◊ si-didy-signer

Konomi identity binding · every outbound Claude call signed · Ed25519 · NiceAssOS L1

Identity · this device's Konomi pubkey

Generated on first load. Private key stays in IndexedDB as a non-extractable Web Crypto object. Register this pub with the verifier or with Claude directly.

pub (base64url)
loading…
algorithm
Ed25519
storage
IndexedDB · non-extractable

Sign · wrap a Claude payload

Paste any request body Claude would accept. We canonicalise, digest, and sign. Result is a fetch-ready envelope with X-Konomi-* headers.

Verify · attack simulation

Signed envelopes verify against this device's pub. Tamper with the body or the signature and verification refuses. This is what the verifier proxy enforces before forwarding to Anthropic.

Verifier · local proxy stats

Point si-didy at http://127.0.0.1:4319/v1/messages. This panel pulls live stats from the running verifier.

–
accepted
–
rejected
–
forwarded
–
top reason
unknown

Integration · one hook

Wire si-didy's fetch layer through SiDidySigner.wrap():

import { SiDidySigner } from './si-didy-signer.js';
const signer = new SiDidySigner({ source: 'idb' });
await signer.loadKey();

// wherever si-didy calls Claude:
const signed = await signer.wrap({
  method:  'POST',
  headers: { 'content-type': 'application/json', 'x-api-key': ANTHROPIC_KEY },
  body:    JSON.stringify(payload)
});
const res = await fetch('https://api.anthropic.com/v1/messages', signed);
// or point at http://127.0.0.1:4319/v1/messages for local verify-and-forward