Attestation verifier
Paste the drill records of a surface and the signing keys, and this page checks what
safegrd history checks: the first record starts at genesis, every record names the
certificate hash of the one before it, and every signature verifies under the key the record
names. It runs in this browser and sends nothing anywhere, so an auditor can check a chain
without installing the CLI and without trusting this site. The page is one HTML file and one
script, which you can save and keep.
An Evidence Pack carries its records and its keys; paste it alone.
One hex key pins that key for every record, whatever key id the record names.
What is checked
| Check | Fails when |
|---|---|
| Genesis | The oldest record's prev_hash is not genesis. |
| Chain | A record's prev_hash is not the certificate_hash of the record before it, by started_at: a record was changed, removed or inserted. |
| Signature | The Ed25519 signature does not verify over the record's signed fields (verification_id, snapshot_id, node_id, surface_type, status, tables_restored, rows_restored, duration_ms, certificate_hash, prev_hash, joined with |) under the key it names. |
| Retired key | A record under a retired key was completed after the key retired, or follows a record signed under a newer key. |
| Unknown key | A record names a signing_key_id the key set does not publish. A record with no signature is counted and said, never passed as verified. |
Ed25519 verification uses the browser's WebCrypto. Chrome 113, Firefox 130 and Safari 17 and
newer have it. The page does not recompute certificate_hash, as the CLI does not: the
hash is what the chain links, and the signature is what binds it to the server's key.
The same check from a terminal: safegrd history --file records.json --keys-file keys.json
(Attestation chain).