Open-Source

Warrant Verifier

Verify any Aether warrant independently. No trust in Aether required — just math.

1. Get the Public Key

Look up any Ed25519-sealed warrant at /warrant-proof — the public key used to sign it is returned with the proof.

2. Reconstruct Payload

Concatenate answer_version_id, conclusion, and premises with | and ;; delimiters.

3. Verify Signature

Check the Ed25519 signature against the public key. If it matches, the warrant is authentic.

Signature Specification

AlgorithmEd25519 (EdDSA over Curve25519) + HMAC-SHA256 fallback
Payloadanswer_version_id | conclusion | premises.join(";;")
EncodingBase64 (signature), UTF-8 (payload)
Source HashSHA-256 of fetched source content (first N bytes), stored per-snapshot

Python

verify_warrant.py
from cryptography.hazmat.primitives import hashes, serialization
from cryptography.hazmat.primitives.asymmetric import ed25519
from cryptography.hazmat.primitives import hmac
import json, base64

def verify_warrant(warrant, public_key_pem, hmac_key):
    """Verify an Aether warrant signature."""
    # 1. Reconstruct the signed payload
    payload = "|".join([
        warrant["answer_version_id"],
        warrant["conclusion"],
        ";;".join(warrant.get("premises", [])),
    ])

    # 2. Verify Ed25519 signature
    public_key = serialization.load_pem_public_key(public_key_pem)
    sig = base64.b64decode(warrant["signed_hash"])
    try:
        public_key.verify(sig, payload.encode())
    except Exception:
        return False, "Ed25519 signature mismatch"

    # 3. Verify source content hashes (optional)
    for snap in warrant.get("source_snapshots", []):
        # Re-fetch the URL and compare SHA-256
        # stored_hash = snap["content_hash"]
        pass

    return True, "Warrant verified — provenance confirmed"

JavaScript / Node.js

verify.js
import { createVerify, createHmac } from 'crypto';

export function verifyWarrant(warrant, publicKeyPem, hmacKey) {
  // 1. Reconstruct the signed payload
  const payload = [
    warrant.answer_version_id,
    warrant.conclusion,
    (warrant.premises || []).join(';;'),
  ].join('|');

  // 2. Verify Ed25519 signature
  const verify = createVerify('sha256');
  verify.update(payload);
  verify.end();

  const isValid = verify.verify(
    publicKeyPem,
    Buffer.from(warrant.signed_hash, 'base64'),
    'ed25519'
  );

  if (!isValid) {
    return { valid: false, reason: 'Ed25519 signature mismatch' };
  }

  return { valid: true, reason: 'Warrant verified — provenance confirmed' };
}

cURL (Hosted API)

bash
curl -X POST https://api.aether.ai/v1/warrants/verify \
  -H "Content-Type: application/json" \
  -d '{
    "warrant_id": "warr_abc123",
    "public_key": "-----BEGIN PUBLIC KEY-----\n...\n-----END PUBLIC KEY-----"
  }'

Get the Public Key

Aether's Ed25519 public key isn't a single value printed on this page — it's returned live, alongside the full cryptographic proof, for every Ed25519-sealed warrant. Look up any warrant id or sf2x_ hash to get the exact public key used to sign it, and verify the signature yourself.

Verify a live warrant now