HARA / IDENTITY

One GitHub identity across Hara.

Sign in once here and the same GitHub account is visible on www, World, Specs, and Packages. The browser session is operational identity only; package keys, namespace grants, signatures, and revocations remain independently verifiable trust records in Git.

WEB SESSION GitHub account

A short-lived, signed session identifies the stable numeric GitHub account across approved Hara origins.

TRUST STATE Keys and grants

Publisher authorization still requires explicit public keys, namespace grants, signatures, and revocation checks.

PUBLIC COORDINATES

Inspect the boundary.

Root key — ed25519

Pinned public trust anchor

638ad43d5840a7013e5462d0a52da429774257b8ec0a0794e6818aaa0aa835a2

The GitHub provider token is used only to read the account identity during sign-in and is not retained in the Hara session. Private package signing material is never held or served here.