About this demo

This origin is regenerated deterministically from the AIFeed repository on every deploy. Nothing here is hand-signed in a browser and nothing is hidden.

Keys are public on purpose

The demo signing keys live in the repository under demos/keys.js, labelled DEMO ONLY. They exist so the build and the DNS anchor are reproducible. A real publisher generates keys privately; the protocol never requires sharing them.

How the demo runs

demos/sites.jsContent model: pages, policies, navigation, themes.
tools/gen-demos.jsRenders HTML, generates SVG art, then signs manifest, pages, and index.
functions/[[path]].jsCloudflare Pages Function routes hosts, negotiates markdown, enforces strict.
tools/check-live.jsVerifies every deployed origin end to end.

What is signed

  • The manifest: JCS-canonical JSON, Ed25519, domain separation aifeed.v0.2\n.
  • Each page document: the signature covers the canonical URL and the raw bytes.
  • The delta index: same treatment with its own context.
Point an agent at this site: node examples/agent/compliant-agent.js https://demo.aifeed.md --use retrieval --fetch