# Quickstart

> Five minutes from nothing to a working node.

Five minutes from nothing to a working node. You need Docker with Compose, Go, Rust (cargo), and
SSH access to the private identity module (see CONTRIBUTING.md).

```
make identity-proxy     # fetch the identity module on this machine, for the image build
make limitd-vendor      # and the limits sidecar's crates, which include the identity's hdtp-limits
docker compose up -d    # the node and its limits sidecar (SPEC §5.7)
docker compose logs hdtp-gateway | grep -A2 "setup"
```

The log prints your portal URL and a **one-time setup token**. Open it — the
wizard registers your first **passkey**, which is the node's only login, on every
bind including loopback. Register a second on another device: there is
deliberately no online recovery path. If you lose them all, recovery needs shell
access on the host — `hdtp-gateway passkey reset-wizard` mints a one-time link
that re-opens registration.

Then create the identity people will reach, and have your wallet certify this node for it (see
[Your wallet](/gateway/how-to/your-wallet/)):

```
docker compose exec hdtp-gateway hdtp-gateway account create --slug me --name "Your Name"
docker compose exec -T hdtp-gateway hdtp-gateway account csr --slug me > me.csr
hdtp id create --name "Your Name" --vault me.hdtp-vault.json
hdtp id issue --vault me.hdtp-vault.json --csr me.csr --chain-out chain.pem
docker compose cp chain.pem hdtp-gateway:/tmp/chain.pem
docker compose exec hdtp-gateway hdtp-gateway account install-leaf --slug me --chain /tmp/chain.pem
```

Open *Card* in the portal and download `me.vcf`. That is what you hand to people. Until the chain is
installed there is no card: the page says the account has no certificate yet.

> This quickstart is not prose someone hopes still works. An automated scenario
> builds these images, drives the portal through a real Chrome, registers a
> passkey with a virtual authenticator, and pairs a contact. Running it as written
> is how three bugs in it were found.
