Skip to content

00 — OpenPassport's open notebook

Every model starts from zero. Your business's truth gets diluted.

You move from ChatGPT to Claude, from Claude to Gemini, from one person to the next, and the context gets rebuilt by hand. Every copy drifts. OpenPassport is our experiment to pin that truth down: versioned Markdown, a manifest with SHA-256 hashes, and exposure profiles. Any model can load it; anyone can verify it; it belongs to whoever originates it.

Format
Markdown + manifest
Integrity
SHA-256 · UTF-8 · LF
Status
Working prototype
Fig. 0Same company, three truths
  • ChatGPT

    offer: the one in March's PDF

    outdated
  • Claude

    tone: whatever the last chat used

    drift
  • Gemini

    current state: —

    no context

one Passport, loaded into all three

passport/ · manifest.json

7 layers · sha256 per file · profiles

verify → 100% PASS

01—Anatomy

A Passport is a folder. Its contract is the manifest.

Seven Markdown layers, numbered in the order a model should read them. A manifest.json declares every file: layer, type, visibility and hash. If it isn't in the manifest, it isn't part of the Passport.

Identity. Who originates the Passport, what it exists for and what it isn't. Read first; it doesn't change from session to session.

manifest.json → files[1]real
{
  "path": "01-IDENTITY.md",
  "layer": "identity",
  "mediaType": "text/markdown",
  "sha256": "8e0f98223171905ac6bdc3da4f35e4fd643d7cc328b7a4c9b1e419e07ca1fca5",
  "visibility": "public"
}

Load order · loadContract

  1. 1 manifest.json · bootstrap
  2. 2 MASTER-PROMPT.md · firstContext
  3. 3 profiles[].files · in listed order

Outside the seven

Files the manifest declares as well. Runtime and the private layer exist in the Multiversa.Group Passport v0.3.0; in the template they're optional.

manifest.json
manifest · public
The package contract: files, layers, hashes, profiles and load order.
MASTER-PROMPT.md
interpreter · public
The first context the model reads: how to interpret everything else.
runtime/*.json
runtime · private-operational
What is connected today. Optional in the template.
private/founder-private.md
founder-context · founder-private
The originator's context. Never ships in a public profile.

02—Integrity

Change one byte and the Passport says so.

Portability without verification is just another copy waiting to drift. So the format pins a byte contract, and every file travels with its hash.

i.

Byte contract

UTF-8 and LF line endings. A .gitattributes file keeps Git on Windows from converting to CRLF and breaking the hashes; build --fix-crlf normalizes before sealing.

hashByteContract: "UTF-8, LF line endings"

ii.

SHA-256 per file

Every declared file carries the hash of its exact bytes, in lowercase hex. Change a comma and the hash changes.

hashAlgorithm: "sha256" · hashEncoding: "lowercase-hex"

iii.

manifestSelfHash

The manifest hashes itself: its own entry is replaced with 64 zeros, it's serialized with 2-space indentation and LF, and the SHA-256 is computed. Same result in TypeScript and in Go.

raw-bytes-with-own-sha256-replaced-by-64-zeroes

~/multiversa-lab · multiversa passport verify
$ multiversa passport verify ./open-passport-template
🔒 Verificando integridad criptográfica en: …/open-passport-template
🎉 [100% PASS] Todos los archivos verificados con hashes SHA-256 e integridad LF determinista.
# now we alter one byte in the voice layer
$ echo tamper >> ./open-passport-template/03-VOICE.md
$ multiversa passport verify ./open-passport-template
🔒 Verificando integridad criptográfica en: …/open-passport-template
💥 Falló la verificación de integridad:
- Hash inválido para 03-VOICE.md: esperado=b1e0352c856f0b6302bf0405055bd5de8beef9b67b901bf258e2d9d41d37dbb6, obtenido=1e0a8150268ac7effe020f671f4b842dacf1ee3bab0fe9c35a5b7d99d1e92198
# exit status 1
Real output of the CLI built from cli/ · Oct 10, 2026 · path shortened

What it proves

That the bytes you're reading are the ones that were sealed. If someone edits a layer without rebuilding the manifest, verify fails and tells you which file and which hash.

What it doesn't prove yet

Who sealed it: there's no author signature yet. The Go CLI has no tests of its own, and the CI fallback can report full integrity after checking only the manifest. Fixing that is LAB-008.

03—Governance

The model proposes. Whoever originates the Passport decides.

A profile defines which files each consumer sees. The same Passport can feed a public chat and an internal assistant without mixing what each one is allowed to read.

Files included per profile
Filecore
pub
commercial
pub
operational
priv
founder
priv
01-IDENTITY.md
02-DOCTRINE.md
03-VOICE.md
04-OFFER.md
05-GOVERNANCE.md
06-CURRENT-STATE.md
07-EVIDENCE.md
runtime/adapters.json
runtime/runtime-state.json
private/founder-private.md
Fig. 3 — Real profiles from the Multiversa.Group Passport v0.3.0 (manifest.json).

Fail-closed

Partial

An unknown profile is an error, never full access. The CLI already does this on export: perfil 'nope' no encontrado en manifest.json. The MCP server doesn't yet: if it can't find the profile, it doesn't filter. Fixing that is LAB-007.

The package grants no authority

"ownership": "originator-owned",
"authorityGrantedByPackage": false,
"implicitMemory": false

Loading a Passport doesn't give any agent permission to act, and it doesn't create implicit memory. Sensitive decisions go through a person.

One vocabulary, not two

Today the template identifies profiles by id and the Group Passport by name. Two consumers can read the same file differently. Unifying them is LAB-001 and LAB-004.

“AI proposes; the human decides.”

04—Position

Memory remembers. The Passport establishes.

They don't compete. Working memory keeps what happened; the Passport pins down what's true, with a version and a hash. One sits beneath the other, and the model consults both.

  1. Canonical layer

    Passport-Context

    versioned · hashed · governed · originator-owned

  2. Models and agents

    • ChatGPT
    • Claude
    • Gemini
    • Grok
    • Qwen
    • Mistral
    • …
  3. Working memory

    pgvector · provider memory · Engram

Fig. 4 — Where the Passport sits.
Working memoryPassport
What it keeps
What happened: observations, decisions and session summaries.
What is true for the business: identity, offer, governance, state.
Who writes
The agent, automatically or semi-automatically.
The originator, with human review.
How it changes
Continuously, every session.
By version: packageVersion and an asOf cut-off date.
Verification
Whatever each engine offers.
SHA-256 per file and manifestSelfHash.
Portability
Lives in its engine: vector database, provider or local binary.
A folder of plain text; loads into any model.
Ownership
Depends on the tool or the provider.
originator-owned, declared in the manifest.

Engram is open-source persistent memory for coding agents, by Gentleman Programming. In the Lab it's a recommended upstream, not a rival: it remembers the work; the Passport pins the judgment.

05—Lab notebook

What works, what's missing and what we don't promise.

This is a lab, not a packaged product. We publish the verified state with a cut-off date, and we correct it in public when we get something wrong.

  • passport-core · TypeScript

    Working prototype

    3 of 3 tests pass. Not published on npm.

  • multiversa passport · Go

    Working prototype

    Builds. verify: 100% PASS on the Multiversa.Group Passport v0.3.0. No tests of its own.

  • open-passport-template

    Working prototype

    Lives in the repository. verify: PASS.

  • mcp-passport

    In the lab

    The code exists. Not verified in use. An unknown profile doesn't fail closed today.

  • Contract V0

    Pending: Contract V0

    Versioned schema, fixtures, TS/Go parity, fail-closed MCP and a release. 10 open tasks.

Contract V0 · 0 of 10

odd/tasks/openpassport-contract-v0.md
  1. LAB-001Freeze the vocabulary and versioning policy
  2. LAB-002Publish the JSON Schema and canonical fixtures
  3. LAB-003Migration from 7 layers to 10 domains
  4. LAB-004Align profile and visibility semantics
  5. LAB-005TypeScript core as the canonical behavior
  6. LAB-006Go CLI parity and content export
  7. LAB-007Fail-closed per-profile access in MCP
  8. LAB-008Honest integrity verification in CI
  9. LAB-009Reproducibility with Docker
  10. LAB-010Package and document a versioned release

Release channel

Repository
Open lab. main moves.
Stable version
The tagged release the founder controls.
OpenPassport tags
None. The repository's MV-2026.07.0-rc.* prereleases belong to the Lab's umbrella release, not to OpenPassport.
First tag
v0.1.0 · pending

Errata

We've withdrawn two claims made by earlier versions of this page:

  • OpenPassport v1.0 as an issued standard. The code exists; the release doesn't.
  • Validated on 8 real projects. There was no evidence to back it.

06—Logbook

What we did, when, and with what.

A dated record of how the Lab works and which tools it uses. One line per entry; newest first.

  1. workflow

    Workflow tools: Claude (the Claude app and Claude Code), plus Gentle Suite and Gentle Shell by Gentleman Programming.

  2. web

    Lab landing aligned with Multiversa's visual DNA: the same Cosmic Night tokens and typography as Multiversa.Group.

  3. release

    Publishing model: the repository is the lab; the stable version will be a tagged release. OpenPassport has no tags of its own yet.

  4. passport

    Passport 0.3.0/0.3.1: a single truth across the website, CV and Passport; hashes verified with the CLI multiversa passport verify.

Tools and credits

Credit where it's due. These tools are part of how we work. This is attribution, not endorsement: none of their authors sponsors or backs Multiversa, and their names and marks belong to them.

Gentleman Programming: gentlemanprogramming.com · github.com/Gentleman-Programming

  • Claude

    Anthropic

    The Claude app and Claude Code: research, writing and assisted building. AI proposes; we decide.

  • Gentle Suite

    Alan Buscaglia · Gentleman Programming

    Gentle AI configures the coding agents you already use (Claude Code, Cursor, OpenCode, Codex, Pi…). Engram is persistent memory for agents: a Go binary with SQLite + FTS5 and an MCP server.

    Open source · MIT

  • Gentle Shell

    Alan Buscaglia · Gentleman Programming

    A Pi-native coding-agent harness for controlled development (formerly gentle-pi).

    Open source · MIT

07—Use it

Clone. Verify. You decide.

Everything on this page is in the repository, under the MIT license. These commands were run exactly as shown before we published them.

  1. 01

    Clone the lab

    $ git clone https://github.com/moshequantum/multiversa-lab.git && cd multiversa-lab
  2. 02

    TypeScript core

    $ pnpm install && pnpm build:core && pnpm test

    # tests 3 · pass 3 · fail 0

  3. 03

    Go CLI

    $ cd cli && go build -o multiversa .

    go 1.23+ · local binary

  4. 04

    Verify the template

    $ ./multiversa passport verify ../templates/open-passport-template

    [100% PASS]

  5. 05

    Create your own

    $ ./multiversa passport init ./mi-passport --name "MiNegocio" --originator "Tu nombre"

    writes the 7 layers, .gitattributes and MASTER-PROMPT.md

  6. 06

    Edit the layers and seal it

    $ ./multiversa passport build ./mi-passport

    hashes + manifestSelfHash + generation.receipt.json · then: export --profile core-public

?—FAQ

What people ask us, in short.

What is OpenPassport?
Our experiment to pin down a business's truth: a folder with seven Markdown layers and a manifest.json that declares every file with its layer, type, visibility and SHA-256 hash. Whatever isn't in the manifest isn't part of the Passport. It belongs to whoever originates it.
How do I verify a Passport?
With the Go CLI in the repository: build it with go build -o multiversa . inside cli/ and run ./multiversa passport verify <folder>. It recomputes every file's SHA-256 and the manifestSelfHash; if someone changed a byte without rebuilding the manifest, verify fails and tells you which file and which hash.
Is it stable? What's its status?
It isn't stable. It's a working prototype (cut-off: Oct 10, 2026): passport-core passes 3 of 3 tests and isn't published on npm; the CLI verifies real Passports; the MCP server isn't verified in use. Contract V0 is pending (0 of 10 tasks) and OpenPassport has no tagged release of its own.
Which models can load it?
Any model that reads text: a Passport is a folder of plain text. On this page we show it with ChatGPT, Claude, Gemini, Grok, Qwen and Mistral. MASTER-PROMPT.md is the first thing the model reads, and the manifest sets the load order.
How is it different from a memory system?
Working memory (pgvector, provider memory, Engram) keeps what happened in sessions. The Passport pins down what's true for the business, with a version and a hash, and its originator governs it. They don't compete: the model consults both.
What's the license?
MIT. Everything on this page, code included, is in the public repository github.com/moshequantum/multiversa-lab.