touchstone-verify
Independently verify a Touchstone disclosure — in pure Python, with zero dependencies. Read it before you trust it: it's a small, self-contained file.
A disclosure is a tamper-evident slice of an agent's action log. This package re-derives, with no trust in Touchstone, that the slice is intact (entry hashes recompute), attributed (the subject's Ed25519 signature holds, epoch-aware across key rotation), and ordered (hash-chained, with checkpoints that are append-only, server-signed, and witness-co-signed). It also checks selective-disclosure field proofs and reports the external anchors. It proves tampering by anyone who is not Touchstone — it does not prove completeness, and says so.
It agrees byte-for-byte with the other two Touchstone verifiers (verify.php, verifier.js):
all three are tested against the same conformance corpus.
Install
pip install touchstone-verify
Use
Command line — pass a file, a URL, or a disclosure token:
touchstone-verify https://touchstone.cv/d/833cd4ca23fbb940dd71843ca47a807e
touchstone-verify ./bundle.json
touchstone-verify 833cd4ca23fbb940dd71843ca47a807e # fetches from touchstone.cv
Exit code 0 = verified, 1 = a load-bearing check failed, 2 = couldn't load.
Library:
from touchstone_verify import verify_disclosure
import json, urllib.request
bundle = json.load(urllib.request.urlopen("https://touchstone.cv/d/<token>"))
result = verify_disclosure(bundle)
print(result["ok"]) # True / False
for e in result["entries"]:
for c in e["checks"]:
print(c["ok"], c["msg"])
Grade a receipt's columns by k
from touchstone_verify import grade_columns, find_columns
import json, urllib.request
doc = json.load(urllib.request.urlopen("https://touchstone.cv/columns/<recorder>/<seq>"))
cols, digest = find_columns(doc)
r = grade_columns(cols, digest)
print(r["coherent"], r["min_k"]) # True / cheapest falsehood path (min k across load-bearing columns)
k is the minimum number of independent parties who must collude before a column can be false,
computed from the evidence (never the declared grade): k=0 re-derivable, k = 1 + distinct-control witnesses (co-sigs collapse on a shared key or a receipt-carried controller binding, so it's an
upper bound), k=1 testimony. Declaring more strength than the evidence supports fails closed.
Mint a receipt (the producer half)
Verification is dependency-free; minting needs an Ed25519 signer, so it lives behind an extra:
pip install "touchstone-verify[record]"
from touchstone_verify import Recorder
# reads TOUCHSTONE_RECORDER / _API_KEY / _SUBJECT / _SIGNING_KEY (or _KEY_FILE={"seed_b64":…})
r = Recorder.from_env()
rc = r.record({"kind": "invoice", "amount": 100}, event_type="invoice")
print(rc.seq, rc.entry_hash) # the server's assignment; local_entry_hash_ok() confirms it
rc.wait_for_anchor() # blocks until the next checkpoint sweeps this seq
print(rc.verify()) # payload_hash → entry_hash → checkpoint root (ok: True)
Your key never leaves the process, and the payload is canonicalized locally using the same
jcs / entry-hash code this package verifies with — one crypto core, no drift — so a malicious server
cannot make you sign a different commitment than you intended. Receipt.verify() walks the receipt to
its Bitcoin-anchored checkpoint (finish with ots verify on your own node). For a fully trustless
recorder whose every entry is inclusion-provable, provision it with app:provision-recorder --inclusion-public.
What it checks
- Integrity — every
entry_hashrecomputes from its fields, including the beacon fold: abeacon_bindingrecorder's entries carryserver_beacon = {chain, round, randomness}as a finalbeacon:<chain>:<round>:<randomness>line of the preimage (a checkable not-before). Absent → the exact legacy 7-field preimage, so older entries verify unchanged. - Attribution — the subject signature verifies over the canonical signed content; genesis
proof-of-possession;
key_rotationnew-key PoP; counterparty co-signatures. - Ordering —
prev_hashchain linkage; Merkle inclusion in the cited checkpoint. - Checkpoints — server signature over each Merkle root; append-only linkage between consecutive checkpoints; independent witness co-signatures.
- Selective disclosure — each revealed field proves Merkle inclusion in
payload_hash; withheld fields never appear in the bundle.
For split-view / Bitcoin-anchor cross-checking across independent relays, see the companion
gossip_check.py at https://touchstone.cv/gossip_check.py.
License
Metadata
Release files for touchstone-verify 0.5.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| touchstone_verify-0.5.0.tar.gz | 26.5 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| touchstone_verify-0.5.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 50.1 kB
Release files / touchstone_verify-0.5.0.tar.gz
| Download URL | touchstone_verify-0.5.0.tar.gz |
|---|---|
| Size | 26.5 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
085f00bcf0defcbeaf520394995bee55690ac39a80f916b2d2f63e63d50f51cd
|
|
BLAKE2b-256 checksum How to use checksums |
ec5cc0ff5ea5410d11cff6c4afefb0aacbf679b1185c92ed094922fe1de93fb3
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 12, 2026.
Transparency logRelease files / touchstone_verify-0.5.0-py3-none-any.whl
| Download URL | touchstone_verify-0.5.0-py3-none-any.whl |
|---|---|
| Size | 23.7 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
5f822833c9ee3d7c16179628891893b53c65d21d25994a2a502e62b5a5d9519f
|
|
BLAKE2b-256 checksum How to use checksums |
d4d8a2008eb26d4bd6903cc2612f6c9204fcbd9e8356a27a45bcd1631c7992ec
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 12, 2026.
Transparency log