HDTP
The normative text of the protocol is published at hdtp.io/spec, with every MUST listed at /spec/musts and the test vectors at /spec/vectors. What follows is the protocol repository’s own summary.
- Identity — a self-signed root certificate you hold, pinned by its fingerprint. The host you choose serves you under a leaf your root issued for its address, valid for as long as you choose up to 398 days; contacts learn each renewed leaf from the chain, carried once and named by fingerprint after. Every call is mTLS with the leaf key.
- Contacts — standard vCards with
X-HDTP-CERT; shared over channels people already use; always mutual, always human-approved. - Invites — short URLs/QRs whose settings (expiry, max uses, auto-accept, preset) live server-side, so they’re revocable at the protocol level.
- Capabilities — everything a contact may do is an MCP tool, filtered per caller via
tools/list; new integrations are just new tools. - Delivery — direct HTTPS, always; there is no relay. A person who must be reachable while their own machine is off is hosted by a provider under a leaf they issued and can leave (§9).
Learn the protocol
Section titled “Learn the protocol”The guided pages on hdtp.io, one per topic: