spacedb-access 0.1.0

SpaceDB Layer 5 — identity & access: signed, scoped, expiring, revocable capabilities (ECDSA P-256 / ES256) that gate every read/write/compute. Inaccessible by default, accessible by mID-gated consent. The DID directory is a seam MATA implements over IAMHUMAN. Phase 1 SpaceDB Mission, M5.
Documentation

spacedb-access — SpaceDB Layer 5 (identity & access)

The consent layer, and the AI-age differentiator: inaccessible by default, accessible by mID-gated consent. Every read / write / compute is authorized by a signed, scoped, expiring, (S2) revocable [Capability] issued by an owner's identity to a bearer — a human or an AI agent with its own identity.

M5-S1 ships the core: [Identity] (ECDSA P-256 / ES256), the [Capability] + [SignedCapability] model, the [KeyDirectory] seam (DID → published key), and [authorize] — the single chokepoint enforcing signature · bearer · scope · ops · expiry. Revocation + delegation (S2) and the audit log + human-vs-AI policy (S3) build on this.

Open-core (MIT): no MATA dependency. Identities are P-256 keys behind the KeyDirectory seam; MATA resolves did:mata via IAMHUMAN, a self-hoster uses [MemKeyDirectory]. ES256 matches mID, so MATA's real mIDs verify identically.