Quickstart
Five minutes from nothing to a working node. You need Docker with Compose, Go, Rust (cargo), and SSH access to the private identity module (see CONTRIBUTING.md).
make identity-proxy # fetch the identity module on this machine, for the image buildmake limitd-vendor # and the limits sidecar's crates, which include the identity's hdtp-limitsdocker compose up -d # the node and its limits sidecar (SPEC §5.7)docker compose logs hdtp-gateway | grep -A2 "setup"The log prints your portal URL and a one-time setup token. Open it — the
wizard registers your first passkey, which is the node’s only login, on every
bind including loopback. Register a second on another device: there is
deliberately no online recovery path. If you lose them all, recovery needs shell
access on the host — hdtp-gateway passkey reset-wizard mints a one-time link
that re-opens registration.
Then create the identity people will reach, and have your wallet certify this node for it (see Your wallet):
docker compose exec hdtp-gateway hdtp-gateway account create --slug me --name "Your Name"docker compose exec -T hdtp-gateway hdtp-gateway account csr --slug me > me.csrhdtp id create --name "Your Name" --vault me.hdtp-vault.jsonhdtp id issue --vault me.hdtp-vault.json --csr me.csr --chain-out chain.pemdocker compose cp chain.pem hdtp-gateway:/tmp/chain.pemdocker compose exec hdtp-gateway hdtp-gateway account install-leaf --slug me --chain /tmp/chain.pemOpen Card in the portal and download me.vcf. That is what you hand to people. Until the chain is
installed there is no card: the page says the account has no certificate yet.
This quickstart is not prose someone hopes still works. An automated scenario builds these images, drives the portal through a real Chrome, registers a passkey with a virtual authenticator, and pairs a contact. Running it as written is how three bugs in it were found.