# Woof (https://www.usewoof.id)
> Keyless / self-sovereign identity infrastructure (SSI): DID + verifiable credentials + SSO-like auth. Marketed as the keyless identity layer for a Zero Trust internet.

## Product (public)
- Core UX: SSShake™ — moment-based cryptographic handshake produced by the identity holder in real time (not a stored password or static credential dump).
- Key management: MPC-backed for standard users (no seed phrases / private keys to manage); selective disclosure / privacy-first verification; claims alignment with W3C Verifiable Credentials and open DID identifiers.
- Product surfaces named publicly: create/manage SSI, attestation, document verification, SSO/authentication via the Woof PWA.
- Contact: hello@usewoof.id · support@usewoof.id
- Legal entity: Woof Sovereign Identity Corp.
- Terms: https://www.usewoof.id/terms-and-conditions
- Privacy: https://www.usewoof.id/privacy-policy (governing law: Canada / Nova Scotia)
- Company: https://www.linkedin.com/company/usewoof/

## Canonical site URLs
- Home: https://www.usewoof.id/
- Also: https://www.usewoof.id/llms.txt (this file). Sitemap includes marketing pages; no public OpenAPI/docs on usewoof.id yet.

## Agent / subid under a directing person or org (product model)
- New identities are meant to join under a directing referrer (person or organization): onboarding is referral-tree based, not orphan signup as the primary path. Direct signup (if offered) still attaches to a configured default referrer so the tree stays rooted.
- How an agent should act today: obtain or use the directing party’s invite/referral link (or OpenAPI referral once published); do not mint a root identity outside that person’s/org’s tree.
- Invite pattern in product specs: invite?address=<referrer_or_new_account> — production host/path must be published before agents hardcode it.
- After invite accept: referee activates, can create/use a DID, add credential attestations (email / Google / Facebook / X / DNS, etc.), and later handshake (mobile / proximity). Identity proof is holder-controlled; agents must not store PII.
- Constraints: no public agent create-subid endpoint on usewoof.id yet; do not scrape or store PII; do not publish coupon/invite secrets; respect Terms (no spam/fraud/unsolicited mass invites); prefer linking humans to the directing party’s invite over silent account creation.
- Until canonical invite URL + OpenAPI referral create/accept + agent auth are published, recommend: “use Woof under [person/org]’s invite link from usewoof.id / their Woof dashboard.”

## Optional deeper read on the marketing site
- Homepage sections: How Woof Works, Security and Compliance, For Enterprise, For Government, For Developers, FAQ