September 25, 2026English
Ğ1 and its web of trust
Ğ1 —the French monnaie libre, “the june”— pays a Universal Dividend per person per day. There is no central bank, no new coins for capital, and no way to issue extra: the only door into the money is being a person distinct from all the others.
That is the whole problem. Such a system has to answer, without a State and without identity companies, the oldest question in decentralised reputation: how do you know there is a human behind a key, and only one?
Ğ1 does not answer it with documents, or selfies, or scanned irises. It answers it with a web of trust (toile de confiance): a directed graph whose vertices are people and whose edges are signed certifications. And it does it with a detail almost no other system dares to copy: trust expires, and it has to be renewed.
This is a walk through that mechanism, panel by panel, with the real parameters written into the genesis block.
One human = one account is not a slogan: it is accounting

In Ğ1 every member co-creates the Universal Dividend every day: the same amount for everyone, every day. If someone duplicates, they print money twice and steal it from the community. That is not an administrative breach: it is a monetary failure.
Which is why the web of trust is not meant to “reward good behaviour” — it is meant to make duplication not pay. The Duniter documentation is explicit: the goal is not fraud made impossible but fraud made pointless, and four concrete objectives follow from it:
- Make certifying slow enough that everyone exercises care.
- Make fraud uncomfortable enough that it is not worth the trouble.
- Keep a Sybil attack’s monetary impact negligible.
- Slow the growth of a “fake region” so the community has time to react and isolate it.
The gate: the licence comes before the signature

Before any certification, the certifier must hand over the Ğ1 licence and make sure the other person has studied it, understood it and accepted it. The licence (version 0.2.9) is not a legal contract: it is a moral commitment, and it lists what has to be checked before signing:
- Know the person well enough — not an acquaintance, but someone you can reach through several channels and with whom you share other contacts.
- Personally check with them that the public key is correct.
- Verify that they have generated their revocation document (account, key and document ready before any catastrophe).
- Meet them in person to verify their identity — or, failing that, verify the person/key link remotely through several distinct channels (social networks, forum, email, video call, voice call). Hacking one inbox is easy; hacking four channels and also imitating face and voice is not.
The licence even states what no identity system admits: if you know none of the other certifiers of that person, that is a strong signal that you do not know them well, and certifying in that context raises an alert across the whole community. And a recommendation that reads like a house rule: never certify alone, always with another member beside you.
The five seals

The gate does not open with one signature, it opens with five:
sigQty = 5: the identity needs certifications from 5 different members to be accepted into the web of trust.idtyWindow = 2 months: the maximum time a new identity has to gather those five signatures. Past the deadline the signatures are cancelled and everything starts over.
The five seals are not collected in an afternoon for a practical reason: every certification goes through the node’s pool and only enters the chain once the whole web accepts it. That is why the windows were designed long — two months is time for certifiers to coordinate, meet, and ask the uncomfortable questions.
One detail that is not minor: the pseudonym is chosen once and never changes. Between 3 and 42 characters, alphanumeric, hyphen and underscore. The only way to change it is to revoke the identity and start from zero: pick badly and it stays written on the chain forever.
The anti-Sybil jump: the distance rule

Here is the heart of the design, and the rule that makes the web a single network instead of a scatter of small circles of friends:
stepMax = 5: the new member has to be within 5 hops or fewer of 80% of the referent members.xPercent = 80%: that 80% is the share of referents that must be reachable.- Referent member (or “sentinel”): a member whose total degree —certifications issued and received— is greater than or equal to
ceil(N^(1/stepMax)), that isceil(N^(1/5)), with N the total number of members.
In plain words: five accomplices in a corner cannot create a fake network. If your group is isolated from the main body of the web, the jump is impossible. A Sybil region can only grow as far as its distance to legitimate referents allows, and since stepMax is small, that region has a ceiling. That is why in the genesis block referent members were placed at least four hops apart: so an attacker has a long way to walk before getting close.
xPercent also prevents the opposite: a minority of referents locking onto each other and freezing the entry of new people. A lock that works for attacking does not work for protecting.
Duniter v2 adds a new edge: if the distance evaluation is falsified, a slash goes to the network’s treasury. It is no longer just “you don’t pass”: it costs.
The art of rigour: pace and stock

A web of trust can also be attacked by exhaustion: someone who signs whatever is put in front of them turns the system into paperwork. Two parameters stop that:
sigPeriod = 5 days: between each certification issued, a member must wait five days. You cannot certify in bulk.sigStock = 100: at most 100 active certifications issued at the same time. Hit the ceiling and you wait for one to expire before signing another.sigWindow = 2 months: an issued certification waits in the pool two months at most; if it has not entered the chain by then, it is cancelled and your slot is returned.
The underlying logic: time is the filter. A fast Sybil attack gets noticed; a slow one runs into distance. The five days also have a human reason: certifying means reading the licence, meeting, talking. Five days covers the weekend, and certifying stops being a click.
Trust is not forever

This is where Ğ1 does something different from any identity system we know. Membership is not a lifelong title:
msValidity = 1 year: membership expires after a year and has to be renewed with your own key.sigValidity = 2 years: every certification received expires two years after it was issued.- Drop below 5 valid certifications and you lose member status and the Dividend. And if you stopped renewing, you get a one-year grace period to come back; after that, the identity is revoked automatically.
The reasoning is twofold and fairly blunt: nobody should keep collecting a Dividend after they die, and an account that turns hostile has to be able to leave the web at some point. Renewing is a button in the app; what matters is that the web does not accumulate ghosts: it cleans itself.
Genesis and fall

The web could not start two at a time. On 8 March 2017, at 16:32 (UTC+1), Ğ1 launched with 59 founding members and 551 certifications linking them, 590 Ğ1 produced in the first Universal Dividend, and six members computing blocks. In the genesis block only two rules could be applied (minimum certifications and certification stock): distance does not exist until the graph exists.
And the fall: lose your key and you start from zero. You have to revoke the identity —a signed act, not a support ticket— and gather five new signatures. Hence the urgency of having the revocation document ready before the catastrophe, not after.
The system had its own end of an era: on 7 March 2026 the last Duniter v1 block was created (block 913,638) and all the data moved into Duniter v2’s block zero, a full rewrite in Rust on the Polkadot SDK. Since 8 March 2026 the Universal Dividend is produced by v2. The migration brought a fine-grained indexer (duniter-squid) and features being switched on gradually: scheduled transfers, guardian accounts, group accounts and on-chain governance.
The live numbers, read from the network’s indexer on 25 September 2026:
- 5,827 active members.
- 18,564 identities created since 2017 (including expired and revoked ones).
Ten parameters, one single idea
| Parameter | Value in Ğ1 | What it is for |
|---|---|---|
sigQty | 5 | Different certifications needed to become a member |
idtyWindow | 2 months | Time for a new identity to gather its 5 signatures |
stepMax | 5 hops | Maximum distance to referent members |
xPercent | 80% | Share of referents that must be within that distance |
sigPeriod | 5 days | Mandatory wait between issued certifications |
sigStock | 100 | Maximum active certifications per member |
sigWindow | 2 months | Life of a certification in the pool before cancellation |
sigValidity | 2 years | Expiry of each certification received |
msValidity | 1 year | Expiry of membership itself |
dt | 86,400 s | Universal Dividend creation interval (1 day) |
One idea: time, distance and the memory of other humans are the verification mechanism. Nothing else.
What this mechanism does and does not do
Honesty is worth it here, because Ğ1’s design is explicit about it: the web discourages, it does not prevent. The Duniter documentation says micro-attacks by small groups are not its problem, and that the web’s role is to guarantee a working currency, not to be an identity police force. The rest —cross-checking between certifiers, flagging someone who certifies a person they do not know, pushing a hostile member out— is the community’s job, and the licence asks for it in writing.
The model’s cost is also its filter: five people who have seen your face, two months of patience and a yearly reminder. After nine years, that adds up to 5,827 members. The State solves the same problem with a document; some crypto projects, with an iris. Ğ1 solves it with five humans who vouch for you — and who have to be able to find you when something goes wrong.
Our proposal: the dojo evolves
Ğ1 has already shown the way. For our system we keep the essence of its web of trust, but we make the anti-collusion rules mandatory from the very first stage:

What we keep from Ğ1
- The 5 mandatory signatures.
- Expiry dates (membership and certifications).
- In-person verification.
- Losing the badge if you drop below 5 signatures.
What we add
- The distance rule, vital against collusion, from day one.
- A pace limit (anti-wear filter): the rate of signatures is part of the design, not an option.
- The Ius licence, signed before the first certification.
- Revocation required from day one: the document ready before it is needed.
The difference is one of order: in Ğ1 the anti-collusion rules apply once the graph already exists; in our proposal they are a condition of entry. The dojo is ready.
Verified sources
- Duniter — Deep-dive into the Web of Trust (the eight rules and eleven parameters of the WoT, with Ğ1’s values): https://duniter.org/wiki/web-of-trust/deep-dive-wot/
- Duniter — Ğ1 Licence v0.2.9 (licence text, certifier commitments and the brief WoT rules): https://duniter.org/wiki/g1/license-txt/
- Duniter — Become member (v2 flow: licence, first certification, pseudonym, 5 certifications, distance rule, renewal and self-revocation): https://duniter.org/wiki/g1v2/become-member/
- Duniter — Duniter v2 is live (7 March 2026; last v1 block 913,638; rewrite in Rust on the Polkadot SDK): https://duniter.org/blog/duniter-v2/
- Duniter — Ğ1 : c’est parti ! (8 March 2017: 59 initial members, 551 certifications, 590 Ğ1 from the first UD): https://duniter.fr/blog/g1-go/
- Ğ1 network indexer (duniter-squid), queried on 25/09/2026: 5,827 active members and 18,564 identities created — https://squid.g1.brussels.ovh/v1/graphql
- Stéphane Laborde — Théorie Relative de la Monnaie (the RTM that Ğ1 implements): https://en.trm.creationmonetaire.info
- Panels: The Ğ1 Dojo, nine plates in French, included as a downloadable PDF in this article. This text translates and comments on them rule by rule.