Protocol v2Adopt DeDi by publishing signed files on your own domain. No server to run, no account to create. See what changed →
Trust Infrastructure

One lookup to verify anyone, anywhere.

DeDi makes public registries instantly verifiable. Publish membership lists, public keys, licences, and revocations as signed files on your own domain — or on dedi.global — and let anyone verify them in milliseconds.

Live lookup
GET /dedi/lookup/central_bank/licensed_banks/bank-7
namespace central_bank
registry licensed_banks
bank_name Acme National Bank
status ACTIVE
signature ✓ Verified
Built for
Regulators Trade associations Certificate authorities Central banks License boards Standards bodies
Verifying a counterparty today
takes days, not seconds.

Two parties need to transact. Here's what it actually takes to check each other.

Today

Fragmented trust

1. Check authorisation
Different API per regulator. Some publish CSVs monthly. Others use PDF lists on websites.
2. Screen sanctions & verify entity
XML feeds, separate LEI lookups, cross-references with bank IDs. Every source has its own format and auth.
3. Exchange keys & monitor
Bilateral key exchange per partner. Poll each source on different schedules. No real-time alerts.
10+ sources  |  5+ formats  |  Days to weeks
No crypto proof  |  No push alerts
With DeDi

One endpoint

1. Lookup anything
Same API call for every registry, every jurisdiction. Authorised firms, sanctions, public keys — all one format.
2. Verify instantly
Every response is cryptographically signed. Tamper-proof and machine-verifiable without contacting the source.
3. Subscribe once
Get push notifications the moment anything is revoked or updated. Works for every counterparty, globally.
1 endpoint  |  1 format (JSON)  |  Milliseconds
Crypto-signed  |  Real-time push

DeDi = DNS for Trust. One lookup to verify anyone, anywhere, instantly.

How it works
Three steps. Any registry.
From publishing to verification — no server, no blockchain knowledge required.
01
Publish
Publish your registry as signed files on a domain you control — or upload it via the dedi.global dashboard or API. Every record carries your organisation's signature.
Who publishes

Governments, regulators, central banks, trade associations, certificate authorities

02
Discover
DeDi servers discover, verify, and index published files. Anyone can look up any record with a single API call — or fetch the file straight from the publisher.
What's discoverable

Public keys, membership lists, licenses, revocation records

03
Verify
Every result carries the publisher's own signature, relayed unaltered. Systems confirm authenticity automatically, whether they read from a server or from the source.
Who verifies

Applications, compliance systems, AI agents, other registries, humans

Protocol v2 · What's new
Publish files.
You're on the network.

The latest DeDi protocol update makes adoption as simple as putting signed files on a domain you control. No server to run, no account to create, no API to integrate.

01

Sign your registry

One self-contained, signed DeDi file per registry, plus a signed manifest at /.well-known/dedi.index.json declaring your keys and listing the registries you offer.

02

Host it anywhere you control

Your website, a source repository, a public file host — or deposit it with a DeDi server. Where the bytes live carries no weight in the trust model: verifiers check your signature against your manifest.

03

Get discovered

Add your domain to the public discovery list. DeDi servers such as dedi.global crawl, verify, and index your files and serve them through the standard lookup and query APIs — relaying your signature, never substituting their own. Servers are caches and indexes, not authorities.

What a publisher serves
https://example.org/.well-known/dedi.index.json
Signed manifest · fixed path · one per domain
https://example.org/dedi/dedi.public-keys.json
One signed file per registry
https://example.org/dedi/dedi.revocations.json
Same shape · a negative list
Sign with your own Ed25519 key using dedi-cli. Keys never leave the publisher. Rotation and revocation are self-service: update your manifest and you're done. Existing dedi.global publishers need to change nothing — hosted and self-published registries are served through the same APIs.
What organisations publish
Five types of verifiable registries.
01

Membership lists

Publish your member directory so anyone can verify membership in milliseconds. No more phone calls, spreadsheets, or outdated PDFs.
Example: A trade association publishes its member firms. A bank verifies a counterparty's membership before settling a transaction.
02

Public key registries

Make your organisation's signing keys globally discoverable. No bilateral exchange, no incompatible formats. Key rotations propagate instantly.
Example: A certificate authority publishes root keys. Any relying party discovers and verifies them without manual onboarding.
03

Policy registries

Publish regulatory requirements in formats that systems can automatically parse and enforce. No more manual interpretation of PDF regulations.
Example: A regulator publishes data residency rules. Platforms auto-enforce them without compliance teams manually updating configurations.
04

Revocation lists

Revoke credentials, suspend licenses, or recall certificates — and every relying party is notified in real-time. No more stale data.
Example: A license board suspends a practitioner. Every platform checking that license is alerted instantly, not on the next monthly CSV refresh.
05

AI agent registries

Register AI agents with verifiable identity, capabilities, and authorization. Let any system confirm an agent's legitimacy before granting access.
Example: An enterprise publishes its approved AI agents. Partner systems verify agent identity and permissions before accepting automated requests.
Not limited to these five. DeDi supports any type of public registry — issuers define their own schema and publish whatever registry they need.
Built as public infrastructure. Free for everyone.
99.99%
dedi.global uptime SLA
<200ms
Lookup time
Free
Forever
Open
Source & protocol
Get started in minutes.
Three ways in: self-publish on your own domain, publish on dedi.global, or integrate with the API.
Self-publish Protocol v2
01

Generate a signing key

Run dedi-cli keygen. Your private key stays with you.

02

Write and sign your files

Author the manifest and one DeDi file per registry, then sign each with dedi-cli sign.

03

Host and get listed

Serve the files on your domain and add it to the discovery list.

Publish on dedi.global No code
01

Create your namespace

Register at publish.dedi.global. Takes under a minute.

02

Upload your registry

Upload individually or bulk-import via CSV.

03

Share your registry link

Every registry gets a permanent, verifiable URL.

Integrate REST API
01

Lookup any record

GET /dedi/lookup/{namespace}/{registry}/{record}

02

Query registries

GET /dedi/query/{namespace}/{registry}

03

Subscribe to changes

Webhook notifications from dedi.global on any revocation or update — for hosted and crawled registries alike.

Why DeDi
Universal digital infrastructure.
01

No single point of failure

Publishers host their own signed files; any DeDi server can index them. No central API, no gatekeeper, no dependency on any single organisation — including us.

Publisher-hosted, server-optional
02

Tamper-proof by design

Every record carries a cryptographic signature from the publisher, relayed unaltered by any server. Verification is instant and works without contacting the original source.

<200ms verification time
03

Works everywhere

One protocol for all public registries — across sectors, jurisdictions, and use cases. From governments to startups.

Open standard & protocol

Do I need to run anything?

No. If you can put a file on your website, you can publish a DeDi registry. Prefer not to host at all? dedi.global publishes on your behalf.

Is this only for financial services?

No. DeDi works for any public registry — healthcare, legal, supply chain, government, education, and more.

What about private data?

DeDi is for public registries only. All data published should already be publicly available information.

Free & open
access.
No licensing fees, no usage caps. Built for public benefit by Networks for Humanity.

Everything is free — publishing, API access, and all platform features. No setup costs, no hidden charges.

Community governance: Future pricing (if any) will be developed with community input through a governance committee.

Start Using DeDi →

Registry Publishing

Create & manage unlimited registries
Free forever

API Access

Lookup, query, search, and watch
Free

Standard Support

Documentation & community
Included

Enterprise Support

Custom SLAs, integration help
Contact Us
More questions.
Can't find what you need? Contact our team.

DeDi (Decentralized Directory) is an open protocol, stewarded under LF Decentralized Trust, for publishing public registries as signed, machine-readable files that anyone can discover and verify. dedi.global is a free, hosted DeDi server run by Networks for Humanity: it publishes registries for organisations that would rather not host files themselves, and indexes files published anywhere else. Think of it as DNS for trust — a universal lookup layer for any public information your organisation needs to share.

Unlike traditional databases, DeDi provides cryptographic proof of authenticity, decentralized availability (no single point of failure), and unified discoverability. Anyone can verify any record without contacting the original source.

Any public information that needs third-party verification: member lists, license registries, public keys, certificates, approved vendor lists, accreditation records, sanctions lists, and more.

Yes. If you already operate a public registry, publish its contents as signed DeDi files alongside it — no change to your existing systems is required. dedi.global also supports bulk imports from CSV, JSON, and XML, and the REST API works with any language or platform.

Adoption no longer requires a server or an account. A publisher adopts DeDi by serving a signed manifest at /.well-known/dedi.index.json and one signed file per registry on a domain it controls. DeDi servers become an optional role: they discover, verify, and index published files and expose the lookup and query APIs across many publishers, relaying each publisher's signature unaltered. The information model — namespace, registry, record — is unchanged.

No. Self-publish on your own domain and any DeDi server can index you. dedi.global is there for organisations that would rather not host files themselves, and for anyone who wants cross-registry search, version history, and availability guarantees on top of the files. Existing dedi.global publishers need to change nothing; hosted and self-published registries are served through the same lookup and query APIs.

Any future pricing will be co-created with the community through a governance committee. DeDi is not a commercial product — any costs would only cover engineering and operations.

Ready to publish
your registry?

Sign two files on your own domain, or publish on dedi.global in under a minute.

Finternet Labs LF Decentralized Trust Dhiway