Federation model

Ishtaria worlds are run independently. Two worlds can be linked when their operators agree.

Separate planets, linked by portals

Each world has its own planet. Worlds are connected by portals: crossing one is a discrete event, not a seamless border. This avoids the hardest problems of shared territory – real-time synchronisation across servers, deciding authority over objects on a border, and behaviour when one side goes down. See 0001 – Separate planets linked by portals.

Portals as gameplay

  • An agreement between operators permits a portal.

  • Players must build it: materials, energy, technology.

  • Each end is placed by its own world’s operator.

  • State: building → open → congested / closed; parameters are capacity per hour, cargo limit and optional opening windows.

Trust

A world can never assume that a peer runs unmodified software. Therefore:

  • every message between worlds is signed with the server’s Ed25519 key;

  • everything a peer sends passes the local import policy;

  • every item carries provenance – the world that minted it vouches for it;

  • every agreement defines what happens on termination.

Identity

Players are @localpart:home.server (as in Matrix). The home server keeps the master record. Each world runs its own identity provider (e.g. Keycloak over OIDC); there is no central account system.

Discovery

A world publishes its signing key and endpoints at https://<server>/.well-known/ishtaria/server.json. Keys are additionally verified out of band by operators when they sign an agreement.

Moderation

Bans are local. Worlds may share block lists, Fediverse-style. An agreement may state content rules (PvP, age rating).

Chat

Cross-world chat, guilds and groups use Matrix; Ishtaria does not reimplement messaging.