Witness application

Apply to become a witness

Tell us who operates your witness and where to reach its add-checkpoint endpoint. A human reviews every application — witness value comes from independence, so we look for genuinely diverse operators, infrastructure, and jurisdictions.

Who operates it

Published on the public directory — attributable, diverse operators are what makes witnessing meaningful. Your email stays private; it's our review channel.

Where the operator is legally based, not where the machine runs. The machine's location is weighed too, as infrastructure.

The witness endpoint

From your witness software's startup output or config. The cosigner name and each vkey are checked cryptographically as you type — they must match each other exactly.

No witness running yet? The operator guide covers the software, keys, and hosting first.

Where we POST add-checkpoint. Behind a bastion, include your backend key hash segment.

What stock witnesses (omniwitness, armored-witness, sigsum) sign with today.

The cosignature spec's recommended type for new deployments — serving it puts you ahead of most of the network.

Anything else (optional)

Submitting is an offer to operate independently — not a mosskeys account, a contract, or a guarantee of listing. We never run witnesses on behalf of applicants, and we never count a witness we operate ourselves.

What happens next

  1. 1

    Human review. We check operator, infra, and jurisdiction independence — diversity, not headcount.

  2. 2

    Activation. Your witness joins the submission registry; Pro-tier checkpoints start arriving at your endpoint automatically.

  3. 3

    Transparent listing. Your operator identity goes on the public directory and every cosignature you serve is visible on the checkpoints themselves.

Verifiers pin your vkeys and choose for themselves which witnesses to trust — listing is transparency, not our endorsement.