{
  "name": "forge-identity",
  "language": "rust",
  "version": "0.2.0",
  "description": "OAS identity binding for Forge agents \u2014 ANVIL Spec \u00a711.1-11.2",
  "manifest": "forge-rs/crates/forge-identity/Cargo.toml",
  "manifestSha256": "57e3544070ac91e9296c549c8638683324eeacd8f4853bc6ca7c7299acce5f60",
  "status": "source-reference",
  "registryPublicationVerified": false,
  "route": "/libraries/rust/forge-identity",
  "features": {},
  "files": [
    {
      "path": "forge-rs/crates/forge-identity/src/agent_identity.rs",
      "sha256": "e88967a6f4dd208e88f23046a063c8f4ad2cf674ea688af6bf430c8c7f50b251",
      "artifactSha256": "68f17ba0395368a9b061605f36e8baaa04b5ddf92a207fc583386cc1ac276fc7",
      "url": "/reference/source/forge-rs/crates/forge-identity/src/agent_identity.rs.txt",
      "declarations": [
        {
          "name": "::ForgeAgentIdentity",
          "line": 63,
          "signature": "pub struct ForgeAgentIdentity {\n\n}",
          "documentation": "A Forge agent's cryptographic identity, binding an OAS DID, keypair, and lineage.\n\nEvery Forge agent has a `ForgeAgentIdentity` from creation. The identity\nincludes the agent's Ed25519 keypair (derived via HKDF-SHA256 from its parent),\nthe OAS DID document, and the lineage proof chain.\n\nSee ANVIL Specification \u00a711.1 \u2014 OAS Identity Binding.\n\n# Security\n\n- The [`Debug`] implementation never exposes the private key.\n- Clone creates an independent copy of the keypair.\n- The signing key is zeroized on drop (via `OasKeyPair`'s inner `SigningKey`).\n\n# Examples\n\n```\nuse forge_identity::lineage::{create_hmr_identity, derive_agent_identity};\n\nlet hmr = create_hmr_identity(\"test\", \"alice\").unwrap();\nlet agent = derive_agent_identity(&hmr, \"analyzer\", \"test\").unwrap();\nassert_eq!(agent.kind(), \"agent\");\nassert_eq!(agent.lineage_depth(), 1);\n```"
        },
        {
          "name": "::ForgeAgentIdentity::new",
          "line": 137,
          "signature": "pub fn new(\n        did: String,\n        kind: String,\n        keypair: OasKeyPair,\n        document: OasDocument,\n        lineage_depth: u32,\n    ) -> ForgeIdentityResult<Self>;",
          "documentation": "Creates a new `ForgeAgentIdentity` from its constituent parts.\n\nThis is the internal constructor used by the [`lineage`](crate::lineage) module.\nExternal callers should use [`create_hmr_identity`](crate::lineage::create_hmr_identity)\nor [`derive_agent_identity`](crate::lineage::derive_agent_identity) instead.\n\n# Arguments\n\n* `did` - The `did:oas` identifier string.\n* `kind` - The entity kind (e.g., `\"hmr\"`, `\"agent\"`).\n* `keypair` - The Ed25519 keypair for this identity.\n* `document` - The signed OAS Identity Document.\n* `lineage_depth` - The number of derivation steps from the human root.\n\n# Returns\n\nA validated `ForgeAgentIdentity`.\n\n# Errors\n\nReturns [`ForgeIdentityError::InvalidIdentity`] if the DID is empty or\nthe document ID does not match the provided DID.\n\n# Examples\n\n```\nuse forge_identity::lineage::create_hmr_identity;\n\n// Prefer using the high-level creation functions:\nlet identity = create_hmr_identity(\"test\", \"alice\").unwrap();\nassert_eq!(identity.did(), \"did:oas:test:hmr:alice\");\n```"
        },
        {
          "name": "::ForgeAgentIdentity::did",
          "line": 178,
          "signature": "pub fn did(&self) -> &str;",
          "documentation": "Returns the `did:oas` identifier string for this agent.\n\n# Examples\n\n```\nuse forge_identity::lineage::create_hmr_identity;\n\nlet hmr = create_hmr_identity(\"test\", \"alice\").unwrap();\nassert_eq!(hmr.did(), \"did:oas:test:hmr:alice\");\n```"
        },
        {
          "name": "::ForgeAgentIdentity::kind",
          "line": 192,
          "signature": "pub fn kind(&self) -> &str;",
          "documentation": "Returns the entity kind (e.g., `\"hmr\"`, `\"mhr\"`, `\"agent\"`, `\"tool\"`).\n\n# Examples\n\n```\nuse forge_identity::lineage::create_hmr_identity;\n\nlet hmr = create_hmr_identity(\"test\", \"alice\").unwrap();\nassert_eq!(hmr.kind(), \"hmr\");\n```"
        },
        {
          "name": "::ForgeAgentIdentity::document",
          "line": 211,
          "signature": "pub fn document(&self) -> &OasDocument;",
          "documentation": "Returns a reference to the signed OAS Identity Document.\n\nThe document contains the full DID document structure including\nverification methods, authentication references, lineage section,\nand document proof.\n\n# Examples\n\n```\nuse forge_identity::lineage::create_hmr_identity;\n\nlet hmr = create_hmr_identity(\"test\", \"alice\").unwrap();\nlet doc = hmr.document();\nassert!(doc.proof.is_some());\n```"
        },
        {
          "name": "::ForgeAgentIdentity::lineage_depth",
          "line": 234,
          "signature": "pub fn lineage_depth(&self) -> u32;",
          "documentation": "Returns the lineage depth (number of derivation steps from human root).\n\n- `0` for HMR and MHR root entities.\n- `1` for agents derived directly from a root.\n- `n` for agents `n` steps removed from the root.\n\nSee ANVIL Spec \u00a711.2 \u2014 Lineage Propagation.\n\n# Examples\n\n```\nuse forge_identity::lineage::{create_hmr_identity, derive_agent_identity};\n\nlet hmr = create_hmr_identity(\"test\", \"alice\").unwrap();\nassert_eq!(hmr.lineage_depth(), 0);\n\nlet agent = derive_agent_identity(&hmr, \"bot\", \"test\").unwrap();\nassert_eq!(agent.lineage_depth(), 1);\n```"
        },
        {
          "name": "::ForgeAgentIdentity::sign",
          "line": 261,
          "signature": "pub fn sign(&self, message: &[u8]) -> Vec<u8>;",
          "documentation": "Signs a message with this agent's Ed25519 signing key.\n\nThe returned bytes are a 64-byte Ed25519 signature. Use\n[`verify`](Self::verify) or [`OasKeyPair::verify_with_key`] to\nverify the signature against this agent's public key.\n\n# Arguments\n\n* `message` - The raw bytes to sign.\n\n# Returns\n\nA 64-byte Ed25519 signature as a `Vec<u8>`.\n\n# Examples\n\n```\nuse forge_identity::lineage::create_hmr_identity;\n\nlet hmr = create_hmr_identity(\"test\", \"alice\").unwrap();\nlet sig = hmr.sign(b\"audit trail entry\");\nassert_eq!(sig.len(), 64);\n```"
        },
        {
          "name": "::ForgeAgentIdentity::verify",
          "line": 294,
          "signature": "pub fn verify(&self, message: &[u8], signature: &[u8]) -> ForgeIdentityResult<()>;",
          "documentation": "Verifies an Ed25519 signature against this agent's public key.\n\nUses constant-time comparison internally (provided by `ed25519-dalek`).\n\n# Arguments\n\n* `message` - The original message that was signed.\n* `signature` - The 64-byte Ed25519 signature to verify.\n\n# Returns\n\n`Ok(())` if the signature is valid.\n\n# Errors\n\nReturns [`ForgeIdentityError::InvalidIdentity`] if the signature\ndoes not verify against this agent's public key.\n\n# Examples\n\n```\nuse forge_identity::lineage::create_hmr_identity;\n\nlet hmr = create_hmr_identity(\"test\", \"alice\").unwrap();\nlet message = b\"audit trail entry\";\nlet sig = hmr.sign(message);\nassert!(hmr.verify(message, &sig).is_ok());\nassert!(hmr.verify(b\"tampered\", &sig).is_err());\n```"
        },
        {
          "name": "::ForgeAgentIdentity::verifying_key_bytes",
          "line": 316,
          "signature": "pub fn verifying_key_bytes(&self) -> [u8; 32];",
          "documentation": "Returns the raw 32-byte Ed25519 verifying (public) key bytes.\n\nThis is the agent's public key that can be shared freely. Use it\nto verify signatures produced by [`sign`](Self::sign).\n\n# Examples\n\n```\nuse forge_identity::lineage::create_hmr_identity;\n\nlet hmr = create_hmr_identity(\"test\", \"alice\").unwrap();\nlet pub_key = hmr.verifying_key_bytes();\nassert_eq!(pub_key.len(), 32);\n```"
        }
      ]
    },
    {
      "path": "forge-rs/crates/forge-identity/src/error.rs",
      "sha256": "61fd83dc1e7edbeb21cd24433915ca3d33a8c6199df7a52e99a673a59dff2e5b",
      "artifactSha256": "9be9c093fa19c1a0cafb91aa29e54aabe5ce756b9f0b4192910beff12fd14cdb",
      "url": "/reference/source/forge-rs/crates/forge-identity/src/error.rs.txt",
      "declarations": [
        {
          "name": "::ForgeIdentityError",
          "line": 44,
          "signature": "#[derive(Debug, Error)]\npub enum ForgeIdentityError {\n    /// HKDF key derivation failed for the specified derivation path.\n    ///\n    /// This indicates a failure in the cryptographic key derivation process\n    /// when creating a child agent identity from a parent.\n    ///\n    /// See ANVIL Spec \u00a711.1 \u2014 OAS Identity Binding.\n    #[error(\"identity derivation failed for path '{path}' from parent {parent_did}: {reason}\")]\n    DerivationFailed {\n        /// The parent's DID from which derivation was attempted.\n        parent_did: String,\n        /// The HKDF derivation path that was used.\n        path: String,\n        /// A description of why the derivation failed.\n        reason: String,\n    },\n\n    /// Lineage chain verification failed for the specified identity.\n    ///\n    /// The cryptographic chain from the agent to its human root could not\n    /// be verified. This may indicate a tampered identity, a missing parent\n    /// document, or an invalid proof signature.\n    ///\n    /// See ANVIL Spec \u00a711.2 \u2014 Lineage Propagation.\n    #[error(\"lineage verification failed for '{did}': {reason}\")]\n    LineageVerificationFailed {\n        /// The DID of the identity whose lineage failed verification.\n        did: String,\n        /// A description of why verification failed.\n        reason: String,\n    },\n\n    /// Lineage chain exceeds the maximum allowed generation depth.\n    ///\n    /// ANVIL Spec \u00a711.2 defines a maximum lineage depth to prevent\n    /// unbounded delegation chains. The default maximum is 16.\n    #[error(\"lineage chain depth {depth} exceeds ANVIL maximum {max_depth} (ANVIL Spec \u00a711.2)\")]\n    ChainTooDeep {\n        /// The actual depth of the lineage chain.\n        depth: u32,\n        /// The configured maximum depth.\n        max_depth: u32,\n    },\n\n    /// The identity is malformed or fails structural validation.\n    ///\n    /// This covers cases like missing DID fields, invalid document structure,\n    /// or inconsistent lineage sections.\n    #[error(\"invalid identity: {reason}\")]\n    InvalidIdentity {\n        /// A description of the structural problem.\n        reason: String,\n    },\n\n    /// Saving or loading an identity to/from persistent storage failed.\n    ///\n    /// This may indicate I/O errors, permission problems, or corrupted\n    /// identity files on disk.\n    #[error(\"identity persistence failed: {reason}\")]\n    PersistenceFailed {\n        /// A description of the persistence failure.\n        reason: String,\n    },\n\n    /// An error propagated from the underlying OAS SDK.\n    ///\n    /// This wraps [`oas_sdk::OasError`] for seamless `?` propagation\n    /// from OAS SDK calls within forge-identity functions.\n    #[error(\"OAS SDK error: {0}\")]\n    Oas(#[from] oas_sdk::OasError),\n}",
          "documentation": "Errors that can occur during Forge agent identity operations.\n\nEvery variant includes actionable context: what failed, why, and the\nrelevant ANVIL specification section. No generic \"something went wrong\"\nmessages.\n\n# ANVIL Spec References\n\n- ANVIL Spec \u00a711.1 \u2014 OAS Identity Binding\n- ANVIL Spec \u00a711.2 \u2014 Lineage Propagation\n- ANVIL Spec \u00a714.2 \u2014 Error Handling"
        },
        {
          "name": "::ForgeIdentityResult",
          "line": 127,
          "signature": "pub type ForgeIdentityResult<T> = Result<T, ForgeIdentityError>;",
          "documentation": "A specialized `Result` type for forge-identity operations.\n\n# Examples\n\n```\nuse forge_identity::error::ForgeIdentityResult;\n\nfn example() -> ForgeIdentityResult<String> {\n    Ok(\"identity created\".to_string())\n}\n```"
        }
      ]
    },
    {
      "path": "forge-rs/crates/forge-identity/src/glyph/error.rs",
      "sha256": "543f458b5a772bb2fd0f0a9d79e4e8bba9bd7dfb2a6a491cad4329689d8b24d6",
      "artifactSha256": "b15713b303740baba5ad89a46655478548d3934eaeacac27f2bc94617b4f8960",
      "url": "/reference/source/forge-rs/crates/forge-identity/src/glyph/error.rs.txt",
      "declarations": [
        {
          "name": "::GlyphError",
          "line": 25,
          "signature": "#[derive(Debug, Error)]\npub enum GlyphError {\n    /// The provided DID string is malformed or unparseable.\n    #[error(\"invalid DID '{did}': {reason}\")]\n    InvalidDid {\n        /// The DID string that failed validation.\n        did: String,\n        /// Why the DID is invalid.\n        reason: String,\n    },\n\n    /// The entity kind string does not map to a known glyph kind.\n    #[error(\"invalid glyph entity kind '{kind}': expected one of hmr, mhr, enr, agent, org\")]\n    InvalidKind {\n        /// The kind string that was not recognized.\n        kind: String,\n    },\n\n    /// Payload encoding failed.\n    #[error(\"glyph payload encoding failed for DID '{did}': {reason}\")]\n    PayloadEncodingFailed {\n        /// The DID being encoded.\n        did: String,\n        /// Why encoding failed.\n        reason: String,\n    },\n\n    /// Rendering the glyph to the requested output format failed.\n    #[error(\"glyph render failed: {reason}\")]\n    RenderFailed {\n        /// Why rendering failed.\n        reason: String,\n    },\n}",
          "documentation": "Errors that can occur during glyph operations.\n\nEvery variant provides enough context for a developer to diagnose\nthe issue without reading source code.\n\n# Examples\n\n```\nuse forge_identity::glyph::error::GlyphError;\n\nlet err = GlyphError::InvalidDid {\n    did: \"not-a-did\".to_string(),\n    reason: \"expected 'did:' prefix\".to_string(),\n};\nassert!(err.to_string().contains(\"not-a-did\"));\n```"
        },
        {
          "name": "::GlyphResult",
          "line": 60,
          "signature": "pub type GlyphResult<T> = Result<T, GlyphError>;",
          "documentation": "A specialized `Result` type for glyph operations."
        }
      ]
    },
    {
      "path": "forge-rs/crates/forge-identity/src/glyph/mod.rs",
      "sha256": "685cb3c462875bb7a4fcf47200bcf60a0d751b92cb61a63273372c2ca4ae4476",
      "artifactSha256": "32528096f6e839f9dd8430f371daaba7bfc0a44b1f804978db5bae173c975f54",
      "url": "/reference/source/forge-rs/crates/forge-identity/src/glyph/mod.rs.txt",
      "declarations": [
        {
          "name": "error",
          "line": 56,
          "signature": "pub mod error;",
          "documentation": "# Glyph \u2014 Visual Identity for Forge Agents\n\nDeterministic visual identity glyphs for OAS agents, implementing the\nglyph contract from the Forge coding-provider and glyph implementation\nplan (Phase 5).\n\nA glyph is a scannable, aesthetically unique avatar that encodes an\nagent's `did:oas` identity into a colored block grid. Unlike QR codes,\nglyphs use variable block sizes, shapes, and colors to create a visually\ndistinctive pattern that doubles as a profile picture.\n\n## Encoding Architecture\n\nThe glyph encodes data across three visual channels per cell:\n\n- **Block size** (4 levels) -- 2 bits per cell\n- **Shape** (square, circle, diamond, triangle) -- 2 bits per cell\n- **Hue shift** (4 palette variations) -- 2 bits per cell\n\nThis yields 6 bits per cell in a 12x12 grid.\n\n## Determinism Guarantee\n\nSame DID + same options = identical output bytes. This is enforced by:\n\n1. BLAKE3-hashing the DID components for the payload.\n2. Deriving the palette from the payload hash (no randomness).\n3. Rendering the grid with deterministic float formatting.\n\n## Quick Start\n\n```\nuse forge_identity::glyph::{\n    GlyphDescriptor, GlyphEntityKind, GlyphRenderOptions,\n    GlyphRenderTarget, render::render_glyph,\n};\n\nlet descriptor = GlyphDescriptor {\n    did: \"did:oas:l1fe:agent:data-analyst\".to_string(),\n    kind: GlyphEntityKind::Agent,\n    label: Some(\"Data Analyst\".to_string()),\n};\n\nlet options = GlyphRenderOptions {\n    target: GlyphRenderTarget::Web,\n    width: Some(256),\n    height: Some(256),\n    color_override: None,\n};\n\nlet result = render_glyph(&descriptor, &options).unwrap();\nlet svg = result.svg_data().unwrap();\nassert!(svg.starts_with(\"<svg\"));\n```"
        },
        {
          "name": "palette",
          "line": 57,
          "signature": "pub mod palette;",
          "documentation": ""
        },
        {
          "name": "payload",
          "line": 58,
          "signature": "pub mod payload;",
          "documentation": ""
        },
        {
          "name": "render",
          "line": 59,
          "signature": "pub mod render;",
          "documentation": ""
        },
        {
          "name": "pub use error::{GlyphError, GlyphResult};",
          "line": 61,
          "signature": "pub use error::{GlyphError, GlyphResult};",
          "documentation": ""
        },
        {
          "name": "pub use palette::{GlyphColor, GlyphPalette};",
          "line": 62,
          "signature": "pub use palette::{GlyphColor, GlyphPalette};",
          "documentation": ""
        },
        {
          "name": "::GlyphDescriptor",
          "line": 81,
          "signature": "#[derive(Debug, Clone, serde::Serialize, serde::Deserialize)]\npub struct GlyphDescriptor {\n/// The agent's DID string (e.g. `did:oas:l1fe:agent:data-analyst`).\n\npub did: String,\n/// The entity kind that determines the kind-region visual motif.\n\npub kind: GlyphEntityKind,\n/// Optional human-readable label rendered below the glyph.\n\npub label: Option<String>\n}",
          "documentation": "The glyph input contract: describes what to render.\n\nA `GlyphDescriptor` captures the agent DID, entity kind, and an optional\nhuman-readable label. This is the input to [`render::render_glyph`].\n\n# Examples\n\n```\nuse forge_identity::glyph::{GlyphDescriptor, GlyphEntityKind};\n\nlet desc = GlyphDescriptor {\n    did: \"did:oas:l1fe:agent:data-analyst\".to_string(),\n    kind: GlyphEntityKind::Agent,\n    label: Some(\"Data Analyst\".to_string()),\n};\n```"
        },
        {
          "name": "::GlyphEntityKind",
          "line": 114,
          "signature": "#[derive(Debug, Clone, Copy, PartialEq, Eq, Hash, serde::Serialize, serde::Deserialize)]\npub enum GlyphEntityKind {\n    /// Human Root identity.\n    Hmr,\n    /// Multi-Human Root identity.\n    Mhr,\n    /// Entity Root identity (organizations, services, etc.).\n    Enr,\n    /// Agent identity.\n    Agent,\n    /// Organization identity.\n    Org,\n}",
          "documentation": "Entity kinds supported by the glyph system.\n\nMaps to the upstream `oas-glyph` entity kind taxonomy, restricted to\nthe five kinds relevant to the Forge identity surface:\n\n| Kind | Upstream Value | Visual Motif |\n|------|---------------|-------------|\n| `Hmr` | 0 | Shield (human root) |\n| `Mhr` | 1 | Multi-shield (machine root) |\n| `Enr` | 2 | Grid (entity root) |\n| `Agent` | 3 | Diamond (agent) |\n| `Org` | 4 | Hexagon (organization) |\n\n# Examples\n\n```\nuse forge_identity::glyph::GlyphEntityKind;\n\nlet kind = GlyphEntityKind::parse_kind(\"agent\").unwrap();\nassert_eq!(kind, GlyphEntityKind::Agent);\nassert_eq!(kind.as_str(), \"agent\");\nassert_eq!(kind.as_u8(), 3);\n```"
        },
        {
          "name": "::GlyphEntityKind::parse_kind",
          "line": 146,
          "signature": "pub fn parse_kind(s: &str) -> Option<Self>;",
          "documentation": "Parse a kind string into a `GlyphEntityKind`.\n\n# Arguments\n\n* `s` - A lowercase kind string.\n\n# Returns\n\n`Some(kind)` if the string matches a known kind, `None` otherwise.\n\n# Examples\n\n```\nuse forge_identity::glyph::GlyphEntityKind;\n\nassert_eq!(GlyphEntityKind::parse_kind(\"hmr\"), Some(GlyphEntityKind::Hmr));\nassert_eq!(GlyphEntityKind::parse_kind(\"unknown\"), None);\n```"
        },
        {
          "name": "::GlyphEntityKind::as_str",
          "line": 166,
          "signature": "pub fn as_str(&self) -> &'static str;",
          "documentation": "Return the canonical string representation of this kind.\n\n# Examples\n\n```\nuse forge_identity::glyph::GlyphEntityKind;\n\nassert_eq!(GlyphEntityKind::Agent.as_str(), \"agent\");\n```"
        },
        {
          "name": "::GlyphEntityKind::as_u8",
          "line": 189,
          "signature": "pub fn as_u8(&self) -> u8;",
          "documentation": "Return the numeric value used in payload encoding.\n\nValues 0-4 match the upstream `oas-glyph` `EntityKind` discriminants\nfor the supported subset.\n\n# Examples\n\n```\nuse forge_identity::glyph::GlyphEntityKind;\n\nassert_eq!(GlyphEntityKind::Hmr.as_u8(), 0);\nassert_eq!(GlyphEntityKind::Agent.as_u8(), 3);\n```"
        },
        {
          "name": "::GlyphEntityKind::from_u8",
          "line": 211,
          "signature": "pub fn from_u8(v: u8) -> Option<Self>;",
          "documentation": "Reconstruct a `GlyphEntityKind` from its numeric value.\n\nReturns `None` if the value does not map to a known kind.\n\n# Examples\n\n```\nuse forge_identity::glyph::GlyphEntityKind;\n\nassert_eq!(GlyphEntityKind::from_u8(3), Some(GlyphEntityKind::Agent));\nassert_eq!(GlyphEntityKind::from_u8(99), None);\n```"
        },
        {
          "name": "::GlyphRenderTarget",
          "line": 238,
          "signature": "#[derive(Debug, Clone, Copy, PartialEq, Eq, serde::Serialize, serde::Deserialize)]\npub enum GlyphRenderTarget {\n    /// SVG output for web rendering.\n    Web,\n    /// ANSI-colored terminal output.\n    Terminal,\n}",
          "documentation": "Render target selection.\n\nDetermines the output format of the glyph rendering:\n\n- `Web` produces a self-contained SVG string.\n- `Terminal` produces ANSI-colored block characters.\n\n# Examples\n\n```\nuse forge_identity::glyph::GlyphRenderTarget;\n\nlet target = GlyphRenderTarget::Web;\n```"
        },
        {
          "name": "::GlyphRenderOptions",
          "line": 260,
          "signature": "#[derive(Debug, Clone, serde::Serialize, serde::Deserialize)]\npub struct GlyphRenderOptions {\n/// The render target (Web or Terminal).\n\npub target: GlyphRenderTarget,\n/// Desired width in pixels (Web) or columns (Terminal). Defaults to 512/12.\n\npub width: Option<u32>,\n/// Desired height in pixels (Web) or rows (Terminal). Defaults to 512/6.\n\npub height: Option<u32>,\n/// Optional background color override. If `None`, the palette-derived\n\n/// background is used.\n\npub color_override: Option<palette::GlyphColor>\n}",
          "documentation": "Render options controlling the glyph output.\n\n# Examples\n\n```\nuse forge_identity::glyph::{GlyphRenderOptions, GlyphRenderTarget};\n\nlet options = GlyphRenderOptions {\n    target: GlyphRenderTarget::Web,\n    width: Some(512),\n    height: Some(512),\n    color_override: None,\n};\n```"
        },
        {
          "name": "::GlyphRenderFormat",
          "line": 276,
          "signature": "#[derive(Debug, Clone, Copy, PartialEq, Eq, serde::Serialize, serde::Deserialize)]\npub enum GlyphRenderFormat {\n    /// Self-contained SVG XML string.\n    Svg,\n    /// PNG image bytes.\n    Png,\n    /// ASCII art (plain text).\n    AsciiArt,\n    /// Braille dot pattern.\n    Braille,\n    /// ANSI half-block characters.\n    HalfBlock,\n}",
          "documentation": "Output format tag for render results.\n\nDescribes the actual format of the rendered data bytes."
        },
        {
          "name": "::GlyphRenderResult",
          "line": 307,
          "signature": "#[derive(Debug, Clone, serde::Serialize, serde::Deserialize)]\npub struct GlyphRenderResult {\n/// The output format.\n\npub format: GlyphRenderFormat,\n/// The rendered data bytes.\n\npub data: Vec<u8>,\n/// Width of the rendered output (pixels for SVG/PNG, columns for terminal).\n\npub width: u32,\n/// Height of the rendered output (pixels for SVG/PNG, rows for terminal).\n\npub height: u32\n}",
          "documentation": "The output of a glyph render operation.\n\nContains the rendered data bytes, format tag, and dimensions.\n\n# Examples\n\n```\nuse forge_identity::glyph::{GlyphRenderResult, GlyphRenderFormat};\n\nlet result = GlyphRenderResult {\n    format: GlyphRenderFormat::Svg,\n    data: b\"<svg>...</svg>\".to_vec(),\n    width: 256,\n    height: 256,\n};\nassert!(result.svg_data().is_some());\n```"
        },
        {
          "name": "::GlyphRenderResult::svg_data",
          "line": 337,
          "signature": "pub fn svg_data(&self) -> Option<String>;",
          "documentation": "Extract the rendered data as a UTF-8 string, if the format is text-based.\n\nReturns `Some(string)` for SVG, AsciiArt, Braille, and HalfBlock formats.\nReturns `None` for binary formats like PNG.\n\n# Examples\n\n```\nuse forge_identity::glyph::{GlyphRenderResult, GlyphRenderFormat};\n\nlet result = GlyphRenderResult {\n    format: GlyphRenderFormat::Svg,\n    data: b\"<svg></svg>\".to_vec(),\n    width: 256,\n    height: 256,\n};\nassert_eq!(result.svg_data(), Some(\"<svg></svg>\".to_string()));\n```"
        }
      ]
    },
    {
      "path": "forge-rs/crates/forge-identity/src/glyph/palette.rs",
      "sha256": "8624b8f4d25846bb3aa37a9907674b03e03ab40b1c0c2c0579c7e97dd5492fcf",
      "artifactSha256": "8daebc73a5847608193130b07e53452fd0560bfe22893a351f7c1233b88b63eb",
      "url": "/reference/source/forge-rs/crates/forge-identity/src/glyph/palette.rs.txt",
      "declarations": [
        {
          "name": "::GlyphColor",
          "line": 31,
          "signature": "#[derive(Debug, Clone, Copy, PartialEq, Eq, serde::Serialize, serde::Deserialize)]\npub struct GlyphColor {\n/// Red channel (0-255).\n\npub r: u8,\n/// Green channel (0-255).\n\npub g: u8,\n/// Blue channel (0-255).\n\npub b: u8\n}",
          "documentation": "An RGB color triple.\n\nAll channels are 8-bit unsigned (0-255). Alpha is not stored because\nglyph rendering always uses fully opaque colors; the SVG renderer adds\nopacity through element-level attributes if needed.\n\n# Examples\n\n```\nuse forge_identity::glyph::palette::GlyphColor;\n\nlet red = GlyphColor { r: 255, g: 0, b: 0 };\nassert_eq!(red.to_hex(), \"#ff0000\");\n```"
        },
        {
          "name": "::GlyphColor::rgb",
          "line": 42,
          "signature": "pub fn rgb(r: u8, g: u8, b: u8) -> Self;",
          "documentation": "Create a color from RGB components."
        },
        {
          "name": "::GlyphColor::to_hex",
          "line": 56,
          "signature": "pub fn to_hex(&self) -> String;",
          "documentation": "Format as a CSS hex color string (e.g. `#ff8040`).\n\n# Examples\n\n```\nuse forge_identity::glyph::palette::GlyphColor;\n\nlet c = GlyphColor::rgb(255, 128, 64);\nassert_eq!(c.to_hex(), \"#ff8040\");\n```"
        },
        {
          "name": "::GlyphColor::lerp",
          "line": 94,
          "signature": "pub fn lerp(a: &GlyphColor, b: &GlyphColor, t: f64) -> Self;",
          "documentation": "Linearly interpolate between two colors.\n\n# Arguments\n\n* `a` - Start color (t=0.0).\n* `b` - End color (t=1.0).\n* `t` - Interpolation factor, clamped to [0.0, 1.0].\n\n# Examples\n\n```\nuse forge_identity::glyph::palette::GlyphColor;\n\nlet black = GlyphColor::rgb(0, 0, 0);\nlet white = GlyphColor::rgb(255, 255, 255);\nlet mid = GlyphColor::lerp(&black, &white, 0.5);\nassert!(mid.r > 100 && mid.r < 150);\n```"
        },
        {
          "name": "::GlyphPalette",
          "line": 134,
          "signature": "#[derive(Debug, Clone, serde::Serialize, serde::Deserialize)]\npub struct GlyphPalette {\n/// Primary identity color.\n\npub primary: GlyphColor,\n/// Secondary identity color (hue-offset from primary).\n\npub secondary: GlyphColor,\n/// Accent color for kind region and highlights.\n\npub accent: GlyphColor,\n/// Background color (dark, desaturated primary).\n\npub background: GlyphColor\n}",
          "documentation": "A complete glyph color palette derived from an agent's identity.\n\nThe palette is deterministically computed from the BLAKE3 hash of the\nDID payload bytes. Every field is fully determined by the payload input;\nno randomness is involved.\n\n# Palette Structure\n\n| Field | Derivation |\n|-------|-----------|\n| `primary` | HSL from hash bytes 0-3 (hue), byte 8 (saturation), byte 9 (lightness) |\n| `secondary` | HSL offset 60-180 degrees from primary hue, via hash bytes 4-7 |\n| `accent` | Bright, saturated version of secondary hue |\n| `background` | Dark, desaturated version of primary hue |\n\n# Examples\n\n```\nuse forge_identity::glyph::palette::{GlyphPalette, derive_palette};\nuse forge_identity::glyph::GlyphEntityKind;\n\nlet payload = vec![0u8; 38]; // normally from encode_did_payload\nlet palette = derive_palette(&payload, GlyphEntityKind::Agent);\n\n// Palette is deterministic\nlet palette2 = derive_palette(&payload, GlyphEntityKind::Agent);\nassert_eq!(palette.primary, palette2.primary);\nassert_eq!(palette.secondary, palette2.secondary);\n```"
        },
        {
          "name": "::derive_palette",
          "line": 178,
          "signature": "pub fn derive_palette(payload: &[u8], kind: GlyphEntityKind) -> GlyphPalette;",
          "documentation": "Derive a deterministic color palette from payload bytes and entity kind.\n\nThe palette is computed by hashing the payload with BLAKE3 and mapping\nthe resulting bytes to HSL color space. The algorithm matches the upstream\n`oas-glyph` palette derivation:\n\n1. Primary hue from bytes 0-3 (LE u32 scaled to 0-360 degrees).\n2. Secondary hue offset from bytes 4-7 (60-180 degrees from primary).\n3. Saturation from byte 8 (50-90%).\n4. Lightness from byte 9 (35-55%).\n\nThe entity kind influences the accent color intensity to provide visual\ndifferentiation between humans, machines, organizations, and agents.\n\n# Arguments\n\n* `payload` - Payload bytes from [`encode_did_payload`](super::payload::encode_did_payload).\n* `kind` - The entity kind for kind-specific accent tuning.\n\n# Returns\n\nA [`GlyphPalette`] with four deterministic colors.\n\n# Examples\n\n```\nuse forge_identity::glyph::palette::{GlyphPalette, derive_palette};\nuse forge_identity::glyph::GlyphEntityKind;\n\nlet payload = vec![42u8; 38];\nlet palette = derive_palette(&payload, GlyphEntityKind::Hmr);\nassert_ne!(palette.primary.to_hex(), palette.secondary.to_hex());\n```"
        },
        {
          "name": "::derive_palette_from_did",
          "line": 251,
          "signature": "pub fn derive_palette_from_did(did: &str, kind: GlyphEntityKind) -> GlyphPalette;",
          "documentation": "Derive a palette directly from a DID string.\n\nConvenience function that hashes the DID with BLAKE3 (matching the upstream\n`GlyphPalette::from_did` behavior) to produce a palette without first\nencoding a payload. Useful when you need colors but not the full glyph\nrendering pipeline.\n\n# Arguments\n\n* `did` - A DID string.\n* `kind` - The entity kind.\n\n# Returns\n\nA [`GlyphPalette`] deterministically derived from the DID string.\n\n# Examples\n\n```\nuse forge_identity::glyph::palette::derive_palette_from_did;\nuse forge_identity::glyph::GlyphEntityKind;\n\nlet p1 = derive_palette_from_did(\"did:oas:l1fe:agent:bot\", GlyphEntityKind::Agent);\nlet p2 = derive_palette_from_did(\"did:oas:l1fe:agent:bot\", GlyphEntityKind::Agent);\nassert_eq!(p1.primary, p2.primary);\n```"
        }
      ]
    },
    {
      "path": "forge-rs/crates/forge-identity/src/glyph/payload.rs",
      "sha256": "ba9bb563250c478d44cf7e907d7be35eb048c78cf20f179a731ce7fd3c67fbc9",
      "artifactSha256": "db5e03bd7e8992d5c8c152e4ea959316c7b9dd25ea234ae7df5c7ec5a07b102b",
      "url": "/reference/source/forge-rs/crates/forge-identity/src/glyph/payload.rs.txt",
      "declarations": [
        {
          "name": "::GLYPH_VERSION",
          "line": 29,
          "signature": "pub const GLYPH_VERSION: u8;",
          "documentation": "Glyph payload format version (4 bits, values 0-15)."
        },
        {
          "name": "::PAYLOAD_SIZE",
          "line": 34,
          "signature": "pub const PAYLOAD_SIZE: usize;",
          "documentation": "Fixed payload size in bytes.\n\n1 (header) + 1 (namespace hash) + 32 (identifier hash) + 4 (checksum) = 38."
        },
        {
          "name": "::encode_did_payload",
          "line": 67,
          "signature": "pub fn encode_did_payload(did: &str) -> GlyphResult<Vec<u8>>;",
          "documentation": "Encode a DID string into a deterministic byte payload for glyph generation.\n\nThe DID is parsed to extract the namespace, kind, and identifier components.\nEach component is hashed with BLAKE3 to produce a compact, fixed-size payload\nthat drives the glyph's visual structure.\n\n# Arguments\n\n* `did` - A DID string in the format `did:<method>:<namespace>:<kind>:<identifier>`\n\n# Returns\n\nA [`Vec<u8>`] of exactly [`PAYLOAD_SIZE`] bytes encoding the DID components.\n\n# Errors\n\nReturns [`GlyphError::InvalidDid`] if the DID string cannot be parsed.\nReturns [`GlyphError::PayloadEncodingFailed`] if encoding fails.\n\n# Examples\n\n```\nuse forge_identity::glyph::payload::encode_did_payload;\n\nlet payload = encode_did_payload(\"did:oas:l1fe:agent:data-analyst\").unwrap();\nassert_eq!(payload.len(), 38);\n\n// Deterministic: same DID always produces the same bytes\nlet payload2 = encode_did_payload(\"did:oas:l1fe:agent:data-analyst\").unwrap();\nassert_eq!(payload, payload2);\n```"
        },
        {
          "name": "::verify_payload_checksum",
          "line": 110,
          "signature": "pub fn verify_payload_checksum(payload: &[u8]) -> bool;",
          "documentation": "Verify a payload's internal checksum.\n\nReturns `true` if the last 4 bytes match the BLAKE3 checksum of the\npreceding bytes.\n\n# Arguments\n\n* `payload` - A payload previously produced by [`encode_did_payload`].\n\n# Examples\n\n```\nuse forge_identity::glyph::payload::{encode_did_payload, verify_payload_checksum};\n\nlet payload = encode_did_payload(\"did:oas:l1fe:agent:data-analyst\").unwrap();\nassert!(verify_payload_checksum(&payload));\n```"
        },
        {
          "name": "::extract_version",
          "line": 135,
          "signature": "pub fn extract_version(payload: &[u8]) -> Option<u8>;",
          "documentation": "Extract the version nibble from a payload header byte.\n\n# Arguments\n\n* `payload` - A payload previously produced by [`encode_did_payload`].\n\n# Examples\n\n```\nuse forge_identity::glyph::payload::{encode_did_payload, extract_version};\n\nlet payload = encode_did_payload(\"did:oas:l1fe:agent:data-analyst\").unwrap();\nassert_eq!(extract_version(&payload), Some(1));\n```"
        },
        {
          "name": "::extract_kind",
          "line": 154,
          "signature": "pub fn extract_kind(payload: &[u8]) -> Option<GlyphEntityKind>;",
          "documentation": "Extract the entity kind nibble from a payload header byte.\n\n# Arguments\n\n* `payload` - A payload previously produced by [`encode_did_payload`].\n\n# Examples\n\n```\nuse forge_identity::glyph::payload::{encode_did_payload, extract_kind};\nuse forge_identity::glyph::GlyphEntityKind;\n\nlet payload = encode_did_payload(\"did:oas:l1fe:agent:data-analyst\").unwrap();\nassert_eq!(extract_kind(&payload), Some(GlyphEntityKind::Agent));\n```"
        }
      ]
    },
    {
      "path": "forge-rs/crates/forge-identity/src/glyph/render.rs",
      "sha256": "bcc7fe27823af38d16358b2bc9fbef3f732fc31c92251692d5846b6010de0445",
      "artifactSha256": "19ed2a76fb4b5d847c0c47c7e76e4c2304b79d9bc3fbe37a35160a1c077994f9",
      "url": "/reference/source/forge-rs/crates/forge-identity/src/glyph/render.rs.txt",
      "declarations": [
        {
          "name": "::render_glyph",
          "line": 69,
          "signature": "pub fn render_glyph(\n    descriptor: &GlyphDescriptor,\n    options: &GlyphRenderOptions,\n) -> GlyphResult<GlyphRenderResult>;",
          "documentation": "Render a glyph from a descriptor and options.\n\nThis is the main entry point for glyph rendering. It encodes the DID\npayload, derives the color palette, constructs the grid, and renders\nto the requested target format.\n\n# Arguments\n\n* `descriptor` - The glyph input contract (DID, kind, optional label).\n* `options` - Render configuration (target, size, color override).\n\n# Returns\n\nA [`GlyphRenderResult`] containing the rendered output.\n\n# Errors\n\nReturns [`GlyphError::InvalidDid`] if the DID cannot be parsed.\nReturns [`GlyphError::RenderFailed`] if rendering fails.\n\n# Examples\n\n```\nuse forge_identity::glyph::{\n    GlyphDescriptor, GlyphEntityKind, GlyphRenderOptions, GlyphRenderTarget,\n    render::render_glyph,\n};\n\nlet descriptor = GlyphDescriptor {\n    did: \"did:oas:l1fe:agent:data-analyst\".to_string(),\n    kind: GlyphEntityKind::Agent,\n    label: Some(\"Data Analyst\".to_string()),\n};\nlet options = GlyphRenderOptions {\n    target: GlyphRenderTarget::Web,\n    width: Some(256),\n    height: Some(256),\n    color_override: None,\n};\n\nlet result = render_glyph(&descriptor, &options).unwrap();\nassert!(result.svg_data().is_some());\n```"
        }
      ]
    },
    {
      "path": "forge-rs/crates/forge-identity/src/lib.rs",
      "sha256": "a3fadc0c1eec140b607a2093c00cb88129cbb01e59c2cfe0235d82aee0b9e292",
      "artifactSha256": "eb11b2ed8b8eca76d58bf25b539403e1492da2c7db191f224dca12fab3a741ee",
      "url": "/reference/source/forge-rs/crates/forge-identity/src/lib.rs.txt",
      "declarations": [
        {
          "name": "agent_identity",
          "line": 67,
          "signature": "pub mod agent_identity;",
          "documentation": "# forge-identity\n\nOAS identity binding for Forge agents, implementing ANVIL Spec \u00a711.1\u201311.2.\n\nThis crate binds OAS (Open Agent Specification) cryptographic identities\nto Forge agents. Every agent has a `ForgeAgentIdentity` containing an\nEd25519 keypair, a signed OAS Identity Document, and a lineage proof chain\nlinking the agent back to its human root.\n\n# Components\n\n- **[`agent_identity`]** \u2014 The core [`ForgeAgentIdentity`](agent_identity::ForgeAgentIdentity)\n  struct with signing, verification, and accessor methods.\n- **[`lineage`]** \u2014 High-level workflows for creating HMR/MHR root identities,\n  deriving child agent identities, and verifying lineage chains.\n- **[`persistence`]** \u2014 Save and load identities to/from JSON files.\n- **[`error`]** \u2014 Typed error enum with actionable messages and ANVIL spec references.\n\n# Quick Start\n\n```\nuse forge_identity::prelude::*;\n\n// 1. Create a Human Root identity\nlet hmr = create_hmr_identity(\"test\", \"alice\").unwrap();\nassert_eq!(hmr.did(), \"did:oas:test:hmr:alice\");\nassert_eq!(hmr.lineage_depth(), 0);\n\n// 2. Derive an agent identity from the HMR\nlet agent = derive_agent_identity(&hmr, \"data-analyzer\", \"test\").unwrap();\nassert_eq!(agent.did(), \"did:oas:test:agent:data-analyzer\");\nassert_eq!(agent.lineage_depth(), 1);\n\n// 3. Sign and verify with the agent's key\nlet message = b\"audit trail entry\";\nlet signature = agent.sign(message);\nassert!(agent.verify(message, &signature).is_ok());\n\n// 4. Verify the lineage chain\nuse oas_lineage::provider::InMemoryProvider;\nuse oas_lineage::config::VerifyConfig;\n\nlet mut provider = InMemoryProvider::new();\nprovider.register(hmr.document().clone());\n\nlet result = verify_lineage_chain(&agent, &provider, &VerifyConfig::default());\nassert!(result.is_ok());\n```\n\n# Security\n\n- Private key material is never exposed in [`Debug`] output (`[REDACTED]`).\n- Signing keys are zeroized on drop via `ed25519-dalek`'s `ZeroizeOnDrop`.\n- All signature verification uses constant-time comparison.\n- No `unsafe` code \u2014 `#![forbid(unsafe_code)]` is enforced workspace-wide.\n- No `unwrap()`, `expect()`, or `panic!()` in library code.\n\n# ANVIL Spec References\n\n- ANVIL Spec \u00a711.1 \u2014 OAS Identity Binding\n- ANVIL Spec \u00a711.2 \u2014 Lineage Propagation\n- ANVIL Spec \u00a714.2 \u2014 Error Handling"
        },
        {
          "name": "error",
          "line": 68,
          "signature": "pub mod error;",
          "documentation": ""
        },
        {
          "name": "glyph",
          "line": 69,
          "signature": "pub mod glyph;",
          "documentation": ""
        },
        {
          "name": "lineage",
          "line": 70,
          "signature": "pub mod lineage;",
          "documentation": ""
        },
        {
          "name": "local_dev",
          "line": 71,
          "signature": "pub mod local_dev;",
          "documentation": ""
        },
        {
          "name": "persistence",
          "line": 72,
          "signature": "pub mod persistence;",
          "documentation": ""
        },
        {
          "name": "prelude",
          "line": 81,
          "signature": "pub mod prelude;",
          "documentation": "Re-exports of the most commonly used types and functions.\n\nImport this module to get started quickly:\n\n```\nuse forge_identity::prelude::*;\n```"
        },
        {
          "name": "pub use crate::agent_identity::ForgeAgentIdentity;",
          "line": 82,
          "signature": "pub use crate::agent_identity::ForgeAgentIdentity;",
          "documentation": ""
        },
        {
          "name": "pub use crate::error::{ForgeIdentityError, ForgeIdentityResult};",
          "line": 83,
          "signature": "pub use crate::error::{ForgeIdentityError, ForgeIdentityResult};",
          "documentation": ""
        },
        {
          "name": "pub use crate::lineage::{\n        create_hmr_identity, create_mhr_identity, derive_agent_identity, verify_lineage_chain,\n        DEFAULT_MAX_LINEAGE_DEPTH,\n    };",
          "line": 84,
          "signature": "pub use crate::lineage::{\n        create_hmr_identity, create_mhr_identity, derive_agent_identity, verify_lineage_chain,\n        DEFAULT_MAX_LINEAGE_DEPTH,\n    };",
          "documentation": ""
        },
        {
          "name": "pub use crate::persistence::{load_identity, save_identity};",
          "line": 89,
          "signature": "#[allow(deprecated)]\npub use crate::persistence::{load_identity, save_identity};",
          "documentation": ""
        }
      ]
    },
    {
      "path": "forge-rs/crates/forge-identity/src/lineage.rs",
      "sha256": "18e2439a314fba84a7097048458cf47d48849a7182b9f9be36ad514b5199f179",
      "artifactSha256": "639d2360f967553e99f440747cb358ed75b85de909e56506cea9021383cc7b48",
      "url": "/reference/source/forge-rs/crates/forge-identity/src/lineage.rs.txt",
      "declarations": [
        {
          "name": "::DEFAULT_MAX_LINEAGE_DEPTH",
          "line": 54,
          "signature": "pub const DEFAULT_MAX_LINEAGE_DEPTH: u32;",
          "documentation": "The default maximum lineage chain depth per ANVIL Spec \u00a711.2.\n\nThe ANVIL specification recommends a maximum of 16 derivation steps\nfrom a human root entity. Chains exceeding this depth are rejected."
        },
        {
          "name": "::create_hmr_identity",
          "line": 94,
          "signature": "pub fn create_hmr_identity(\n    namespace: &str,\n    identifier: &str,\n) -> ForgeIdentityResult<ForgeAgentIdentity>;",
          "documentation": "Creates a new Human Root (HMR) identity.\n\nGenerates a fresh Ed25519 keypair, constructs an OAS Identity Document\nfor a `did:oas:<namespace>:hmr:<identifier>` DID, and signs it.\n\nHMR identities are the ultimate trust anchors in the lineage chain.\nEvery derived agent traces back to an HMR.\n\nSee ANVIL Spec \u00a711.1 \u2014 OAS Identity Binding.\n\n# Arguments\n\n* `namespace` - The OAS namespace (e.g., `\"l1fe\"`, `\"test\"`).\n* `identifier` - The unique identifier within the namespace.\n\n# Returns\n\nA [`ForgeAgentIdentity`] with lineage depth 0 and kind `\"hmr\"`.\n\n# Errors\n\nReturns [`ForgeIdentityError::Oas`] if DID construction, document building,\nor signing fails in the underlying OAS SDK.\n\nReturns [`ForgeIdentityError::InvalidIdentity`] if the resulting identity\nfails structural validation.\n\n# Examples\n\n```\nuse forge_identity::lineage::create_hmr_identity;\n\nlet hmr = create_hmr_identity(\"test\", \"alice\").unwrap();\nassert_eq!(hmr.did(), \"did:oas:test:hmr:alice\");\nassert_eq!(hmr.kind(), \"hmr\");\nassert_eq!(hmr.lineage_depth(), 0);\n```"
        },
        {
          "name": "::create_hmr_with_seed",
          "line": 218,
          "signature": "pub fn create_hmr_with_seed(\n    namespace: &str,\n    identifier: &str,\n    seed_bytes: &[u8; 32],\n) -> ForgeIdentityResult<ForgeAgentIdentity>;",
          "documentation": "Creates a new Human Root (HMR) identity from a deterministic 32-byte seed.\n\nThe Ed25519 keypair is derived from `seed_bytes` using HKDF-SHA256 with\nthe kind/namespace/identifier bound into the info string. The same seed\nwill produce the same identity across runs (deterministic), but different\n`(namespace, identifier)` pairs derive different keys from the same seed.\n\nUse this when you want **deterministic identity from a sealed secret** --\ne.g., the seed lives in a sealed env var (`FORGE_TUTOR_HMR_SEED`) so the\nHMR's keypair is reproducible across boots without ever writing the\nkeypair to disk.\n\nSee ANVIL Spec \u00a711.1 \u2014 OAS Identity Binding.\n\n# Arguments\n\n* `namespace` - The OAS namespace (e.g., `\"l1fe\"`, `\"test\"`).\n* `identifier` - The unique identifier within the namespace.\n* `seed_bytes` - 32 bytes of high-entropy material. Treat as a secret.\n\n# Returns\n\nA [`ForgeAgentIdentity`] with lineage depth 0, kind `\"hmr\"`, and an\nEd25519 keypair derived from `seed_bytes`.\n\n# Errors\n\n- [`ForgeIdentityError::Oas`] if document construction or signing fails.\n- [`ForgeIdentityError::InvalidIdentity`] if the derived keypair fails\n  structural validation or HKDF expansion fails (should not happen with\n  uniformly random `seed_bytes`).\n\n# Examples\n\n```\nuse forge_identity::lineage::create_hmr_with_seed;\n\nlet seed: [u8; 32] = [42u8; 32];\nlet hmr = create_hmr_with_seed(\"test\", \"alice\", &seed).unwrap();\nassert_eq!(hmr.did(), \"did:oas:test:hmr:alice\");\nassert_eq!(hmr.kind(), \"hmr\");\nassert_eq!(hmr.lineage_depth(), 0);\n\n// Same seed + same (namespace, identifier) => same DID with same key.\nlet hmr_again = create_hmr_with_seed(\"test\", \"alice\", &seed).unwrap();\nassert_eq!(hmr_again.did(), hmr.did());\n```"
        },
        {
          "name": "::create_mhr_with_seed",
          "line": 257,
          "signature": "pub fn create_mhr_with_seed(\n    namespace: &str,\n    identifier: &str,\n    seed_bytes: &[u8; 32],\n) -> ForgeIdentityResult<ForgeAgentIdentity>;",
          "documentation": "Creates a new Multi-Human Root (MHR) identity from a deterministic 32-byte seed.\n\nCompanion to [`create_hmr_with_seed`] for machine-originated root entities.\nSame HKDF derivation rules apply -- different kinds derive different keys\nfrom the same seed thanks to the `kind` binding in the HKDF info string.\n\n# Examples\n\n```\nuse forge_identity::lineage::{create_hmr_with_seed, create_mhr_with_seed};\n\nlet seed: [u8; 32] = [7u8; 32];\nlet hmr = create_hmr_with_seed(\"test\", \"alice\", &seed).unwrap();\nlet mhr = create_mhr_with_seed(\"test\", \"alice\", &seed).unwrap();\n// Different kinds => different DIDs and different keypairs even with same seed.\nassert_ne!(hmr.did(), mhr.did());\n```"
        },
        {
          "name": "::create_mhr_identity",
          "line": 313,
          "signature": "pub fn create_mhr_identity(\n    namespace: &str,\n    identifier: &str,\n) -> ForgeIdentityResult<ForgeAgentIdentity>;",
          "documentation": "Creates a new Multi-Human Root (MHR) identity.\n\nSimilar to [`create_hmr_identity`] but for machine-originated root entities.\nMHR identities use `did:oas:<namespace>:mhr:<identifier>`.\n\nSee ANVIL Spec \u00a711.1 \u2014 OAS Identity Binding.\n\n# Arguments\n\n* `namespace` - The OAS namespace (e.g., `\"l1fe\"`, `\"test\"`).\n* `identifier` - The unique identifier within the namespace.\n\n# Returns\n\nA [`ForgeAgentIdentity`] with lineage depth 0 and kind `\"mhr\"`.\n\n# Errors\n\nReturns [`ForgeIdentityError::Oas`] if DID construction, document building,\nor signing fails in the underlying OAS SDK.\n\nReturns [`ForgeIdentityError::InvalidIdentity`] if the resulting identity\nfails structural validation.\n\n# Examples\n\n```\nuse forge_identity::lineage::create_mhr_identity;\n\nlet mhr = create_mhr_identity(\"test\", \"system1\").unwrap();\nassert_eq!(mhr.did(), \"did:oas:test:mhr:system1\");\nassert_eq!(mhr.kind(), \"mhr\");\nassert_eq!(mhr.lineage_depth(), 0);\n```"
        },
        {
          "name": "::derive_agent_identity",
          "line": 382,
          "signature": "pub fn derive_agent_identity(\n    parent: &ForgeAgentIdentity,\n    name: &str,\n    namespace: &str,\n) -> ForgeIdentityResult<ForgeAgentIdentity>;",
          "documentation": "Derives a child agent identity from a parent identity.\n\nPerforms the complete agent derivation workflow per ANVIL Spec \u00a711.2:\n\n1. Validates the parent's lineage depth does not exceed the maximum.\n2. Derives a child Ed25519 keypair using HKDF-SHA256.\n3. Generates an AgentLineageProof2025 linking child to parent.\n4. Constructs a signed OAS Identity Document with a complete lineage section.\n\nThe child's lineage depth is `parent.lineage_depth() + 1`.\n\n# Arguments\n\n* `parent` - The parent identity (HMR, MHR, or another agent).\n* `name` - The child agent's identifier (e.g., `\"analyzer\"`, `\"scraper\"`).\n* `namespace` - The child's namespace (often the same as the parent's).\n\n# Returns\n\nA [`ForgeAgentIdentity`] with kind `\"agent\"` and an incremented lineage depth.\n\n# Errors\n\nReturns [`ForgeIdentityError::ChainTooDeep`] if the parent's lineage depth\nplus one exceeds [`DEFAULT_MAX_LINEAGE_DEPTH`].\n\nReturns [`ForgeIdentityError::Oas`] if key derivation, document building,\nor signing fails in the underlying OAS SDK.\n\nReturns [`ForgeIdentityError::InvalidIdentity`] if the resulting identity\nfails structural validation.\n\n# Examples\n\n```\nuse forge_identity::lineage::{create_hmr_identity, derive_agent_identity};\n\nlet hmr = create_hmr_identity(\"test\", \"alice\").unwrap();\nlet agent = derive_agent_identity(&hmr, \"analyzer\", \"test\").unwrap();\n\nassert_eq!(agent.did(), \"did:oas:test:agent:analyzer\");\nassert_eq!(agent.kind(), \"agent\");\nassert_eq!(agent.lineage_depth(), 1);\nassert!(agent.document().lineage.is_some());\n```"
        },
        {
          "name": "::verify_lineage_chain",
          "line": 468,
          "signature": "pub fn verify_lineage_chain(\n    identity: &ForgeAgentIdentity,\n    provider: &dyn DocumentProvider,\n    config: &VerifyConfig,\n) -> ForgeIdentityResult<VerifyResult>;",
          "documentation": "Verifies the lineage chain for a given agent identity.\n\nWalks the cryptographic chain from the agent to its human root,\nverifying each hop's AgentLineageProof2025 signature against the\nresolved parent document's public key.\n\nSee ANVIL Spec \u00a711.2 \u2014 Lineage Propagation.\n\n# Arguments\n\n* `identity` - The agent identity whose lineage to verify.\n* `provider` - A [`DocumentProvider`] for resolving parent documents.\n* `config` - Verification configuration (timeouts, max depth).\n\n# Returns\n\nA [`VerifyResult`] on success, containing chain metadata and any warnings.\n\n# Errors\n\nReturns [`ForgeIdentityError::LineageVerificationFailed`] if any step\nof the verification fails (missing parent, invalid signature, etc.).\n\n# Examples\n\n```\nuse forge_identity::lineage::{\n    create_hmr_identity, derive_agent_identity, verify_lineage_chain,\n};\nuse oas_lineage::provider::InMemoryProvider;\nuse oas_lineage::config::VerifyConfig;\n\nlet hmr = create_hmr_identity(\"test\", \"alice\").unwrap();\nlet agent = derive_agent_identity(&hmr, \"bot\", \"test\").unwrap();\n\nlet mut provider = InMemoryProvider::new();\nprovider.register(hmr.document().clone());\n\nlet result = verify_lineage_chain(&agent, &provider, &VerifyConfig::default());\nassert!(result.is_ok());\n```"
        }
      ]
    },
    {
      "path": "forge-rs/crates/forge-identity/src/local_dev/did.rs",
      "sha256": "48a0040312a8e50a8bd7e63f2e5bc064d4ac3787837c23a1c9fbe0f21e1b3967",
      "artifactSha256": "7cbe7f3ecb7598646a855eb587b005508d9b373d089ce02a0eecbe32a042a78d",
      "url": "/reference/source/forge-rs/crates/forge-identity/src/local_dev/did.rs.txt",
      "declarations": [
        {
          "name": "::FORGE_DEV_METHOD",
          "line": 35,
          "signature": "pub const FORGE_DEV_METHOD: &str;",
          "documentation": "The DID method prefix for local development identities.\n\nThis prefix is explicitly rejected by all production DID resolvers."
        },
        {
          "name": "::forge_dev_did",
          "line": 63,
          "signature": "pub fn forge_dev_did(machine_id: &str, kind: &str, identifier: &str) -> String;",
          "documentation": "Constructs a local dev DID string.\n\n# Format\n\n`did:forge-dev:<machine-id>:<kind>:<identifier>`\n\nThe `machine_id` is a 16-character hex string derived from\n`SHA-256(\"forge-dev-root:\" + hostname + \":\" + username + \":\" + profile_name)[0..8]`.\nIt is computed once per profile and stored in the profile file. This scopes\nevery DID to the physical machine + OS user + profile name, preventing\ncollisions across developers and across named profiles on the same machine.\n\n# Arguments\n\n* `machine_id` - The 16-char hex machine identifier from the profile.\n* `kind` - One of `\"mhr\"`, `\"hmr\"`, `\"agent\"`, `\"org\"`.\n* `identifier` - The entity name or derived fingerprint.\n\n# Examples\n\n```\nuse forge_identity::local_dev::did::forge_dev_did;\n\nlet did = forge_dev_did(\"a1b2c3d4e5f6a7b8\", \"agent\", \"data-analyst\");\nassert_eq!(did, \"did:forge-dev:a1b2c3d4e5f6a7b8:agent:data-analyst\");\n```"
        },
        {
          "name": "::derive_machine_id",
          "line": 100,
          "signature": "#[cfg(not(target_arch = \"wasm32\"))]\npub fn derive_machine_id(profile_name: &str) -> String;",
          "documentation": "Derives a deterministic machine identifier from hostname, username,\nand profile name.\n\nThe ID is stable across sessions on the same machine for the same user\nand same profile, ensuring agent DIDs remain consistent across SDK restarts.\n\n# Algorithm\n\n`SHA-256(\"forge-dev-root:\" + hostname + \":\" + username + \":\" + profile_name)`\ntruncated to the first 8 bytes, hex-encoded to 16 characters.\n\n# Arguments\n\n* `profile_name` - The profile name (e.g., `\"default\"`, `\"alice\"`).\n\n# Returns\n\nA 16-character hex string (8 bytes of SHA-256 output).\n\n# Examples\n\n```\nuse forge_identity::local_dev::did::derive_machine_id;\n\nlet id1 = derive_machine_id(\"default\");\nlet id2 = derive_machine_id(\"default\");\nassert_eq!(id1, id2); // Deterministic on the same machine\nassert_eq!(id1.len(), 16); // Always 16 hex chars\n\nlet id3 = derive_machine_id(\"alice\");\nassert_ne!(id1, id3); // Different profiles produce different IDs\n```"
        },
        {
          "name": "::derive_machine_id",
          "line": 108,
          "signature": "#[cfg(target_arch = \"wasm32\")]\npub fn derive_machine_id(profile_name: &str) -> String;",
          "documentation": "WASM fallback: derives a machine identifier using fixed host/user values."
        },
        {
          "name": "::derive_machine_id_from_parts",
          "line": 141,
          "signature": "pub fn derive_machine_id_from_parts(hostname: &str, username: &str, profile_name: &str) -> String;",
          "documentation": "Derives a machine identifier from explicit hostname, username, and profile name.\n\nThis is the deterministic core of [`derive_machine_id`], exposed for\ncross-language parity testing where hostname and username must be fixed.\n\n# Arguments\n\n* `hostname` - The machine hostname.\n* `username` - The OS username.\n* `profile_name` - The profile name.\n\n# Returns\n\nA 16-character hex string.\n\n# Examples\n\n```\nuse forge_identity::local_dev::did::derive_machine_id_from_parts;\n\nlet id = derive_machine_id_from_parts(\"dev-machine\", \"alice\", \"default\");\nassert_eq!(id.len(), 16);\n\n// Same inputs always produce the same output\nlet id2 = derive_machine_id_from_parts(\"dev-machine\", \"alice\", \"default\");\nassert_eq!(id, id2);\n```"
        },
        {
          "name": "::validate_forge_dev_did",
          "line": 161,
          "signature": "pub fn validate_forge_dev_did(did: &str) -> ForgeIdentityResult<()>;",
          "documentation": "Validates that a string is a valid forge-dev DID.\n\n# Arguments\n\n* `did` - The DID string to validate.\n\n# Returns\n\n`Ok(())` if the DID has the correct format.\n\n# Errors\n\nReturns [`ForgeIdentityError::InvalidIdentity`] if the DID does not match\nthe expected `did:forge-dev:<machine-id>:<kind>:<identifier>` format."
        }
      ]
    },
    {
      "path": "forge-rs/crates/forge-identity/src/local_dev/mod.rs",
      "sha256": "32434596ae628e28d6d0c924c4cf8ec5f8c840651308a48a3f948914967f9e24",
      "artifactSha256": "41b2f76232f172681ff05f2ca290627e85ed4e40eecb187ad1ab8e9ce0721e2d",
      "url": "/reference/source/forge-rs/crates/forge-identity/src/local_dev/mod.rs.txt",
      "declarations": [
        {
          "name": "did",
          "line": 38,
          "signature": "pub mod did;",
          "documentation": "Local development identity layer for Forge agents.\n\nThis module provides a lightweight, self-contained identity and authorization\nlayer that works entirely offline without external services. It uses real\nEd25519 cryptography but with a distinct DID method (`did:forge-dev`) that\nis rejected by all production systems.\n\n# Architecture\n\n- [`LocalDevProfile`] \u2014 The top-level profile managing root identity, org, and agent cache.\n- [`ForgeDevIdentity`] \u2014 A dev identity wrapping [`ForgeAgentIdentity`](crate::agent_identity::ForgeAgentIdentity)\n  with development metadata.\n- [`LocalOrg`] \u2014 A local organization container for grouping dev identities.\n- [`did`] \u2014 DID construction and validation for the `forge-dev` method.\n- [`persistence`] \u2014 Profile save/load to/from JSON files.\n\n# Security\n\nLocal dev identities use real Ed25519 keys and real signatures. The only\ndifference from production is the DID method prefix (`forge-dev` vs `oas`).\nThe `forge-dev` method is not recognized by any production DID resolver,\nregistry, or verifier.\n\n# Examples\n\n```no_run\nuse forge_identity::local_dev::LocalDevProfile;\n\n// Load or create a profile at the default path\nlet mut profile = LocalDevProfile::load_or_create_default().unwrap();\n\n// Derive an agent identity (lazy, cached)\nlet agent = profile.agent_identity(\"data-analyst\").unwrap();\nassert!(agent.did().starts_with(\"did:forge-dev:\"));\nassert_eq!(agent.kind(), \"agent\");\n```"
        },
        {
          "name": "persistence",
          "line": 39,
          "signature": "pub mod persistence;",
          "documentation": ""
        },
        {
          "name": "::LocalDevProfile",
          "line": 79,
          "signature": "pub struct LocalDevProfile {\n\n}",
          "documentation": "A local development profile providing identity and authorization\nwithout external services.\n\n`LocalDevProfile` is the entry point for development-mode operation.\nIt provisions a local root identity, derives agent identities on demand,\nand issues local-scoped capability tokens that grant all capabilities.\n\n# Security\n\nLocal dev profiles use real Ed25519 cryptography but are clearly\nnon-production. The DID method `forge-dev` is not recognized by any\nproduction verifier, registry, or resolver.\n\n# Examples\n\n```no_run\nuse forge_identity::local_dev::LocalDevProfile;\n\nlet mut profile = LocalDevProfile::load_or_create_default().unwrap();\nlet agent = profile.agent_identity(\"data-analyst\").unwrap();\nassert!(agent.did().starts_with(\"did:forge-dev:\"));\n```"
        },
        {
          "name": "::ForgeDevIdentity",
          "line": 112,
          "signature": "pub struct ForgeDevIdentity {\n\n}",
          "documentation": "A local development identity wrapping [`ForgeAgentIdentity`] with dev metadata.\n\nThis is intentionally NOT a newtype around `ForgeAgentIdentity`. It wraps\nthe real identity and adds development-mode metadata (creation timestamp,\norg binding, profile version)."
        },
        {
          "name": "::ForgeDevIdentity::did",
          "line": 149,
          "signature": "pub fn did(&self) -> &str;",
          "documentation": "Returns the `did:forge-dev` identifier string."
        },
        {
          "name": "::ForgeDevIdentity::kind",
          "line": 154,
          "signature": "pub fn kind(&self) -> &str;",
          "documentation": "Returns the entity kind (e.g., `\"mhr\"`, `\"agent\"`)."
        },
        {
          "name": "::ForgeDevIdentity::lineage_depth",
          "line": 159,
          "signature": "pub fn lineage_depth(&self) -> u32;",
          "documentation": "Returns the lineage depth from the root."
        },
        {
          "name": "::ForgeDevIdentity::inner",
          "line": 164,
          "signature": "pub fn inner(&self) -> &ForgeAgentIdentity;",
          "documentation": "Returns a reference to the underlying [`ForgeAgentIdentity`]."
        },
        {
          "name": "::ForgeDevIdentity::into_inner",
          "line": 169,
          "signature": "pub fn into_inner(self) -> ForgeAgentIdentity;",
          "documentation": "Consumes the dev identity wrapper, returning the inner [`ForgeAgentIdentity`]."
        },
        {
          "name": "::ForgeDevIdentity::org_id",
          "line": 174,
          "signature": "pub fn org_id(&self) -> &str;",
          "documentation": "Returns the org ID this identity belongs to."
        },
        {
          "name": "::ForgeDevIdentity::created_at",
          "line": 179,
          "signature": "pub fn created_at(&self) -> &str;",
          "documentation": "Returns the ISO 8601 creation timestamp."
        },
        {
          "name": "::ForgeDevIdentity::schema_version",
          "line": 184,
          "signature": "pub fn schema_version(&self) -> u32;",
          "documentation": "Returns the schema version."
        },
        {
          "name": "::ForgeDevIdentity::sign",
          "line": 189,
          "signature": "pub fn sign(&self, message: &[u8]) -> Vec<u8>;",
          "documentation": "Signs a message with this identity's Ed25519 signing key."
        },
        {
          "name": "::ForgeDevIdentity::verifying_key_bytes",
          "line": 194,
          "signature": "pub fn verifying_key_bytes(&self) -> [u8; 32];",
          "documentation": "Returns the raw 32-byte Ed25519 verifying (public) key bytes."
        },
        {
          "name": "::LocalOrg",
          "line": 204,
          "signature": "#[derive(Debug, Clone)]\npub struct LocalOrg {\n\n}",
          "documentation": "A local organization for grouping dev identities.\n\nIn production, orgs are managed by external services (IAM, Omerta sidecar,\netc.). In local dev, an org is a named container with a deterministic ID."
        },
        {
          "name": "::LocalOrg::new",
          "line": 216,
          "signature": "pub fn new(name: impl Into<String>) -> Self;",
          "documentation": "Creates a new local org with the given name.\n\nThe org ID is deterministically derived as `\"forge-dev-org:<name>\"`."
        },
        {
          "name": "::LocalOrg::id",
          "line": 223,
          "signature": "pub fn id(&self) -> &str;",
          "documentation": "Returns the org identifier."
        },
        {
          "name": "::LocalOrg::name",
          "line": 228,
          "signature": "pub fn name(&self) -> &str;",
          "documentation": "Returns the org display name."
        },
        {
          "name": "::LocalDevProfile::load_or_create_default",
          "line": 253,
          "signature": "#[cfg(not(target_arch = \"wasm32\"))]\npub fn load_or_create_default() -> ForgeIdentityResult<Self>;",
          "documentation": "Loads or creates a local dev profile at the default path.\n\nThe default path is `~/.forge/dev-profile.json`. If the file exists,\nthe profile is loaded. If it does not exist, a new profile is created\nwith a fresh Ed25519 root identity and persisted to disk.\n\n# Returns\n\nA [`LocalDevProfile`] ready for use.\n\n# Errors\n\nReturns [`ForgeIdentityError::PersistenceFailed`] if the home directory\ncannot be determined or I/O fails.\n\nReturns [`ForgeIdentityError::Oas`] if identity creation fails."
        },
        {
          "name": "::LocalDevProfile::load_or_create",
          "line": 277,
          "signature": "#[cfg(not(target_arch = \"wasm32\"))]\npub fn load_or_create(profile_name: &str) -> ForgeIdentityResult<Self>;",
          "documentation": "Loads or creates a named local dev profile.\n\nNamed profiles are stored at `~/.forge/dev-profile-<name>.json`\n(or `~/.forge/dev-profile.json` for the `\"default\"` profile).\nDifferent profile names produce different machine IDs and therefore\ndifferent DID namespaces.\n\n# Arguments\n\n* `profile_name` - The profile name (e.g., `\"alice\"`, `\"bob\"`).\n\n# Returns\n\nA [`LocalDevProfile`] for the given profile name.\n\n# Errors\n\nReturns [`ForgeIdentityError::PersistenceFailed`] if I/O fails.\nReturns [`ForgeIdentityError::Oas`] if identity creation fails."
        },
        {
          "name": "::LocalDevProfile::root",
          "line": 289,
          "signature": "pub fn root(&self) -> &ForgeDevIdentity;",
          "documentation": "Returns the root dev identity."
        },
        {
          "name": "::LocalDevProfile::org",
          "line": 294,
          "signature": "pub fn org(&self) -> &LocalOrg;",
          "documentation": "Returns the local org."
        },
        {
          "name": "::LocalDevProfile::machine_id",
          "line": 299,
          "signature": "pub fn machine_id(&self) -> &str;",
          "documentation": "Returns the machine ID."
        },
        {
          "name": "::LocalDevProfile::profile_name",
          "line": 304,
          "signature": "pub fn profile_name(&self) -> &str;",
          "documentation": "Returns the profile name."
        },
        {
          "name": "::LocalDevProfile::storage_path",
          "line": 309,
          "signature": "pub fn storage_path(&self) -> &std::path::Path;",
          "documentation": "Returns the storage path."
        },
        {
          "name": "::LocalDevProfile::agent_count",
          "line": 314,
          "signature": "pub fn agent_count(&self) -> usize;",
          "documentation": "Returns the number of cached agent identities."
        },
        {
          "name": "::LocalDevProfile::agent_identity",
          "line": 337,
          "signature": "#[cfg(not(target_arch = \"wasm32\"))]\npub fn agent_identity(&mut self, agent_name: &str) -> ForgeIdentityResult<&ForgeDevIdentity>;",
          "documentation": "Derives (or retrieves from cache) an agent identity for the given name.\n\nAgent identities are derived lazily from the root identity using\nHKDF-SHA256 key derivation. Once derived, they are cached in the\nprofile and persisted to disk.\n\n# Arguments\n\n* `agent_name` - The agent's identifier (e.g., `\"data-analyst\"`).\n\n# Returns\n\nA reference to the cached or newly derived [`ForgeDevIdentity`].\n\n# Errors\n\nReturns [`ForgeIdentityError::Oas`] if key derivation or document\nconstruction fails."
        },
        {
          "name": "::LocalDevProfile::save",
          "line": 366,
          "signature": "#[cfg(not(target_arch = \"wasm32\"))]\npub fn save(&self) -> ForgeIdentityResult<()>;",
          "documentation": "Persists the current profile state to disk.\n\n# Errors\n\nReturns [`ForgeIdentityError::PersistenceFailed`] if serialization or I/O fails."
        }
      ]
    },
    {
      "path": "forge-rs/crates/forge-identity/src/local_dev/persistence.rs",
      "sha256": "e334b9cb607d4201382f7975f68d5b2e300ced8bc910420b264128e4c55c986a",
      "artifactSha256": "4e2dc2734e8ce9cd31273c05b061bc64e78c2547bbd4159e46b74e0799dfd79c",
      "url": "/reference/source/forge-rs/crates/forge-identity/src/local_dev/persistence.rs.txt",
      "declarations": [
        {
          "name": "::PROFILE_SCHEMA_VERSION",
          "line": 28,
          "signature": "pub const PROFILE_SCHEMA_VERSION: u32;",
          "documentation": "The current schema version for the profile JSON format."
        },
        {
          "name": "::PersistedProfile",
          "line": 42,
          "signature": "#[derive(Debug, Clone, Serialize, Deserialize)]\npub struct PersistedProfile {\n/// Schema version for forward compatibility.\n\npub schema_version: u32,\n/// ISO 8601 timestamp of when the profile was first created.\n\npub created_at: String,\n/// The profile name (e.g., `\"default\"`, `\"alice\"`).\n\npub profile_name: String,\n/// The 16-character hex machine identifier.\n\npub machine_id: String,\n/// The root identity data.\n\npub root: PersistedDevIdentity,\n/// The local organization context.\n\npub org: PersistedOrg,\n/// Cached agent identities, keyed by agent name.\n\npub agents: BTreeMap<String, PersistedDevIdentity>\n}",
          "documentation": "Serializable representation of a local dev profile.\n\nThis is the on-disk format. It is intentionally separate from the in-memory\n[`LocalDevProfile`](super::LocalDevProfile) to decouple serialization from\nruntime behavior."
        },
        {
          "name": "::PersistedDevIdentity",
          "line": 61,
          "signature": "#[derive(Debug, Clone, Serialize, Deserialize)]\npub struct PersistedDevIdentity {\n/// The `did:forge-dev:...` identifier string.\n\npub did: String,\n/// The entity kind (e.g., `\"mhr\"`, `\"agent\"`).\n\npub kind: String,\n/// The 32-byte Ed25519 signing key, hex-encoded.\n\npub signing_key_hex: String,\n/// The full OAS Identity Document serialized as a JSON string.\n\npub document_json: String,\n/// The number of derivation steps from root.\n\npub lineage_depth: u32,\n/// The org ID this identity belongs to.\n\npub org_id: String,\n/// ISO 8601 timestamp of when this identity was created.\n\npub created_at: String\n}",
          "documentation": "Serializable representation of a single dev identity."
        },
        {
          "name": "::PersistedOrg",
          "line": 80,
          "signature": "#[derive(Debug, Clone, Serialize, Deserialize)]\npub struct PersistedOrg {\n/// The org identifier (e.g., `\"forge-dev-org:local\"`).\n\npub id: String,\n/// The org display name.\n\npub name: String\n}",
          "documentation": "Serializable representation of a local organization."
        },
        {
          "name": "::default_profile_path",
          "line": 101,
          "signature": "#[cfg(not(target_arch = \"wasm32\"))]\npub fn default_profile_path() -> ForgeIdentityResult<PathBuf>;",
          "documentation": "Returns the default profile storage path.\n\nThe path is `~/.forge/dev-profile.json` unless the `FORGE_DEV_PROFILE_PATH`\nenvironment variable is set.\n\n# Returns\n\nThe resolved profile path.\n\n# Errors\n\nReturns [`ForgeIdentityError::PersistenceFailed`] if the home directory\ncannot be determined."
        },
        {
          "name": "::named_profile_path",
          "line": 132,
          "signature": "#[cfg(not(target_arch = \"wasm32\"))]\npub fn named_profile_path(profile_name: &str) -> ForgeIdentityResult<PathBuf>;",
          "documentation": "Returns the profile storage path for a named profile.\n\nNamed profiles are stored at `~/.forge/dev-profile-<name>.json`.\n\n# Arguments\n\n* `profile_name` - The profile name.\n\n# Returns\n\nThe resolved profile path.\n\n# Errors\n\nReturns [`ForgeIdentityError::PersistenceFailed`] if the home directory\ncannot be determined."
        },
        {
          "name": "::save_profile",
          "line": 161,
          "signature": "#[cfg(not(target_arch = \"wasm32\"))]\npub fn save_profile(profile: &PersistedProfile, path: &Path) -> ForgeIdentityResult<()>;",
          "documentation": "Saves a persisted profile to disk at the given path.\n\nCreates parent directories if they do not exist. On Unix, sets file\npermissions to 0600 (owner-only read/write).\n\n# Arguments\n\n* `profile` - The profile data to persist.\n* `path` - The filesystem path to write to.\n\n# Errors\n\nReturns [`ForgeIdentityError::PersistenceFailed`] if serialization or I/O fails."
        },
        {
          "name": "::load_profile",
          "line": 213,
          "signature": "#[cfg(not(target_arch = \"wasm32\"))]\npub fn load_profile(path: &Path) -> ForgeIdentityResult<PersistedProfile>;",
          "documentation": "Loads a persisted profile from disk.\n\n# Arguments\n\n* `path` - The filesystem path to read from.\n\n# Returns\n\nThe deserialized [`PersistedProfile`].\n\n# Errors\n\nReturns [`ForgeIdentityError::PersistenceFailed`] if the file cannot be read\nor the JSON is malformed."
        }
      ]
    },
    {
      "path": "forge-rs/crates/forge-identity/src/persistence.rs",
      "sha256": "5eedfb18847c2c0227c9241bf1394c6d31ac846a29d1b1ee74d7dfb83dca6cfb",
      "artifactSha256": "f0dbb99802f4b604a1ae8d80eb2d2c7770ff96ff44e82c40f162c7423c70e49e",
      "url": "/reference/source/forge-rs/crates/forge-identity/src/persistence.rs.txt",
      "declarations": [
        {
          "name": "::save_identity",
          "line": 118,
          "signature": "#[deprecated(\n    since = \"0.2.0\",\n    note = \"Persists signing key in plaintext. Use an encrypted persistence backend \\\n            (e.g., AES-256-GCM + Argon2id) for production workloads. \\\n            See L1F-570 for the encrypted persistence follow-up.\"\n)]\npub fn save_identity(identity: &ForgeAgentIdentity, path: &Path) -> ForgeIdentityResult<()>;",
          "documentation": "Saves an agent identity to a JSON file at the specified path.\n\nThe identity is serialized as a `PersistedIdentity` containing the DID,\nkind, signing key (hex-encoded), full document JSON, and lineage depth.\n\n# Security\n\n**WARNING**: The signing key is currently stored in hex without encryption.\nIn production, use encrypted storage (AES-256-GCM or similar). This\nfunction is suitable for development and testing only.\n\nSee ANVIL Spec \u00a711.1 \u2014 OAS Identity Binding.\n\n# Arguments\n\n* `identity` - The agent identity to save.\n* `path` - The filesystem path to write the JSON file to.\n\n# Returns\n\n`Ok(())` on success.\n\n# Errors\n\nReturns [`ForgeIdentityError::PersistenceFailed`] if serialization or\nfile I/O fails.\n\n# Examples\n\n```no_run\nuse forge_identity::lineage::create_hmr_identity;\nuse forge_identity::persistence::save_identity;\nuse std::path::Path;\n\nlet hmr = create_hmr_identity(\"test\", \"alice\").unwrap();\nsave_identity(&hmr, Path::new(\"/tmp/identity.json\")).unwrap();\n```"
        },
        {
          "name": "::load_identity",
          "line": 213,
          "signature": "pub fn load_identity(path: &Path) -> ForgeIdentityResult<ForgeAgentIdentity>;",
          "documentation": "Loads an agent identity from a JSON file at the specified path.\n\nReads and deserializes a `PersistedIdentity`, reconstructs the\nEd25519 keypair from the stored signing key bytes, parses the OAS\ndocument, and returns a fully functional [`ForgeAgentIdentity`].\n\nSee ANVIL Spec \u00a711.1 \u2014 OAS Identity Binding.\n\n# Arguments\n\n* `path` - The filesystem path to read the JSON file from.\n\n# Returns\n\nA [`ForgeAgentIdentity`] reconstructed from the persisted data.\n\n# Errors\n\nReturns [`ForgeIdentityError::PersistenceFailed`] if:\n- The file cannot be read.\n- The JSON is malformed.\n- The signing key hex is invalid.\n- The OAS document JSON is malformed.\n- The reconstructed identity fails validation.\n\n# Examples\n\n```no_run\nuse forge_identity::persistence::load_identity;\nuse std::path::Path;\n\nlet identity = load_identity(Path::new(\"/tmp/identity.json\")).unwrap();\nprintln!(\"Loaded identity: {}\", identity.did());\n```"
        }
      ]
    }
  ]
}
