Status: Proposed
Date: 2026-09-23
Supersedes: none
Related: ADR-A82 (point 5, as amended), ADR-A77, ADR-A79, ADR-A71, ADR-A29, identity minting specification, iri-identity-patterns.md
Drafted by: Agent, following decisions taken with the human while scoping the identity-minting unit (sketch, plan). Pending human ratification.
ADR-A82, as amended, has the persistence compiler produce minting recipes and conformance vectors, and leaves executing a recipe to runtime code. That code runs in more than one language: the Control Plane is Java, the workers are Python, and other runtimes are expected. An adopter may use neither LATTICE runtime and still want to mint identifiers exactly as LATTICE would. Every implementation must produce byte-identical IRIs for the same recipe and input, or one key gets two identities.
Two languages disagree by default on the operations minting depends on. Java has no NFKC_Casefold and no full case folding. The two languages define whitespace differently. Java measures strings in UTF-16 units. Each runtime ships its own Unicode version.
packages/minting/: packages/minting/python and packages/minting/java. packages/ is a top-level root that ADR-A77 already reserves. They are libraries meant to be embedded, so they belong neither in tools/ (design-time toolchains) nor in platform/ (the LATTICE runtime).pom.xml, not a child of platform/pom.xml. No native code, no network access and no other LATTICE component is needed at build or run time. mise tasks build and test both (ADR-A29).contracts/identity/recipe.schema.json), verifies its digest, and mints from it. It never reads the adopter’s configuration graph.contracts/identity/anchor-vectors.json, which are verified with independent tools, and the vectors the compiler generates per recipe. An implementation written from the specification alone is conformant on exactly the same terms.SecretProvider to it.toolchain-jdk25-python314).contracts/identity/ becomes a public contract. Its schemas, anchor vectors and verification script are MPL-2.0, tracked through REUSE.toml, because JSON cannot carry a licence header.