# UCAN and Ocap Model

**URL:** <https://community.spritely.institute/t/ucan-and-ocap-model/787>\
**Category:** Spritely Goblins\
**Created:** [December 15, 2025, 7:07am UTC](https://community.spritely.institute/t/ucan-and-ocap-model/787 "2025-12-15T07:07:06Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![liltechdude](https://avatars.discourse-cdn.com/v4/letter/l/8c91f0/32.png) [@liltechdude](https://community.spritely.institute/u/liltechdude)\
**Post date:** [December 15, 2025, 7:07am UTC](https://community.spritely.institute/t/ucan-and-ocap-model/787/1 "2025-12-15T07:07:06Z")

</div>

What are you thinking about UCAN?

> **[User Controlled Authorization Network (UCAN) Specification](https://ucan.xyz/specification/)**
>
> User-Controlled Authorization Network (UCAN) is a \[trustless\], secure, \[local-first\], user-originated, distributed authorization scheme. This document provides ...

Based on what I have read from [Composing capability security and conflict-free replicated data types — Spritely Institute](https://spritely.institute/news/composing-capability-security-and-conflict-free-replicated-data-types.html)

> This is where **authorization capabilities** (zcaps) come in. A zcap is a signed certificate that describes what actions a controller of that certificate may perform. Like ocaps, zcaps support _delegation_ which is represented as a chain of signed certificates. A crucial property of a delegated zcap is that it cannot expand privilege, only reduce it. Certificate chains need to bottom out somewhere, so we need to decide upon a root signer. In Brassica Chat, the initiator of the chat room (Alice in our example scenario) is considered to be the root signer for all zcaps used in the chat room. This is just a convention, though, and a user could decide to place their trust in a different root signer.

UCAN should be cool thing.

---

<div class="post-metadata">

**Author:** ![liltechdude](https://avatars.discourse-cdn.com/v4/letter/l/8c91f0/32.png) [@liltechdude](https://community.spritely.institute/u/liltechdude)\
**Post date:** [December 15, 2025, 3:54pm UTC](https://community.spritely.institute/t/ucan-and-ocap-model/787/2 "2025-12-15T15:54:01Z")

</div>

omg [User Controlled Authorization Network (UCAN) Specification | UCAN](https://ucan.xyz/specification/)

> Many thanks to [Christine Lemmer-Webber](https://github.com/cwebber) for her handwritten(!) feedback on the design of UCAN, spearheading the [OCapN](https://github.com/ocapn/ocapn) initiative, and her related work on [ZCAP-LD](https://w3c-ccg.github.io/zcap-spec/).

---

<div class="post-metadata">

**Author:** ![dthompson](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.spritely.institute/dthompson/32/95_2.png) [@dthompson](https://community.spritely.institute/u/dthompson)\
**Post date:** [December 15, 2025, 5:00pm UTC](https://community.spritely.institute/t/ucan-and-ocap-model/787/3 "2025-12-15T17:00:02Z")

</div>

Haha well I think you’ve answered your own question before I could. I’m not familiar with the specifics of how UCAN works, but Christine knows a thing or two. 🙂
