OpenETR¶
Explore the possibilities in your domain: Digital Trade | Warehouse Receipts | Product Passports | Human Rights | Health Records | Academic Records | Apostille Records
Digital Copies Should Function Like Their Originals¶
Copying was never the hard problem. Digital systems can already reproduce content perfectly. The hard problem is discerning the Digital Original and independently determining the Consequential State that follows from actions concerning it.
Paper-based practice often takes this for granted. Physical possession, markings, endorsements, custody, and surrender help people identify the operative original and understand what may happen next. For digital artifacts, this has not yet been satisfactorily achieved in a general, open, and interoperable way across applications and institutions.
Digital records increasingly do more than store information. People, institutions, and machines rely on them to decide what may or must happen next.
This is a question of function, not merely format. In digital trade, the functional-equivalence approach reflected in MLETR asks how an electronic record can perform the legally relevant functions of its paper counterpart without reproducing paper mechanically. The same practical challenge appears more broadly when a record replaces a physical original, and when an authoritative record is born digital.
A warehouse receipt may be active, transferred, encumbered, redeemed, or terminated. A health record may be final, corrected, superseded, or withdrawn. An academic record may be issued and later amended. An Apostille may have been verified against an official register at a particular time.
In each case, the condition of the record affects a decision, right, obligation, status, or action. OpenETR calls that condition Consequential State.
OpenETR provides a general way for any digest-identifiable Digital Artifact to become a Digital Original. Signed, linked records concerning the artifact form a Digital Controllable Record (DCR). When that evidence is validated and evaluated under defined rules, it produces Consequential State.
Digital Artifact
+ Digital Controllable Record
+ Defined Rules
-> Consequential State
-> Digital Original
The transformation does not make the file uncopyable. It makes the artifact's consequential history independently verifiable. Identical copies remain the same digest-identified artifact; copying the bytes does not independently copy or change its Consequential State.
Content makes an artifact identifiable. Consequential State makes it an original.
The Application Should Show Its Work¶
Most digital systems answer consequential questions with an application assertion: the website says who controls the record, the registry says which status is current, or the platform says that an obligation has been discharged. The assertion may be correct, but the application rarely exposes the evidence and rules that produced it.
OpenETR changes that relationship:
Artifact + Portable Evidence + Defined Rules
-> independently reproducible Consequential State
-> application projection
Applications and databases remain useful. They can store records, authenticate users, enforce permissions, coordinate workflows, index evidence, and present the resulting state. They should not have to be the exclusive reason that state is believed.
An end-verifiable signed record carries enough evidence for another implementation to verify its attribution and integrity and determine which artifact and prior records it concerns. Given the same sufficient DCR evidence, rules, and evaluation parameters, another conforming implementation should be able to reproduce the same Consequential State without depending on the original website, service, or database.
This is how OpenETR seeks to make consequences portable. It turns Consequential State from an application assertion into an independently reproducible result.
The protocol result does not compel universal agreement. A person, institution, community, contract, authority, or applicable law still decides whether to recognize the evidence and state for a particular purpose and what effect to give them.
Consequential State -> Recognition -> Effect
Let the application display the answer. Let the artifact, evidence, and rules explain why that answer follows.
Three Primitives. One Core Concept.¶
The OpenETR model is deliberately simple. The diagram below shows how three primitives and one core concept fit together, with recognition and effect remaining outside the protocol.
The Deeper Problem: What Follows¶
Copies Are Not the Problem. Digital content can be copied perfectly, and that is often useful. The harder problem is determining what constitutes the Digital Original and what verifiable evidence establishes its consequential state.
The file alone cannot tell us who made a consequential statement about it, what has happened to it, or which state should now be relied upon.
This matters for warehouse receipts, bills of lading, permits, certificates, product passports, health records, photographs, and many other records that people and institutions act upon.
OpenETR addresses the problem without making one application, database, registry, or wallet the exclusive authority for state. It identifies the exact content and preserves end-verifiable evidence concerning it so another conforming system can apply the same identified ruleset and derive the same state.
Applications may maintain projections of consequential state, but those projections are not the authority. Applications derive consequential state; they do not own it.
Concrete Examples¶
Once the problem is understood as consequential state rather than copy prevention, familiar examples become simple.
Health records. The problem is not whether a lab report can be copied. It is whether this exact report is current, who signed it, and what verified history shows that it was corrected, superseded, or withdrawn.
Warehouse receipts. The problem is not whether the receipt PDF can be copied. It is whether the receipt remains active, who controls it, and whether it has been transferred, encumbered, redeemed, or terminated.
A copy reproduces content. It does not reproduce or change consequential state.
Four Questions¶
These questions extend, in spirit, the Law Commission of England and Wales's recognition that some digital assets may exist beyond the traditional personal-property categories of things in possession and things in action. The Property (Digital Assets etc) Act 2025 now confirms that a digital or electronic thing is not excluded from personal-property rights merely because it is neither. In that spirit, OpenETR uses digital things as a broader protocol description, not as the legal name of the third category or a claim that every Digital Artifact is property.
What is the digital thing? The Digital Artifact, identified by a digest.
What happened concerning it? The Digital Controllable Record, containing evidence signed by actors.
What follows? Consequential State, derived according to defined rules.
What has the digital thing become? A Digital Original, the thing with consequential state.
The final question sits outside the protocol: so what? People, institutions, systems, and law recognize consequential state and determine what effect it receives.
Consequential state should be derived from end-verifiable evidence according to defined rules, not merely asserted by applications, databases or blockchains.
Each proof proves only what it proves.
Three Primitives And One Core Concept¶
Digital Artifact¶
The Digital Artifact is persistent digital content with a unique content identity, normally established by a cryptographic digest. It may be a document, image, credential, record, data structure, or other identifiable content. It is the subject of consequential actions.
Digital Controllable Record¶
The Digital Controllable Record (DCR) is a single end-verifiable record or a graph of related end-verifiable records containing evidence of consequential actions concerning a Digital Artifact. It may contain an Anchor and later records such as transfer, encumbrance, discharge, relinquishment, attestation, redemption, or termination.
The DCR is not the file. It is the portable record of consequential statements made about the file.
Consequential State¶
Consequential State is state that follows from consequential actions according to an identified ruleset. It is not another record or container and it is not “the validation.” Validation asks whether evidence is authentic, intact, authorized, and acceptable under the protocol. Consequential State is what follows when the relevant evidence is evaluated according to the rules.
For example, the resulting state may identify a controller, show that an artifact is active or encumbered, identify a secured party, or show that its lifecycle has ended.
Cryptography validates the evidence. An identified ruleset determines what follows.
Digital Original¶
A Digital Original is a Digital Artifact for which consequential state has been established through a Digital Controllable Record.
Originality does not belong to one physical copy. Identical copies represent the same artifact and can be checked against the same DCR and state.
A copy can reproduce the content. It cannot independently reproduce the consequential state.
The complete path is:
Digital Artifact -> Digital Controllable Record -> Consequential State -> Digital Original
Consequential State -> Recognition -> Effect
A Simple Example¶
A warehouse issues a PDF receipt for stored grain. Its fingerprint identifies the Digital Artifact. The warehouse signs an Anchor Event, and a later signed record transfers control to a buyer. Those records form the candidate DCR. Cryptography validates the evidence, and a transferable-record ruleset derives the candidate current-controller state.
Emailing another copy of the PDF does not transfer the receipt. Editing the PDF creates a different artifact. Changing its consequential state requires valid signed evidence.
A bank, registry, court, or trading partner then decides whether to recognize the signers and resulting state. OpenETR preserves the evidence, and the selected ruleset derives Consequential State; it does not claim that cryptography alone creates ownership or other legal or commercial effect.
Relationship To Mainstay¶
OpenETR is an adjacent member of the Mainstay product family, not a service in the default Mainstay runtime bundle. Mainstay applications can preserve and present artifacts and evidence; OpenETR defines how consequential state is derived from qualifying evidence. Operators, institutions, communities, and recognition frameworks remain responsible for policy and effect.
The shared emphasis is practical continuity with clear boundaries: records and evidence remain understandable across applications and changing conditions, while cooperation does not require every participant to surrender local stewardship.
Start Here¶
| Area | Purpose |
|---|---|
| OpenETR Axioms | Start with the ten foundational propositions and five maxims that define the OpenETR model and its boundaries. |
| The Core Model | Read how Digital Artifacts, DCR evidence, identified rulesets, Consequential State, and Digital Originals fit together. |
| Digital Originality | Explore consequential state and the model through detailed examples. |
| OpenETR Overview | Continue into the architecture, wire format, implementation surfaces, and recognition boundary. |
| OpenETR Roadmap | See the prioritized work for verifier results, retrieval coverage, associated evidence, recognition adapters, and domain pilots. |
| Warehouse Receipts | Work with warehouse receipt documents using MLWR-style terminology over OpenETR DCR evidence and state transition rules. |
| Product Passports | Start modelling Product Passport evidence records for product data, compliance evidence, and lifecycle attestations. |
| Health Records | Placeholder for future health-record Evidence Graph workflows, with privacy and consent concerns called out early. |
| Apostille Documents | Placeholder for future apostille and legalization document verification workflows. |
Live App¶
| Page | Purpose |
|---|---|
https://openetr.org/ |
OpenETR Control Desk app with query-only upload flow |
https://openetr.org/warehouse-receipts |
Warehouse Receipts workspace |
https://openetr.org/digital-product-passports |
Product Passports workspace |
https://openetr.org/openetr |
Advanced OpenETR console |
https://openetr.org/docs |
FastAPI-generated API docs |
Core Vocabulary¶
| Term | Meaning |
|---|---|
| Digital Artifact | Persistent digital content with a unique content identity, normally established by a cryptographic digest. |
| Digital Controllable Record | A single end-verifiable record or graph of related end-verifiable records containing evidence of consequential actions concerning a Digital Artifact. |
| Consequential State | State that follows from consequential actions according to an identified ruleset. |
| Evidence Record | A signed OpenETR lifecycle record within a DCR. |
| Linked Evidence Record | A signed record that associates another document, artifact, or evidence item with a Digital Artifact without necessarily transferring control. |
| Control Graph | The portion of a DCR Evidence Graph to which a transferable-record ruleset assigns control consequences. |
| Evidence Graph | The broader DCR graph, including the Anchor Event, Publisher Notices, ruleset-specific actions, and linked-evidence records. |
| Digital Original | A Digital Artifact for which consequential state has been established through a Digital Controllable Record. |
| Domain Workspace | A user-facing adapter that speaks domain language while using OpenETR DCR evidence and an identified domain ruleset underneath. |
| Recognition Layer | Law, registry policy, institutional rules, verifier policy, or contracts that decide whether consequential state is accepted and what effect it receives. |
Core Thesis¶
OpenETR does not try to become each domain's system of record, registry, legal authority, or compliance engine.
Instead, it preserves durable evidence from which consequential state can be derived:
real-world object, product, document, or record
-> canonical file or data artifact
-> Digital Artifact identified by digest
-> Digital Controllable Record containing an Anchor Event and later records
-> evidence is validated and an identified ruleset derives Consequential State
-> Digital Original
-> durable query link and QR code
-> verifier / registry / authority / relying party decides effect
The artifact content can stay with the operator, manufacturer, registry, platform, or storage service. OpenETR preserves its cryptographic identity and portable DCR evidence.
OpenETR does not decide universal effect. It preserves durable signed evidence and derives Consequential State according to an identified ruleset. Recognition outside the protocol determines what legal, institutional, commercial, or operational effect that state receives.
The same boundary applies to execution. A signed record is attributable evidence of a statement concerning the Digital Artifact; it is not automatic proof that an outside operation was authorized or performed. An integrating system can place OpenETR verification before a protected signing or execution operation, refuse an ineligible action, and publish evidence of the outcome. OpenETR makes that evidence portable and the resulting state independently derivable; the integrating system controls the operation within its own scope.
signing commits evidence
an identified ruleset derives Consequential State
integrating systems control operations
recognition frameworks determine effect
Documentation Tracks¶
| Track | Audience | Starting Point |
|---|---|---|
| OpenETR | Implementers, protocol reviewers, system integrators | OpenETR Overview |
| Warehouse Receipts | Warehouse operators, MLWR reviewers, domain integrators | Warehouse Receipts Overview |
| Product Passports | Product, compliance, lifecycle, and supply-chain integrators | Product Passports Overview |
| Health Records | Health data, consent, privacy, and clinical workflow integrators | Health Records Overview |
| Apostille Documents | Notarial, legalization, authority, and document verification integrators | Apostille Documents Overview |
Source Specifications¶
Key source documents: