Vollmacht
Menu

Experimental · Design and research

Build with us

Explore the source, challenge the design, and follow the work.

Not a released authorization system. Do not use as the sole control for production-critical operations.

Start with the project

The Vollmacht repository is public. Start with its README for the current implementation status and development instructions. This website describes the direction; the repository records what is implemented and tested.

There is no production-ready installation or live merchant integration to offer yet. You can help now by reviewing the architecture, testing documented experiments, and proposing concrete improvements.

Read the contribution guide before opening a change. Follow the security policy for vulnerability reports rather than posting sensitive evidence in a public issue.

Website contributor preview

The website repository is public; no GitHub account is needed to clone it over HTTPS. Hosting is being configured separately. Use the Node version in .node-version and Python 3.12 or later.

git clone https://github.com/vollmachtio/vollmachtio.github.io.git
cd vollmachtio.github.io
npm ci
npm run build
npm run preview

Open http://127.0.0.1:4173. Stop with Ctrl+C. The preview serves only generated website assets, not source files or Git metadata.

Checks

npm test
npx playwright install chromium
npm run test:browser
npm run check:external

Browser tests inspect desktop and mobile widths, keyboard navigation, local links and automated accessibility rules. The external-link check accesses only explicitly permitted documentation hosts and uses no GitHub credentials. Automated accessibility checks do not replace manual testing.

Protocol experiments

Consult the core repository’s README and experiment instructions for current commands, prerequisites and known limitations. This page deliberately avoids duplicating an evolving implementation guide.

The Rust WebAuthn probe tests a browser ceremony. The SimpleWebAuthn experiment assesses operation-derived challenges. Neither is a production mandate service or GitHub enforcement integration. Synthetic test success is not evidence that a physical Touch ID ceremony was tested.

Do not supply production GitHub credentials or use these experiments as the sole control for production-critical operations.

What comes next

Finish browser and key-storage feasibility gates, freeze the mandate profile through review, build issuer/verifier and durable replay state, then add a disposable-repository GitHub demo. Website examples describe that direction, not shipped features.