# Your wallet

> Your identity is a root, and the root lives in your wallet, never on this node.

Your identity is a **root**, and the root lives in your **wallet**, never on this node. The node
holds a **leaf**: a certificate your root issues to this host, for one address, until one date
(HDTP §9, §14.1). The node makes the request, the wallet signs it, the node installs the answer:

```
hdtp-gateway account csr -slug me > me.csr              # the request: this host's key and address
hdtp id issue --vault me.hdtp-vault.json --csr me.csr --chain-out chain.pem
hdtp-gateway account install-leaf -slug me -chain chain.pem
```

The wallet a self-hoster uses is the `hdtp` CLI from hdtp-identity. `hdtp id create` makes the root
once, in a vault file under a passphrase; `hdtp id issue` shows what a request names and asks
before it signs. `account csr` prints only the request on its standard output (what it is for goes
to standard error), and `install-leaf` takes the two certificates `--chain-out` writes, leaf then
root. `account csr -slug me -purpose renew` asks for the next leaf before this one runs out, and
`-purpose move` for a leaf at a new address.

The root never comes to this node, and nothing here can make one: losing the vault and its
passphrase is losing that identity.

**A web wallet, from the portal.** Once an identity has its first leaf, *Identity → Sign with my
web wallet* asks a web wallet (`HDTP_WALLET_URL`, `https://ceremony.hdtp.io` by default) for the
next one: a renewal, or a move when the address changes. The page shows what it will ask and
changes nothing until you continue; a request already waiting is replaced only if you confirm it.
The wallet sends its answer back to this node's `/wallet/return` in the same browser, and the
portal installs it with your session. This is the node's side of it. The wallet's `/sign` page is
BatonDeck's and is not live yet, and how browsers treat a public page sending you back to
`http://localhost` has not been measured, so until both are, use the `hdtp` CLI.

**After a move.** When an install moves the identity to a new address, both the CLI and the portal
say so, and say to run `hdtp-gateway account announce -slug me` until no contact is waiting: the
previous certificate stays valid until its own date for contacts not yet told. When the identity
came from another host, that is also when to delete it there. When this node itself moved to a new
address, there is nothing to delete: the previous certificate goes on answering here until it
expires.
