Developers

Two verifiers, written separately, check the same bundle offline.

JSON Schemas define the canonical objects. The verifiers, one in Python and one in TypeScript, check a bundle against its registry entry and the trust registry with no network access. Both run over a shared conformance corpus and are compared on structure, integrity and the schema contract.

Rules

What every implementation must get right.

  • A registry entry carries no evidence content. Hashes and identifiers are its only link to the bundle.

  • A verification report lists the levels it checked. A report that stops at L2 has not failed L3; that check was not requested.

  • Without a pinned trust root, a verifier reports REVIEW at best, never PASS.

Repositories

One repository per component.

Each carries a release label; the implementation status page lists them. None is on a package registry yet, and there is no hosted API yet.

Before integrating

An integration would rest on closed schemas and offline checks.

Contract. Each object is defined field by field. The schemas and the specification define the bundle, the receipt, the summaries, the registry entry and the trust registry. The schemas fix fields and types; the rule that ties a status to its reason codes is in the specification.
Verification. Offline verification stops at issuer authorization (L3). Before it, the verifiers check bundle structure (L0), file and manifest integrity (L1) and the link to the registry entry (L2). Transparency-log inclusion (L4), anchor finality (L5) and the issuer's legal identity are not checked.

Engineering

Share the first workflow you would integrate.

Tell us which policy it applies and what evidence it needs, and name any optional registry-entry fields it would use.