Skip to main content

What is dig-store?

dig-store is a Git-shaped, encrypted, content-addressable project that compiles to a single self-defending WebAssembly module.

You get Git-style commands — init, add, commit, log, clone, push, pull — for a project that is encrypted at rest and compiles into one .wasm file. That single file is both your data and the server that gates access to it. A host that stores or relays it sees only ciphertext addressed by hashes; it cannot read what it carries.

You address content with a URN, and the URN is the key: it both locates and decrypts. Hand someone a URN and they can read that resource; without it they can't — there is no separate password or access list to manage.

Unlike Git, dig-store is built for build output, not repository source. You point a project at a directory like dist/ and it captures what's there.

Why it exists

Problemdig-store's answer
Hosts can read / scan what you publishContent is encrypted at rest; the host holds only ciphertext keyed by hashes
Access control means passwords and ACLsThe URN is the capability — share it to grant read, withhold it to deny
You have to trust the server to serve genuine bytesclone/pull verify the module's store id, the publisher's signed root, and the on-chain singleton root before installing — fails closed
"How big is this payload?" leaks from file sizeEvery project is one .wasm, padded to a uniform size that reveals nothing about its contents
Serving logic lives separately from the dataThe data and the code that gates it compile into the same module

How to read these docs

  • The dig-store Format — the concepts: projects, deployments, the .wasm module, URNs, encryption, and proofs. Start here if you want to understand what dig-store is.
  • CLI Tutorial — install the CLI and use it in a real project: initialize a project, capture a build directory, commit deployments, share over a remote, and stream content back out.

If you just want to try it, jump straight to the Quickstart (the free, web-first path) or the CLI tutorial.

note

dig-store is part of the DIG Network. The full technical design lives in the Protocol section — the content-addressable WASM store format.