Skip to content

Franz Franz

goFranz // personal journal
development

GLEIF vLEI to IOTA DID Bridge

Welcome, my name is Franz Geffke. I help organizations such as twin succeed online: Increase reach and revenue, sharpen customer focus and lower aquisition cost and integrate with AI - If you think it's time to grow, contact me.

You are here because you clicked on the referral link on my clients website: .

The challenge

Banks, customs authorities and trading partners need to know which legal entity is behind a digital identifier. GLEIF’s verifiable Legal Entity Identifier (vLEI) answers that question in the KERI ecosystem; IOTA DIDs answer it on-chain. There was no bridge between the two trust roots, so an organisation could hold both and still have no way to prove they belong to the same entity.

Implementation

A bidirectional binding, verifiable from either side:

  • KERI side: a self-issued Designated Aliases ACDC, anchored in the legal entity’s Key Event Log and Transaction Event Log, declares the IOTA DID as an alias of the vLEI holder.
  • IOTA side: an on-chain W3C Verifiable Credential (JWT) carries the KERI anchor seal (the KEL anchoring and TEL issuance SAIDs), so a verifier can walk back to the GLEIF trust chain.
  • Verification: three independent on-chain authority checks before the binding is accepted.

Full stack: a Move contract (VleiAttestation), an Express/Node backend, and a React 19 frontend running signify-ts in the browser so signing keys never leave the user’s device. Integrated with the Sally vLEI verifier.

Review

The design went through GLEIF technical review.

Standards

GLEIF vLEI · KERI · ACDC · W3C Verifiable Credentials · IOTA Identity

More projects

Have something like this to build?

Get in touch →