i.
Byte contract
UTF-8 and LF line endings. A .gitattributes file keeps Git on Windows from converting to CRLF and breaking the hashes; build --fix-crlf normalizes before sealing.
hashByteContract: "UTF-8, LF line endings"
00 — OpenPassport's open notebook
You move from ChatGPT to Claude, from Claude to Gemini, from one person to the next, and the context gets rebuilt by hand. Every copy drifts. OpenPassport is our experiment to pin that truth down: versioned Markdown, a manifest with SHA-256 hashes, and exposure profiles. Any model can load it; anyone can verify it; it belongs to whoever originates it.
ChatGPT
offer: the one in March's PDF
Claude
tone: whatever the last chat used
Gemini
current state: —
one Passport, loaded into all three
passport/ · manifest.json
7 layers · sha256 per file · profiles
verify → 100% PASS
01—Anatomy
Seven Markdown layers, numbered in the order a model should read them. A manifest.json declares every file: layer, type, visibility and hash. If it isn't in the manifest, it isn't part of the Passport.
Identity. Who originates the Passport, what it exists for and what it isn't. Read first; it doesn't change from session to session.
{ "path": "01-IDENTITY.md", "layer": "identity", "mediaType": "text/markdown", "sha256": "8e0f98223171905ac6bdc3da4f35e4fd643d7cc328b7a4c9b1e419e07ca1fca5", "visibility": "public" }
Load order · loadContract
Outside the seven
Files the manifest declares as well. Runtime and the private layer exist in the Multiversa.Group Passport v0.3.0; in the template they're optional.
02—Integrity
Portability without verification is just another copy waiting to drift. So the format pins a byte contract, and every file travels with its hash.
i.
UTF-8 and LF line endings. A .gitattributes file keeps Git on Windows from converting to CRLF and breaking the hashes; build --fix-crlf normalizes before sealing.
hashByteContract: "UTF-8, LF line endings"
ii.
Every declared file carries the hash of its exact bytes, in lowercase hex. Change a comma and the hash changes.
hashAlgorithm: "sha256" · hashEncoding: "lowercase-hex"
iii.
The manifest hashes itself: its own entry is replaced with 64 zeros, it's serialized with 2-space indentation and LF, and the SHA-256 is computed. Same result in TypeScript and in Go.
raw-bytes-with-own-sha256-replaced-by-64-zeroes
$ multiversa passport verify ./open-passport-template🔒 Verificando integridad criptográfica en: …/open-passport-template🎉 [100% PASS] Todos los archivos verificados con hashes SHA-256 e integridad LF determinista.# now we alter one byte in the voice layer$ echo tamper >> ./open-passport-template/03-VOICE.md$ multiversa passport verify ./open-passport-template🔒 Verificando integridad criptográfica en: …/open-passport-template💥 Falló la verificación de integridad:- Hash inválido para 03-VOICE.md: esperado=b1e0352c856f0b6302bf0405055bd5de8beef9b67b901bf258e2d9d41d37dbb6, obtenido=1e0a8150268ac7effe020f671f4b842dacf1ee3bab0fe9c35a5b7d99d1e92198# exit status 1
What it proves
That the bytes you're reading are the ones that were sealed. If someone edits a layer without rebuilding the manifest, verify fails and tells you which file and which hash.
What it doesn't prove yet
Who sealed it: there's no author signature yet. The Go CLI has no tests of its own, and the CI fallback can report full integrity after checking only the manifest. Fixing that is LAB-008.
03—Governance
A profile defines which files each consumer sees. The same Passport can feed a public chat and an internal assistant without mixing what each one is allowed to read.
| File | core pub | commercial pub | operational priv | founder priv |
|---|---|---|---|---|
| 01-IDENTITY.md | ||||
| 02-DOCTRINE.md | ||||
| 03-VOICE.md | ||||
| 04-OFFER.md | ||||
| 05-GOVERNANCE.md | ||||
| 06-CURRENT-STATE.md | ||||
| 07-EVIDENCE.md | ||||
| runtime/adapters.json | ||||
| runtime/runtime-state.json | ||||
| private/founder-private.md |
An unknown profile is an error, never full access. The CLI already does this on export: perfil 'nope' no encontrado en manifest.json. The MCP server doesn't yet: if it can't find the profile, it doesn't filter. Fixing that is LAB-007.
"ownership": "originator-owned", "authorityGrantedByPackage": false, "implicitMemory": false
Loading a Passport doesn't give any agent permission to act, and it doesn't create implicit memory. Sensitive decisions go through a person.
Today the template identifies profiles by id and the Group Passport by name. Two consumers can read the same file differently. Unifying them is LAB-001 and LAB-004.
“AI proposes; the human decides.”
04—Position
They don't compete. Working memory keeps what happened; the Passport pins down what's true, with a version and a hash. One sits beneath the other, and the model consults both.
Canonical layer
Passport-Context
versioned · hashed · governed · originator-owned
Models and agents
Working memory
pgvector · provider memory · Engram
Engram is open-source persistent memory for coding agents, by Gentleman Programming. In the Lab it's a recommended upstream, not a rival: it remembers the work; the Passport pins the judgment.
05—Lab notebook
This is a lab, not a packaged product. We publish the verified state with a cut-off date, and we correct it in public when we get something wrong.
passport-core · TypeScript
3 of 3 tests pass. Not published on npm.
multiversa passport · Go
Builds. verify: 100% PASS on the Multiversa.Group Passport v0.3.0. No tests of its own.
open-passport-template
Lives in the repository. verify: PASS.
mcp-passport
The code exists. Not verified in use. An unknown profile doesn't fail closed today.
Contract V0
Versioned schema, fixtures, TS/Go parity, fail-closed MCP and a release. 10 open tasks.
Release channel
Errata
We've withdrawn two claims made by earlier versions of this page:
06—Logbook
A dated record of how the Lab works and which tools it uses. One line per entry; newest first.
Workflow tools: Claude (the Claude app and Claude Code), plus Gentle Suite and Gentle Shell by Gentleman Programming.
Lab landing aligned with Multiversa's visual DNA: the same Cosmic Night tokens and typography as Multiversa.Group.
Publishing model: the repository is the lab; the stable version will be a tagged release. OpenPassport has no tags of its own yet.
Passport 0.3.0/0.3.1: a single truth across the website, CV and Passport; hashes verified with the CLI multiversa passport verify.
Credit where it's due. These tools are part of how we work. This is attribution, not endorsement: none of their authors sponsors or backs Multiversa, and their names and marks belong to them.
Gentleman Programming: gentlemanprogramming.com · github.com/Gentleman-Programming
Claude
Anthropic
The Claude app and Claude Code: research, writing and assisted building. AI proposes; we decide.
Gentle Suite
Alan Buscaglia · Gentleman Programming
Gentle AI configures the coding agents you already use (Claude Code, Cursor, OpenCode, Codex, Pi…). Engram is persistent memory for agents: a Go binary with SQLite + FTS5 and an MCP server.
Open source · MIT
Gentle Shell
Alan Buscaglia · Gentleman Programming
A Pi-native coding-agent harness for controlled development (formerly gentle-pi).
Open source · MIT
07—Use it
Everything on this page is in the repository, under the MIT license. These commands were run exactly as shown before we published them.
Clone the lab
$ git clone https://github.com/moshequantum/multiversa-lab.git && cd multiversa-labTypeScript core
$ pnpm install && pnpm build:core && pnpm test# tests 3 · pass 3 · fail 0
Go CLI
$ cd cli && go build -o multiversa .go 1.23+ · local binary
Verify the template
$ ./multiversa passport verify ../templates/open-passport-template[100% PASS]
Create your own
$ ./multiversa passport init ./mi-passport --name "MiNegocio" --originator "Tu nombre"writes the 7 layers, .gitattributes and MASTER-PROMPT.md
Edit the layers and seal it
$ ./multiversa passport build ./mi-passporthashes + manifestSelfHash + generation.receipt.json · then: export --profile core-public
?—FAQ
manifest.json that declares every file with its layer, type, visibility and SHA-256 hash. Whatever isn't in the manifest isn't part of the Passport. It belongs to whoever originates it.go build -o multiversa . inside cli/ and run ./multiversa passport verify <folder>. It recomputes every file's SHA-256 and the manifestSelfHash; if someone changed a byte without rebuilding the manifest, verify fails and tells you which file and which hash.MASTER-PROMPT.md is the first thing the model reads, and the manifest sets the load order.