your identity (see Your Password), then opens your HOME. From there you can found a Hall, join with an invite, or open the console.
Your Node and Its Owner¶
The first account on a new node is created freely, and it becomes the node's owner. The node has an account of its own, the node user, which signs the owner's rights at that moment. The node user cannot be signed into.
A node can hold more than one account. Every account after the first must be sponsored. Someone who holds the right to create accounts enters their username and password beside yours, in Urchin's Sponsor step. The owner holds that right from the start and can pass it on, and a sponsor can tick a box to pass it on to the new account. A right that is passed on expires after 90 days unless the person who granted it renews it.
Your Handle¶
Your handle is your name plus a six-character tag, for example Mira#7K2QX9. The tag is derived from your identity's
cryptographic identifier, so it is not random and nobody else can have yours. Someone else can be Mira, but they
will have a different tag. The tag uses letters and digits chosen to be hard to misread, so it survives being read
aloud or copied off a screen.
Underneath the handle is an AID, a KERI identifier. When your node connects to another, it proves this identifier with a signed hello, and that is what the other side trusts, not the name.
Your Password¶
Your password unlocks your account's keys, which are stored encrypted in the node's data folder. There is no "forgot password". Nobody else holds a copy, so nobody can reset it for you.
To guard against losing the machine, back up your identity. Type export-identity in Urchin's terminal and it opens a
dialog that asks where to save the file and for a passphrase. The passphrase is not your login password. The file and
its passphrase together can restore your identity on another node, so anyone holding both holds your identity. Keep
them apart, somewhere safe and offline. See Identity management.
The file is written by the node, so on a node running on another computer it lands on that computer. For that reason the backup offer Urchin makes after you create an account appears only when the node runs on your own machine.
Repeated wrong passwords slow down further attempts, and the delay wears off with time.
Command Mode and Chat Mode¶
Urchin's terminal has two input modes:
- Command mode. Everything you type is a command, such as
lookorfound hall riverside. - Chat mode. A plain line goes to the channel on the chip above the input. Start a line with
/to run a command, for example/look.
/cmd and /chat switch between them, and /defaultmode sets the one Urchin starts in.
Your First Commands¶
| Command | What it does |
|---|---|
whoami |
Shows your name, where you are and what you carry |
look (or l) |
Describes where you are, its exits and who is here |
go <exit> |
Moves through an exit. n, s, e, w, up and down work as shortcuts. |
home |
Brings you back to your HOME |
who |
Shows who is here, and who is signed in on this node |
help / help all |
Starting help, then the full command list |
quit |
Disconnects |
Signing In Over SSH¶
Urchin signs you in from its welcome screen. You can also reach your node with an SSH client, on port 8122:
There you type the same commands without the / that Urchin's own commands use. Urchin's own commands, such as the
update commands and the network view, exist only in Urchin. One account can be signed in only once at a time, so quit
Urchin before you sign in over SSH as the same person.
Identity Security¶
- Your password is stretched with Argon2id, a memory-hard function that makes guessing it expensive.
- Your keys are Ed25519 keys held in a KERI keystore, which records key events in an append-only log. There is no command to rotate a key yet.
For more, see Concepts: Identity.
Next Step¶
You have an account. Now let's find your way around.