The public verification layer underneath BermLaunch. It lets a person prove, in public, that an external account belongs to their portable identity — and lets anyone check that proof without asking the application that shows it.
npub
→
public proof
→
Berm Protocol
→
portable evidence
→
applications
Boundaries that never bend
Berm Protocol does not hold private keys.
BermLaunch does not own Berm identity.
Website claims cannot exceed proof.
What Berm Protocol is
Berm Protocol is a public-goods verification layer. It is application neutral: it defines public methods for proving that an external account (today, an X account) is bound to a portable Nostr identity, and it defines the signed evidence those proofs produce.
BermLaunch is an application that consumes Berm Protocol evidence. It is not the protocol, it does not issue identity, and any other application can verify the same evidence under its own rules.
Identity model
An npub is the public half of a Nostr key pair. It is the portable root of a Berm identity. The private key stays with the person; Berm issues no identifier of its own.
External accounts are relationships an npub proves, not the identity itself. An X handle is not identity: the binding is keyed on X's immutable accountId, so a renamed or recycled handle does not move it. The handle is kept as presentation — what the post showed when observed.
(namespace, accountId) -> at most one npub, permanently
npub -> zero, one, or many external accounts
More than one external account never multiplies an npub's identity or weight.
Current standard
Protocol predecessor / authority lineage
R13-A REISSUE R4 — founder pinned
Current method-successor implementation checkpoint
R8 is the label of the implementation lane that delivered the current method. It is not a protocol version number. The earlier R4 method, berm.external_account_binding.x/1, is historical.
Standing: these are founder-pinned artifacts. This page is a documentation projection. It does not authorize deployment, genesis, live X activity, publication or release.
Proving an X account
1. Public publication. The person posts, publicly on X, exactly one proof line:
Berm Protocol: @<handle> permanently binds to <npub> #bermprotocol
2. Subject claim. The person signs, with their own key, a claim that this binding is theirs.
3. Independent validator observation. Validators independently acquire the publicly served X publication — no user OAuth, no private cookies, no privileged X credentials — run the public method, and sign what they derived.
4. The five-minute window. The observation must fall inside a half-open window measured from the post's own creation time:
0 <= observedAt - postCreatedAt < 300000 ms
Exactly five minutes is already outside. There is no mandatory second look and no one-hour finality requirement.
5. Six-field result. A success is exactly npub, accountId, handle, postId, textHash, methodHash — nothing else, and no campaign data.
6. Fail closed. Anything that is not a valid six-field result is a failure with a closed reason code. Nothing is guessed or repaired.
Validators & federation
A public method is not a validator. The method is a hashed public specification anyone can run; a validator is an instance that runs it and signs its own observation.
An operator proves its own binding by the same method, then signs an authorization naming a dedicated validator key and the exact method it may observe under. Each application's acceptance policy decides which methods, operators and keys it accepts, and how many distinct operators must agree.
Honest independence accounting: two validator instances run by one operator are one operator. Today's two instances are same-operator witnessed evidence — a working mechanism, not independent corroboration. One genuinely outside operator changes that claim; none is claimed today.
Evidence
Every step produces a signed, public artifact: the subject's claim, each validator's observation, the operator's authorization, the application's policy, and optional application receipts. Claims and observations are two signatures that are never merged.
The evidence is portable, mirrorable and reconstructable: relays, Git, static archives or indexers can carry it, and no mirror is authoritative over another. A stranger can rebuild a verdict from the artifacts and the public method alone.
This website is explanatory, not final authority. Exact bytes and hashes are.
Applications
BermLaunch consumes the portable binding under its own published policy. Joining a campaign is a distinct step: enrollment is its own signed act, separate from the identity claim, and produces a unique campaign position.
Repository documentation: docs/berm-protocol/ in the source repository. The canonical public repository link is configured at publication and is not asserted here.