0:00 Keanu Pahio | KERI Developement & Deployment | KERI Conference 2026
0:04 I'm gonna start
0:07 and talk about KERI development
0:10 and deployment
0:12 [checks]
0:20 [inaudible, reconstruction - The Objectives are to:]
0:23 [Understand the architecture for deployment
0:31 understand the role of each part
0:37 Deploying local witnesses,
0:43 watchers and wallet
0:47 And to give an idea
0:53 where you]
0:59 can start for development on your own
1:02 and that includes maybe doing your
1:06 own plugin for Locksmith and developing
1:10 your own API for witnesses and
1:13 watchers.
1:15 So I want to talk first about the KERI
1:18 infrastructure that we have.
1:20 [inaudible - We have the Locksmith
1:22 wallet for signing, witnesses]
1:24 and the watchers which is pretty much
1:26 you've seen this the diagram a lot
1:30 in the past few days, but for the
1:33 requirements, the
1:36 only thing that we really need is Python.
1:39 We recommend the version 3.13, [because]
1:44 3.14 had some issues with some repos.
1:49 3.13 should be fine. And then [we need]
1:53 Libsodium because this is what
1:56 KERI uses for its cryptographic
1:58 library.
2:00 First, we'll go with the wallet.
2:03 It's a Locksmith. The role of
2:05 Locksmith on this wallet is to generate
2:07 the AIDs to sign it, to have the key
2:11 pairs secure and to store and verify
2:14 through your KELs and finally the
2:16 OOBIs.
2:18 Nothing more, I think, to expand on,
2:23 It's the basic function
2:25 of a wallet.
2:27 And then we're going to go through
2:28 deploying it. So we have just three
2:31 parts that we're going to go through
2:32 individually and first I'm
2:35 going to show you the repo and how you
2:37 can set up the environment with its
2:39 dependencies and how to run it.
2:43 Everything, every deployment that we're
2:44 going to go through are going to be
2:46 local.
2:47 I can explain that for a while
2:49 later. First you have the public
2:54 repo for the Locksmith which is on
2:57 the KERI Foundation [github repo]. Note that what
3:01 I'm going to use in this presentation
3:03 for the demo is from a branch of this
3:09 repo which is the KERI Foundation
3:11 branch. It's not the main branch that
3:13 I'm going to use because the KERI
3:15 Foundation branch has the KERI
3:17 Foundation plugin that we're going to
3:18 talk about later. I'm also going to
3:23 try to get your attention for the
3:26 docs that are provided by the repo and
3:29 I'm just going to show you a bit through
3:30 those docs. So the developer guide in
3:34 those docs explain what I
3:37 explained before. So if you need a
3:39 reminder, you can just go to the repo
3:41 and then read it. But first it's
3:44 going to be Python 3.13. And then to set
3:46 up your environment, you just have to
3:48 follow the commands that are on the
3:51 developer guide. Pretty easy.
3:55 And then finally to run it, you have the
3:58 Qt resource regeneration. And once you
4:01 copy paste and run those commands,
4:03 you can run this one. Then
4:07 hopefully a lot of initialization logs
4:11 will pop up and you will
4:13 have your Locksmith.
4:16 I'm going to run it myself,
4:21 and show you.
4:24 I'm going to
4:28 activate the virtual environment
4:32 [preparing his demo]
5:10 So here we have our Locksmith.
5:13 I just created a vault, but we can…
5:16 I make a new one…
5:20 call it presentation.
5:23 No passcode and then, here you go.
5:27 So here…
5:29 – A vault is just a logical grouping of
5:32 of AIDs or ..?
5:35 Yes, if you're familiar with the
5:37 KERIpy code, it's the same as a Habery
5:40 which is where you host your AIDs and
5:42 which is where you have your key pairs
5:44 and all that stuff.
5:45 – Okay.
5:47 Here you have the KERI Foundation
5:50 plugin which we're going to talk about
5:52 now. The reason
5:57 why we have a KERI Foundation plugin is
6:00 because of a boot server that
6:02 we have.
6:04 So the boot server, what is the boot
6:06 server? Well the boot server is kind of
6:09 the in between
6:12 between Locksmith and the
6:14 witnesses and watchers. And the role of
6:16 the boot server is to provision the
6:18 witnesses to your wallet. And now,
6:22 maybe a question that you might
6:24 have is why can I not just talk from
6:27 Locksmith directly to the witnesses and
6:29 watchers? The reason for that is
6:32 the witnesses and watchers API.
6:36 When you look here, for example
6:39 for the witnesses API, you have actually
6:43 two servers: you have the boot server
6:45 and then you have the witness server.
6:47 The boot server, if you pay attention to
6:50 the API,
6:53 this is the one that actually creates
6:56 the witnesses and deletes them. And the
6:59 problem is that the boot server is
7:02 private. So it's not publicly
7:03 accessible. So even if you try to send a
7:05 request to it, it will not respond.
7:09 But the witness server and the
7:11 watcher server, those two are public. So
7:14 once you have your witnesses and your
7:16 watcher you can publicly access those
7:19 however you want. And same for the
7:21 watcher API this is also private. So the
7:24 reason is that we have our boot
7:28 server which serve as the one who
7:33 will call the private APIs to get the
7:36 witnesses and watchers and the
7:39 KERI Foundation plug-in acts as a
7:41 bridge between the Locksmith wallet and
7:44 the boot server. Currently the
7:49 KERI Foundation plugin is in charge of
7:52 onboarding, witness registration, watcher
7:55 resolution and auth management. And when
7:57 we're talking about onboarding we're
7:59 talking about setting you up
8:02 so you can have your own witnesses
8:05 and watcher.
8:07 Now an important thing to note is that
8:10 for, at least locally, the
8:13 boot server has
8:16 to be on the same machine or server as
8:21 the witnesses and watchers so it can
8:23 talk locally. As I mentioned before
8:26 because the APIs are private.
8:36 Let's go through the
8:38 plugin before we go through the boot
8:40 server. So I want to go to the plugin
8:42 and how you could, if you wanted, make
8:45 your own plugin.
8:47 If you go to the Locksmith
8:50 repository and if you go to
8:53 “Locksmith/plugins/base.py” it has a bunch of
8:56 classes that allows you to create your
8:59 own plugin. If you look at the
9:03 “PluginBase,” it has a bunch of methods
9:06 that you can override to create your
9:09 own plugin.
9:11 For example, here is the KERI
9:13 Foundation plugin that is in the plugin
9:16 folder. You can also look it up on the
9:18 KERI Foundation branch. It is using
9:21 the plugin base, the witness provider
9:23 plugin and the account provider plugin.
9:26 Then it has
9:28 u for example here you can see that it's
9:30 overriding the plugin_id function
9:32 and the initialize function. I'm not
9:35 going to go into too much detail as to
9:37 How you can .. or What you should put into
9:40 into those methods, but at least know
9:42 that it's there. And if you need the
9:44 preferences you can just look at the
9:46 KERI Foundation plugin in the
9:48 repository to get some
9:51 inspiration.
9:54 Now I want to go
9:57 to the boot server. To
10:01 remind you, the boot server serves as a
10:03 public API to provision your
10:06 witnesses and watcher. The kf-boot is
10:09 also available publicly. So if you want
10:11 to look at it, you can. It's on the
10:13 KERI Foundation repository. You can
10:16 look at it and see how the code works.
10:20 To run it, very simple, create your
10:23 virtual environment. And then here are
10:26 the variables that your KERI
10:30 Foundation boot needs to talk to
10:33 the witnesses and watcher. I'm going
10:36 to just show you a demo.
10:43 Here I have my KERI Foundation
10:47 boot server. I'm going to
10:52 activate it. And then
10:55 just like in the
10:59 slide that I showed, I'm just going to
11:00 copy .., I'm not going to install the
11:03 dependencies since I have already done it.
11:06 I'm going to go here, paste these,
11:09 and then run it. So now you can see that
11:12 it's running here. And if I go
11:17 to my Locksmith [needs to refresh]
11:47 I also need to give Locksmith the
11:54 address for the
12:00 boot server. So here and then if I run
12:03 it back [then]
12:09 my Locksmith
12:12 can get in.
12:14 [Keanu checks and prepares]
12:53 So, I actually can't see it, but
12:59 usually if you look it up on the KERI
13:03 Foundation plugin, it should show that
13:05 you can service an AID and connect
13:10 witnesses and watchers to it.
13:12 – You could try deleting your local KERI
13:16 “home/.keri”
13:19 and then start fresh and then should
13:21 recreate on that.
13:22 Oh, I make a whole other repo?
13:25 I could…
13:26 – Yeah, go ahead.
13:27 I could do it at the end
13:28 probably. I just want to go through
13:31 the whole slide and maybe I'll do
13:33 another demo. But so let me finish the
13:36 slides first. Go to the witnesses, of
13:40 course you have the role of the witnesses
13:42 and what they do to anchor the events
13:44 and trying to keep the authenticity
13:49 and make sure that everything is correct
13:50 of course, because they're the witnesses.
13:54 So same thing, we're going to go through
13:55 the repo, the environment and
13:58 how to run it locally.
14:01 So first you can get the code on the
14:03 witness repository in the KERI
14:06 Foundation.
14:08 It also has docs. So I have the
14:12 developer guide. Same thing just make
14:15 sure that you have Libsodium.
14:18 How to set up your environment.
14:21 And then one thing about the
14:24 configuration:
14:26 If you were here last time Ryan (Hansen),
14:29 you talked about it and how it works. So
14:32 I'm not going to repeat it but
14:34 surely the curls here
14:38 will be the address that the witness
14:42 server is going to use.
14:46 To run the witnesses, you can
14:49 use the first one or I usually use the
14:52 other one. Let me
14:56 show it here.
15:02 So I have it here. Let me activate the ..,
15:27 You have my
15:28 witnesses running
15:31 and if you look at here you can
15:33 see the [private, red.] server address, I mean the
15:35 port which is 5631 ..,
15:38 Sorry, the private one which is
15:40 internal and then external which is the
15:42 public one at the 5632 port which is
15:46 the default one unless you change it in
15:49 the configuration and then you can see
15:52 your witnesses and their own AID.
15:57 Now to develop with witnesses
16:00 you have the API which is given and
16:03 shown in the readme file of the
16:05 repository for the witnesses, you have
16:08 different, of course, action POST
16:11 [action] DELETE but I'm going to go into the POST
16:15 and here basically we have the
16:19 the whole POST function it's a Falcon
16:22 app so it's in under the witness
16:25 collection class. And if you look at it
16:28 closely,
16:29 you can see that when it receive a post
16:33 method, it will first check for the AID,
16:36 check that it's a valid AID, and then it
16:38 just creates a witness,
16:41 gets the OOBIs and sends the data
16:43 back. That's all it does. So, if you
16:46 wanted, you could check for, I don't
16:49 know, check for more things. But if you
16:52 want to start developing witnesses and
16:54 changing maybe how they behave, this is
16:56 where you would go. This is just an
16:58 example of the 'on_post', but there's also
17:01 the 'on_delete'. There's also all the
17:04 the public
17:08 actions and API that you can change
17:11 which would also be under
17:14 under this. So it's in
17:17 ”src/witopnet/witnessing.py”. So if you want to
17:19 change anything go here.
17:25 Now the watchers,
17:28 same thing that we're going to go
17:30 through: public repo of the watchers in
17:33 the KERI Foundation [github repo].
17:35 This one doesn't have docs yet. I
17:38 suppose we might either add it later.
17:42 But that's from the readme.
17:46 I don't think we can install from Pypy
17:48 yet. Correct me if I'm wrong. Yeah, we
17:50 can't install it from PyPy yet. So, just
17:53 clone the repo and then install the
17:56 environment or hopefully from a
17:59 virtual environment.
18:01 Same thing for the
18:03 configuration. The curls is also the
18:06 address from which the watcher server is
18:09 going to respond.
18:10 [Keanu prepares]
18:54 But here you can see the same thing as
18:55 the witnesses. It shows your address,
18:58 public address for the watcher
19:01 server, private and also the watchers
19:04 running. I can probably show it
19:06 better on here.
19:11 You can see they have the watchers here
19:14 as well as their AIDs. You can
19:17 see that it's going up because the
19:19 witnesses are running. So, they're all
19:21 checking the witnesses.
19:28 A quick note that is important
19:31 is that the witnesses and watcher are
19:34 supposed to run together. They're not
19:36 supposed to be individually
19:39 running. They have to be together.
19:41 So, first would be the witnesses and
19:43 then the watchers have to be
19:45 deployed together.
19:48 Same thing for the watchers. You
19:50 have the same API and you can find the
19:54 functions for them in this file here.
19:58 I took the POST for the watchers that
20:01 provision the watcher.
20:03 So to finish: what we have is this
20:08 architecture technically that we have
20:10 the wallet that can make public API
20:12 requests but mostly if you want to just
20:15 have witnesses and watchers provisioning
20:18 it would be through a boot server that
20:20 then talks privately to witnesses and
20:24 watcher server in their own environment.
20:28 I think that's all I have. Unless
20:33 do you guys have any questions?
20:36 Yes.
20:37 – Thank you.
20:39 Given that KERI is a protocol and again
20:42 protocols not companies. So why
20:43 would you want to make changes to
20:45 witnesses or watchers? I thought that
20:47 was like common infrastructure or am I
20:50 wrong?
20:52 – Like for example in this?
20:56 – Yeah. – For example, you can add
20:58 some more checks or you can have… we
21:01 were talking about weight limiting
21:04 for example on how much a person
21:08 could provision witnesses. You could
21:10 limit it or you could expand it.
21:13 Also another thing that you
21:16 could note
21:18 for example for the plugin if I can
21:21 find it. I think it was here. Oh yeah.
21:24 So, for example, for the KERI
21:25 Foundation plugin, all it does right now
21:27 is just onboarding. So, it's pretty
21:29 simple. But if you really wanted to, you
21:31 can make your own plugin where you
21:33 include payment. So, people go through
21:35 the payment first and then it would
21:37 provision your witnesses and watchers.
21:39 – And your watchers can make sure the
21:41 money was transferred.
21:43 – Yeah. So, it could it could go through
21:44 the auth authorization for some account
21:47 account management and
21:50 approvement.
21:51 – Approval.
21:52 Approval. That's the word.
21:54 If you want, I think what
21:57 would be more interesting is probably
21:59 doing your own plug-in first because
22:01 that's when you could decouple that
22:04 from the witnesses and just handle
22:05 everything in your own plugin.
22:08 – One thing to note also that this
22:10 witness service that we're talking about
22:12 here doesn't necessarily, if you're
22:15 manipulating in that 'on_post' handler,
22:18 you're not necessarily manipulating how
22:20 the witness code itself works [inaudible]
22:24 you're just manipulating the
22:27 layer, basically the API layer of
22:29 [inaudible]
22:30 so you can expand…
22:31 – So you're really not modifying any other…
22:34 – Just adding extra functionality,
22:35 auxiliary functionality.
22:39 – Of course being open source if you
22:41 wanted to go in and manipulate the
22:43 witness protocol some way for your own
22:45 version, that's on your own.
22:51 If you look here for example…
22:55 This is all it does, just calls create
22:58 witness but then everything after, you
23:00 can probably
23:03 add more functionalities for yourself
23:05 for example for tracking or for like
23:08 stats if you wanted to but that's up to
23:11 you. So I'm just trying to give you an
23:13 example of where you would start and how
23:16 you could start.
23:17 – That “createWitness” method weaves down
23:20 into the KERIpy.
23:22 – Yeah.
23:27 – Great. Thank you.
23:29 – Yeah, no problem. If you don't have
23:31 any questions, then I think I'll give
23:33 you back 20 minutes.