Home / MeshCore / MeshCore Specification
MeshCore
Privacy-first infrastructure for identity.
Overview
MeshCore is a modular, privacy-first infrastructure for managing digital identity, credentials, authentication data, and secure personal information across devices.
MeshCore is designed to provide a unified identity system rather than treating passwords and credentials as isolated records. The system organizes authentication data, identity records, secure notes, API credentials, recovery information, and related identity resources within an encrypted, user-controlled environment.
MeshCore is designed for mobile devices, tablets, desktops, and browser environments while maintaining a consistent security model based on local-first data control, encryption, and privacy.
The system is designed to remain modular so that core identity functionality can operate independently while optional capabilities such as synchronization, intelligence, authentication methods, and integrations can be added without requiring the entire system to change.
Design Principles
- Privacy-first identity management
- Local-first data ownership
- End-to-end encryption
- Zero-knowledge architecture where applicable
- User-controlled credentials and identity data
- Portable encrypted data
- Modular system architecture
- Optional synchronization
- Vendor-neutral integrations
- Extensible plugin architecture
- Auditable security controls
- Offline-first operation
- Minimal exposure of sensitive information
- Interoperability across devices and platforms
Core Architecture
MeshCore is organized around independent core modules that provide the primary identity infrastructure.
Each module should have clearly defined responsibilities and interfaces. Modules should be capable of operating independently where practical while communicating through secure internal interfaces.
Vault Core
The Vault Core provides the cryptographic and storage foundation for MeshCore.
Features include:
- Encrypted identity vault
- Master credential-based key derivation
- Strong password-based key derivation
- Argon2id support
- End-to-end encrypted data
- Zero-knowledge design principles
- Secure encryption and decryption operations
- Secure key management
- Encrypted local storage
- Portable encrypted vault format
- Vault locking and automatic timeout
- Secure memory handling where supported
- Protection against unauthorized vault access
- Shared security primitives for other modules
The Vault Core must not expose decrypted vault contents to external services unless explicitly authorized by the user through a controlled interface.
Identity Store
The Identity Store manages the information contained within the user’s identity environment.
Features include:
- Website credentials
- Usernames
- Passwords
- Multiple accounts for the same service
- API keys
- Developer credentials
- Recovery codes
- Secure identity records
- Account metadata
- Secure notes
- Membership information
- License information
- Identity-related documents or references
- Tags and categories
- Search and indexing
- Credential expiration information
- Identity relationships
- Account status tracking
- Secure deletion
The Identity Store should support relationships between different identity resources rather than forcing every credential to exist as an isolated record.
Autofill Engine
The Autofill Engine provides secure credential retrieval and form completion across supported environments.
Features include:
- Login form detection
- Credential matching based on site and application context
- Secure username insertion
- Secure password insertion
- Multiple-account selection
- Login page recognition
- Multi-step authentication support
- Context-aware credential selection
- User confirmation controls
- Protection against credential insertion into unauthorized domains
- Browser integration
- Desktop application integration
- Mobile application integration
- Tablet support
The Autofill Engine should minimize credential exposure and should only provide credentials when the destination has been appropriately identified and authorized.
Intelligence Layer
The Intelligence Layer provides optional local analysis and recommendations based on the user’s identity data.
Features include:
- Password health dashboard
- Weak password detection
- Reused credential detection
- Old account tracking
- Unused account tracking
- Risk scoring for individual identities
- Credential security analysis
- Breach awareness
- Compromised credential detection
- Exposed account alerts
- Local usage analysis
- Frequently used credential identification
- Autofill prioritization
- Password upgrade recommendations
- Duplicate account detection
- Security improvement recommendations
- Identity hygiene analysis
Breach awareness should use privacy-preserving methods and should avoid transmitting plaintext credentials to external services.
The Intelligence Layer should prioritize rule-based analysis. The architecture may support optional machine learning capabilities in the future without requiring machine learning for core functionality.
Sensitive analysis should be performed locally whenever practical.
Bridge Layer
The Bridge Layer provides controlled communication between MeshCore and external interfaces.
Features include:
- Secure local API
- Browser extension communication
- Desktop application communication
- Mobile application communication
- Inter-module communication
- Plugin communication
- Authentication between components
- Permission-controlled requests
- Secure credential retrieval
- Session management
- Request validation
- Access auditing
The Bridge Layer should enforce explicit boundaries between the encrypted vault and external interfaces.
Sync Module
The Sync Module provides optional synchronization between trusted MeshCore installations.
Features include:
- End-to-end encrypted synchronization
- Encrypted vault synchronization
- Multi-device synchronization
- Conflict detection
- Conflict resolution
- Device registration
- Device authorization
- Device revocation
- Self-hosted synchronization
- Local network synchronization
- Peer-to-peer synchronization
- Selective synchronization
- Offline synchronization queues
- Synchronization status reporting
No plaintext identity data should be transmitted through the synchronization system.
Synchronization should remain optional. A user should be able to operate MeshCore without maintaining an external synchronization service.
Identity Expansion Module
The Identity Expansion Module extends MeshCore beyond traditional password management.
Features include:
- Secure identity vault
- Government identification records
- Membership records
- License records
- Software license keys
- Recovery credentials
- API credential storage
- OAuth token references
- SSH key references
- Developer credentials
- Encrypted secure notes
- Notes associated with identities and accounts
- Tags and searchable metadata
- Optional expiration rules
- Optional self-destruct rules
- Identity relationships
- Identity graph
- Portable identity exports
- Selective identity exports
- Full encrypted vault exports
- Encrypted import packages
- Re-importable identity data
Sensitive identity records should remain encrypted at rest and should follow the same security model as other MeshCore data.
Identity Graph
MeshCore should support a relational identity model that allows users to connect related identity resources.
The Identity Graph may connect:
- People
- Accounts
- Websites
- Applications
- Credentials
- Secure notes
- API keys
- Tokens
- Recovery methods
- Licenses
- Memberships
- Devices
- Services
- Identity records
The graph should allow relationships to be created without requiring sensitive information to be duplicated across records.
Examples of relationships include:
- Credential belongs to account
- Account belongs to service
- Recovery code belongs to account
- API key belongs to service
- Secure note relates to account
- Identity record relates to service
- Credential is used by application
- Device is authorized for identity
Portable Identity
MeshCore should treat identity data as portable user-owned information.
Features include:
- Encrypted vault export
- Selective record export
- Full identity export
- Encrypted backup packages
- Re-importable data
- Cross-device restoration
- Migration between MeshCore installations
- User-controlled backup destinations
- Export integrity verification
- Import validation
Exports should remain encrypted and should not require a proprietary cloud service.
Security Model
MeshCore should maintain security boundaries between sensitive identity data and external systems.
Security requirements include:
- Encryption at rest
- End-to-end encryption for synchronization
- Strong key derivation
- Secure vault locking
- Device authorization
- Session expiration
- Credential access controls
- Secure deletion mechanisms
- Permission boundaries
- Auditability of security-sensitive operations
- Protection against unauthorized autofill
- Protection against credential exfiltration
- Minimal external data exposure
- Explicit user authorization for sensitive operations
Security-sensitive functionality should fail safely when authorization or identity verification cannot be established.
Device and Session Management
MeshCore should provide controls for managing trusted devices and active sessions.
Features include:
- Trusted device registration
- Device naming
- Device authorization
- Device revocation
- Session management
- Remote session invalidation when supported
- Automatic session expiration
- Vault lock controls
- Biometric unlock where supported
- Secondary authentication options
- Device-specific permissions
Users should be able to identify and revoke access from devices they no longer trust.
Backup and Recovery
MeshCore should provide user-controlled mechanisms for protecting against data loss.
Features include:
- Encrypted backups
- Manual backups
- Optional automated backups
- Backup verification
- Backup restoration
- Recovery workflows
- Recovery credential management
- Multiple backup destinations
- Offline backup support
- Backup versioning
- User-controlled retention
Recovery mechanisms should not require MeshCore to possess the user’s master encryption keys.
Privacy Controls
MeshCore should provide explicit controls over how identity information is processed and exposed.
Features include:
- Local-only processing options
- External service opt-in controls
- Data minimization
- Permission management
- Credential exposure warnings
- Service access controls
- Optional telemetry controls
- Privacy-preserving breach checks
- Local intelligence processing
- User-controlled synchronization
- User-controlled exports
- Data deletion controls
Any optional external service should clearly identify what information is transmitted and why.
Optional Plugin Modules
MeshCore should support an extensible plugin architecture that allows additional functionality without requiring changes to the core identity system.
Plugins should operate through controlled interfaces and should receive only the permissions required for their declared functionality.
Authentication Plugins
Optional authentication plugins may provide:
- Hardware security key support
- Passkey support
- Biometric authentication
- One-time password support
- Additional authentication factors
- External identity provider integrations
Storage Plugins
Optional storage plugins may provide:
- Alternative encrypted storage backends
- External storage destinations
- Local network storage
- User-selected backup providers
- Custom storage adapters
Plugins must not bypass the Vault Core security model.
Autofill Plugins
Optional Autofill plugins may provide:
- Application-specific autofill behavior
- Browser-specific integrations
- Custom form recognition
- Specialized login workflows
- Additional platform integrations
Sync Provider Plugins
Optional synchronization plugins may provide:
- Self-hosted synchronization services
- WebDAV-based synchronization
- Local network synchronization
- Peer-to-peer synchronization
- Custom encrypted synchronization providers
All synchronization providers must preserve the encryption boundary established by MeshCore.
Intelligence Plugins
Optional Intelligence plugins may provide:
- Additional password analysis
- Security auditing
- Account discovery
- Breach intelligence integrations
- Local machine learning models
- Custom security rules
- Identity analysis tools
- Custom recommendation systems
Intelligence plugins should not receive unrestricted access to decrypted identity information unless explicitly authorized.
Integration Plugins
Optional integration plugins may connect MeshCore with:
- Identity providers
- Security tools
- Productivity applications
- Developer tools
- Enterprise systems
- Personal information management systems
- Other identity-related services
Integration permissions should be explicit, limited, and revocable.
Interface Plugins
Optional interface plugins may provide:
- Alternative user interfaces
- Themes
- Accessibility features
- Custom dashboards
- Specialized workflows
- Platform-specific interfaces
Interface plugins should communicate with MeshCore through defined APIs rather than directly accessing protected storage.
Plugin Security
Plugins are considered untrusted extensions unless explicitly installed and authorized by the user.
The plugin system should provide:
- Plugin permissions
- Permission prompts
- Plugin isolation where practical
- Capability-based access
- Plugin identification
- Plugin version tracking
- Plugin enable and disable controls
- Plugin removal
- Plugin access revocation
- Plugin activity auditing
- Secure plugin communication
A plugin should never automatically receive unrestricted access to the user’s identity vault.
Data Ownership
MeshCore is designed around user ownership and control of identity information.
The system should allow users to:
- Access their encrypted data
- Export their data
- Back up their data
- Restore their data
- Move data between devices
- Choose whether synchronization is enabled
- Choose where backups are stored
- Revoke device access
- Remove plugins
- Delete identity records
- Delete the vault
MeshCore should avoid requiring users to remain dependent on a single service provider for access to their identity information.
Specification Branding License (SBL)
Standard
- Fully AGPL-3.0+ compliant system
- Copyleft enforced for network deployments
- Required attribution:
- Roxanne Ardary
- https://www.roxanneardary.com/
Optional
- Specification Branding License (SBL)
- Attribution-free commercial deployment
- Pricing based on scale, usage, and deployment scope
- https://roxanneardary.com/meshcore/
License & Notice Requirements
MeshCore is released under the GNU Affero General Public License v3.0 or later (AGPL-3.0+).
By contributing to this project, you agree that your contributions will also be released under this license.
Please note the following:
- All contributions must comply with the AGPL-3.0+ terms.
- Under Section 7 of the license, all redistributions, forks, and derivative works must preserve attribution to:
Roxanne Ardary and roxanneardary.com. - MeshCore specificiations are free to use with attribution. A Specification Branding License can be negotiated upon request.
- The project’s notice.md file tracks attribution requirements and contributor acknowledgments.
Any update that adds new contributors or modifies attribution should also updatenotice.md. - When submitting a pull request, ensure that any new files maintain the attribution headers where applicable.
- Network-deployed versions of this software must also remain fully AGPL-3.0+ compliant, including exposure of source code modifications when applicable under the license.
For full legal details, please refer to the AGPL-3.0+ license and the project’s notice.md file.
Notice – MeshCore
Attribution Requirement: Under Section 7 of the AGPL 3.0+ license, all redistributions, forks, and derivative works, including network-deployed versions of this project, must provide attribution to Roxanne Ardary and roxanneardary.com.
Contributors
This file tracks contributors and their specific contributions to the project.
- Roxanne Ardary, roxanneardary.com – May 11, 2026
Created the MeshCore repository and defined the foundational architecture for a privacy-first, modular identity infrastructure system including the Vault Core, Identity Store, Autofill Engine, Intelligence Layer, Bridge API, Sync Module, and Identity Expansion system. - [Add other contributors here] – [Date]
[Describe contribution in one sentence]
License – MeshCore
This repository is licensed under the GNU Affero General Public License v3.0 or later (AGPL-3.0+).
Key Points:
- You are free to use, modify, and distribute the code.
- All redistributions, forks, and derivative works or network-deployed versions must also be licensed under AGPL-3.0+ and provide attribution to Roxanne Ardary and roxanneardary.com as required under Section 7 of the license.
- The software is provided “as is,” without warranty of any kind.
For the full license text, see GNU AGPL-3.0 License.
