BermLaunch
Docs / Berm Protocol

Berm Protocol

The public verification layer underneath BermLaunch. It lets a person prove, in public, that an external account belongs to their portable identity — and lets anyone check that proof without asking the application that shows it.

  1. npub
  2. public proof
  3. Berm Protocol
  4. portable evidence
  5. applications

Boundaries that never bend

What Berm Protocol is

Berm Protocol is a public-goods verification layer. It is application neutral: it defines public methods for proving that an external account (today, an X account) is bound to a portable Nostr identity, and it defines the signed evidence those proofs produce.

BermLaunch is an application that consumes Berm Protocol evidence. It is not the protocol, it does not issue identity, and any other application can verify the same evidence under its own rules.

Identity model

An npub is the public half of a Nostr key pair. It is the portable root of a Berm identity. The private key stays with the person; Berm issues no identifier of its own.

External accounts are relationships an npub proves, not the identity itself. An X handle is not identity: the binding is keyed on X's immutable accountId, so a renamed or recycled handle does not move it. The handle is kept as presentation — what the post showed when observed.

(namespace, accountId) -> at most one npub, permanently npub -> zero, one, or many external accounts

More than one external account never multiplies an npub's identity or weight.

Current standard

Protocol predecessor / authority lineageR13-A REISSUE R4 — founder pinned
Current method-successor implementation checkpointR8 — founder accepted and pinned
Current X methodberm.external_account_binding.x/2
Method hashsha256:a95319d8664b16ca355b3d82bc8c4d5bb6007c8aed65116a74447f79b0e5e193
Normative vectors97 — set hash sha256:0ced853da13b3378b4e138883398ecd7831e27b00c2f03ee759af9668a45e6c5
Immutable R8 anchor50c8d54d41fb5395c166c02704b129f14082a69acddef34ba7b5a9a19d233a25

R8 is the label of the implementation lane that delivered the current method. It is not a protocol version number. The earlier R4 method, berm.external_account_binding.x/1, is historical.

Standing: these are founder-pinned artifacts. This page is a documentation projection. It does not authorize deployment, genesis, live X activity, publication or release.

Proving an X account

1. Public publication. The person posts, publicly on X, exactly one proof line:

Berm Protocol: @<handle> permanently binds to <npub> #bermprotocol

2. Subject claim. The person signs, with their own key, a claim that this binding is theirs.

3. Independent validator observation. Validators independently acquire the publicly served X publication — no user OAuth, no private cookies, no privileged X credentials — run the public method, and sign what they derived.

4. The five-minute window. The observation must fall inside a half-open window measured from the post's own creation time:

0 <= observedAt - postCreatedAt < 300000 ms

Exactly five minutes is already outside. There is no mandatory second look and no one-hour finality requirement.

5. Six-field result. A success is exactly npub, accountId, handle, postId, textHash, methodHash — nothing else, and no campaign data.

6. Fail closed. Anything that is not a valid six-field result is a failure with a closed reason code. Nothing is guessed or repaired.

Validators & federation

A public method is not a validator. The method is a hashed public specification anyone can run; a validator is an instance that runs it and signs its own observation.

An operator proves its own binding by the same method, then signs an authorization naming a dedicated validator key and the exact method it may observe under. Each application's acceptance policy decides which methods, operators and keys it accepts, and how many distinct operators must agree.

Honest independence accounting: two validator instances run by one operator are one operator. Today's two instances are same-operator witnessed evidence — a working mechanism, not independent corroboration. One genuinely outside operator changes that claim; none is claimed today.

Evidence

Every step produces a signed, public artifact: the subject's claim, each validator's observation, the operator's authorization, the application's policy, and optional application receipts. Claims and observations are two signatures that are never merged.

The evidence is portable, mirrorable and reconstructable: relays, Git, static archives or indexers can carry it, and no mirror is authoritative over another. A stranger can rebuild a verdict from the artifacts and the public method alone.

This website is explanatory, not final authority. Exact bytes and hashes are.

Applications

BermLaunch consumes the portable binding under its own published policy. Joining a campaign is a distinct step: enrollment is its own signed act, separate from the identity claim, and produces a unique campaign position.

portable identity evidence → campaign enrollment → unique (campaignId, npub) position

Campaign, cohort, allocation, provider and token facts never enter the portable identity binding.

Technical reference

Exact identities for developers and auditors.

Show exact identities and hashes
R13-A REISSUE R4 authorityd47176e2e0d6809b768404c25f069103ac4c4a1bda6f70d9528544e9251784ff
R8 founder pinfef6c8fa131fc00caa048f2a1fde255b09070bfe3c3d70dfb0fef39138dbf8de
Acquisitionberm.acquisition.x-direct-status/1
sha256:46fbed235696decc92e298e55e3a4ee1ebd5e61d169cd3462265cb3ff5c98f1d
Transportberm.transport.x-syndication-via-same-origin-proxy/2
7e208b3b192f1d2d3caa503a6d3b54fac1c8c533dba9ce1d1c11464a9dce11bf
LineageR13-A REISSUE R4 (/1, historical) → R8 (/2, current)

Repository documentation: docs/berm-protocol/ in the source repository. The canonical public repository link is configured at publication and is not asserted here.