Skip to content

What Just Happened

You've completed the basic journey. Let's look at the pieces.


The Container Hierarchy

What you built follows this structure:

Your node (running on your machine)
   │
   └── HOME (yours, created with your account)
         │
         ├── public zone
         │     └── kitchen (the room you created)
         ├── common zone
         │     └── riverside (the Hall you founded)
         │           ├── public zone  (welcome room)
         │           ├── common zone  (general room)
         │           └── private zone (governance room)
         └── private zone

   shelf (a capsule you created)
  • Node — your running Kunuleco instance. It holds accounts, places and connections, and it has an account of its own, the node user, which cannot be signed into.
  • HOME — the place every account starts with. Its three zones hold rooms.
  • Room — a place you create inside a zone.
  • Hall — a place for a group, founded in your Common zone. It has zones and rooms of its own, you are its Steward, and its threshold decides who gets in.
  • Capsule — a container with capability-based access. You grant each person exactly what they may do with it.

For more, see Concepts: Places.


Your Identity Layers

Layer Example Purpose
AID a KERI identifier What your node proves when it connects. Blocks and admissions key on it.
Handle Mira#7K2QX9 Your name plus a tag derived from the AID. Human-friendly, and nobody else can have it.
Short code tiger-castle-7 A lookup key for one invitation. It is not your identity.
Peer seed kunul1… For meeting in person. It pins your node's identity.

The tag stops anyone from taking your name. Someone else can be Mira, but they will be Mira# something else.

For more, see Concepts: Identity.


The Connection Path

When Alex used your code:

  1. Lookup — the short code resolved to your node's connection details.
  2. Transport — Alex's node tried the local network, Veilid, Tor and IPFS at the same time and kept the first that connected.
  3. Proof — the two nodes exchanged signed hellos, and each proved its AID to the other.
  4. Joining — Alex's node joined the presence the invitation named. A presence has a door. The lobby's is always open, and a Hall's follows its threshold. At the default, knock, Alex waited until you ran accept.
  5. Presence — you both appeared in the same presence and could talk.

For more, see Concepts: Connections.


Message Security

  • Signed. Every message is signed, so the other node can check who sent it and that nobody changed it on the way. Signing proves the sender. It does not hide the contents.
  • Encrypted in transit across the internet. Veilid and Tor carry the connection encrypted.
  • ⚠️ Not yet encrypted on a local network. When two nodes on the same network connect to each other directly, that connection is not encrypted yet, so someone on the same network can read what passes between them. Keep this in mind on shared Wi-Fi.
  • Not end-to-end encrypted. Your node and your friend's node can read what passes through them. Live voice is not end-to-end encrypted either.

No central server sat in the message path. Your node keeps a log for troubleshooting, and as of 0.2.188 it no longer records the contents of your messages. It does still record that a message passed, who it was between, and which transport carried it. On a node you run yourself, that log is yours. On a node someone else hosts, the operator can read it.

For more, see Concepts: Trust.


What Persists

What Where Kept?
Your account and keys The node's data folder, encrypted Yes
Your places, rooms and capsules The node's database Yes
Your contacts and blocks The node's database Yes
tell conversations Your chat history on your node Yes
Live connections to other nodes Memory No. They reconnect.

Where to Go From Here


Quick Reference

Commands from this guide, typed in Urchin's terminal:

look                              # where you are, its exits, who is here
go <exit>  ·  home                # move, or return to your HOME
create ~room <name> [--desc …]    # a room, from inside a zone
create ~capsule <name>            # a capability-gated container
found hall <name>                 # a Hall, with you as its Steward
knocks  ·  accept <name>          # see who is waiting, let them in
grant <capsule> <identity> <caps> # let someone use a capsule
meet                              # your peer seed, for someone next to you
invite                            # a short code for your current presence
join <code|seed>                  # use an invitation
friend <identity>                 # add a contact
tell <identity> [message]         # a one-to-one message, kept
who  ·  contacts  ·  friends online

Client commands start with /, for example /check-updates. For every command, see the command reference.