Skip to content

Offline evidence verifier

This page runs the same verifier as the brutor-verify command-line tool, compiled to WebAssembly. Drop or paste an evidence bundle, an action record with its statement, a tree head or a witness receipt, and optionally a key document to pin. Nothing leaves your browser: the page makes no network requests (its content security policy forbids them), sends no analytics, and also works saved to disk and opened from file://.

Open the verifier in its own tab — or use it below. It runs entirely in your browser.

The report lists each check that ran with its literal outcome (ok, failed, skipped) and every finding with its stable code and severity. Only error findings make a result fail. The report never says more than its checks: it does not say “verified”, and it never says anything is compliant — see what the semantic rules check.

The same checks, for scripts and CI. Build it from brutor-gateway-core:

Terminal window
cargo build -p brutor-verify --release
./target/release/brutor-verify bundle bundle.json --keys brutor-evidence-keys.json --json

Release builds are published per platform with their SHA-256 in the release notes. Exit status 0 means no error finding, 1 at least one error finding, 2 a usage or I/O error. Full usage: verifying with brutor-verify.

Terminal window
# in brutor-gateway-core — needs the wasm32-unknown-unknown target and a
# wasm-bindgen-cli matching the wasm-bindgen crate version
crates/brutor-verify/build-web.sh # → crates/brutor-verify/dist/

dist/ holds index.html, brutor_verify.js, brutor_verify_bg.wasm, brutor_verify_wasm.js (the same wasm as base64, for file://) and SHA256SUMS. The docs build copies it unmodified into /tools/verify/app/ with npm run sync:verifier (run automatically before npm run dev and npm run build; set BRUTOR_VERIFY_DIST to use another directory) and checks every file against SHA256SUMS.