Skip to content

HDTP

View as Markdown

The normative text of the protocol is published at hdtp.io/spec, with every MUST listed at /spec/musts and the test vectors at /spec/vectors. What follows is the protocol repository’s own summary.

  1. Identity — a self-signed root certificate you hold, pinned by its fingerprint. The host you choose serves you under a leaf your root issued for its address, valid for as long as you choose up to 398 days; contacts learn each renewed leaf from the chain, carried once and named by fingerprint after. Every call is mTLS with the leaf key.
  2. Contacts — standard vCards with X-HDTP-CERT; shared over channels people already use; always mutual, always human-approved.
  3. Invites — short URLs/QRs whose settings (expiry, max uses, auto-accept, preset) live server-side, so they’re revocable at the protocol level.
  4. Capabilities — everything a contact may do is an MCP tool, filtered per caller via tools/list; new integrations are just new tools.
  5. Delivery — direct HTTPS, always; there is no relay. A person who must be reachable while their own machine is off is hosted by a provider under a leaf they issued and can leave (§9).

The guided pages on hdtp.io, one per topic: