Skip to main content

Offline verifier for Primust VPECs (Ed25519 + post-quantum ML-DSA-65). Free forever. No account required.

Project description

primust-verify

Free forever. No account required. Apache-2.0.

Offline verifier for Primust VPECs (Verifiable Process Execution Credentials).

pip install primust-verify

Verify a VPEC

from primust_verify import verify

result = verify(vpec_json)
assert result.valid

Or from the command line:

primust-verify vpec.json

Exit codes:

  • 0 — valid
  • 1 — invalid (signature mismatch, tampered, or failed checks)
  • 2 — system error

Zero-network verification

Use --trust-root to verify without any network calls:

primust-verify vpec.json --trust-root ./primust-pubkey.pem

This fetches no external resources. The public key PEM is the only trust anchor needed.

Download the Primust public key from: https://primust.com/.well-known/primust-pubkey.pem

Deferred math-tier proofs (PACs)

A governance run's ZK (Noir/UltraHonk) proof is computed asynchronously and isn't ready at the instant the VPEC is sealed, so the sealed envelope marks that proof artifact unresolved_at_seal. The envelope alone therefore can't self-prove the math-tier claim — by default the verifier reports it as unresolved and tells you to consult the live API.

To verify the math tier fully offline, supply the PAC (Proof Attestation Certificate) — a separately-signed certificate that carries the completed proof bundle and binds it to the VPEC:

# Fetch the PAC(s) for a VPEC (public, no auth):
curl https://api.primust.com/api/v1/vpecs/<vpec_id>/pacs > pacs.json

primust-verify vpec.json --trust-root ./primust-pubkey.pem --pacs pacs.json

The verifier resolves a deferred proof at one of two trust levels:

  • trustless — the ZK proof is re-verified locally against the circuit's pinned verification key and its public input is bound to the VPEC's record root. Zero trust in Primust. Requires the Barretenberg bb CLI (see below).
  • attested — only the PAC's issuer signature is checked (e.g. when bb isn't installed). Same trust basis as the live-API consult, but offline. The verifier emits an SI-13 disclosure noting the proof was not independently re-verified.

Pass --require-reverified-proofs to refuse the attested fallback — a deferred proof then only clears if it is genuinely re-verified (trustless).

Enabling trustless re-verification (bb)

Trustless re-verification shells out to the Barretenberg bb CLI. Install it with bbup (installs to ~/.bb/bb, which the verifier finds automatically) or point the verifier at a specific binary with PRIMUST_BB=/path/to/bb. Without bb, the verifier degrades to the attested path (or fails the artifact under --require-reverified-proofs).

You don't need a Primust account to verify a VPEC

This tool is free, open source (Apache-2.0), and works offline. Anyone can verify a VPEC — regulators, auditors, counterparties — without creating an account or contacting Primust.

Verification paths

  • primust-verify CLI — canonical local/offline verifier
  • Evidence Pack verify.html — bundled local browser verifier
  • verify.primust.com — hosted convenience verifier

The hosted site is useful for shared links and quick review, but it is not the canonical zero-network / trust-minimized path.

Options

Flag Description
--production Reject VPECs issued with test keys
--skip-network Skip Rekor transparency log check
--trust-root <path> Use a local PEM file as trust anchor (zero-network mode)
--pacs <path> Supply Proof Attestation Certificate(s) to resolve deferred math-tier proofs offline
--require-reverified-proofs Refuse the attested fallback: a deferred proof clears only if re-verified (trustless, needs bb)
--json Output structured JSON instead of human-readable text

primust-rely — evaluate a Clearance Requirement (relying-party side)

This package also ships primust-rely: the relying-party evaluator that takes YOUR declarative Clearance Requirement (YAML or JSON) and a sealed Action Clearance and answers pass/fail — offline, fail-closed. Primust never enforces: you evaluate, you decide, and the output is your own auditable Reliance Decision record (requirement digest, clearance digest, per-check results, verdict, reasons).

primust-rely merge-approval.yaml clearance.json          # exit 0 = satisfied
primust-rely refund-release.yaml clearance.json --json   # print the Reliance Decision record

A minimal requirement (requirement_version: 1; full JSON Schema ships as primust_verify/clearance_requirement.schema.json, examples under examples/clearance-requirements/):

requirement_version: 1
requirement_id: merge-approval
min_evidence_tier: operator_confirmed   # canonical Source-axis ordering
allowed_results: [cleared]
require_finality: true                  # settled/final on every record
forbidden_reason_codes: [no_witness]
require_no_unresolved_gaps: true
max_age: 24h
issuer:
  name: Primust
  key_ids: [kid_api, kid_api_eu]

Fail-closed guarantees: an unverifiable artifact (bad seal, unknown issuer, tampered bytes) never satisfies any requirement; unknown requirement keys are hard errors (no silent ignores); a clearance missing a field a requirement needs fails that check explicitly — never pass-by-absence.

Requirements

  • Python 3.11+
  • Optional: Barretenberg bb CLI — only for trustless re-verification of deferred math-tier proofs (see "Deferred math-tier proofs" above). Not needed for signature, schema, surface, gap, or attested-PAC verification.

License

Apache-2.0


Docs | Verify online | Primust

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

primust_verify-1.12.0.tar.gz (298.8 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

primust_verify-1.12.0-py3-none-any.whl (178.7 kB view details)

Uploaded Python 3

File details

Details for the file primust_verify-1.12.0.tar.gz.

File metadata

  • Download URL: primust_verify-1.12.0.tar.gz
  • Upload date:
  • Size: 298.8 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.12.13

File hashes

Hashes for primust_verify-1.12.0.tar.gz
Algorithm Hash digest
SHA256 32e23ae68730ac906aa58dd75b9322996139e751fcadf8892b89a14fa16dcc90
MD5 fa8fbcafebf933daa48af4d7fe85bb2f
BLAKE2b-256 c1d7537c3d281fa2238bf564332f0cbb77f1d1b1007f0344bca7c7ea5232c4cf

See more details on using hashes here.

File details

Details for the file primust_verify-1.12.0-py3-none-any.whl.

File metadata

File hashes

Hashes for primust_verify-1.12.0-py3-none-any.whl
Algorithm Hash digest
SHA256 cd29fac98c1bbc9d7c87950f9b8326ac14bfe90e3b46386d1d7f0529ae500857
MD5 abc6bb746faa62688b4dd7c93b0da638
BLAKE2b-256 20b611742e572b31f8c377ed3a2b7f9f4c05eb3f68e9c4a74a5b002ca0188c50

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page