Skip to main content
New

1 minute read

Trooth command-line tool 0.7.0: check a signed reading yourself

trooth verify checks a record's signed witness statement on your own machine: the signature, the key's status, the domain it was signed for, the counts, and the check mapping and evidence manifest digests.

What changed

The rules are written in docs/VERIFY.md in the trooth-cli repository, with 18 test cases, valid and deliberately broken, that any other checker must agree on. With saved files and --offline the command sends nothing. New exit codes: 8 when the signature or key is not trusted, 9 when the domain, a digest or the counts do not match. The release was published from GitHub with npm provenance, through npm trusted publishing, so no npm token is stored anywhere.

Why it changed

Until now the CLI printed signature_checked: false and pointed elsewhere for the check. A reader should be able to check the one object Trooth signs with a single command and written rules.

Who is affected

  • Affected: Anyone who relies on a Trooth reading and wants to check it without trusting Trooth's own summary, including agents and pipelines that call the command-line interface (CLI).
  • Availability: npm, as trooth 0.7.0. No account.
  • Release stage: Available.
  • Areas: CLI.

What to do

No action required. Nothing is required. Run npx trooth verify with a domain to try it; trooth check is unchanged apart from its closing line.

Versions and migration

  • trooth: 0.7.0

Dates

  • Announced: October 6, 2026, the day this entry was written. Entries are never backdated.
  • Released: October 6, 2026.

What this does not fix

A checked reading shows Trooth's key signed that reading for that domain. Witness statements are not yet in a public transparency log, and the signed time is asserted by Trooth, not independently established.

Read more

Follow what changes at Trooth

Every entry by email, or a feed narrowed to one area or to the changes that need you to act.

Product updates by email

Occasional notes when something on this page changes. You get one confirmation email when you subscribe, every email carries an unsubscribe link, and the address is never sold or shared.

RSSCLI onlyNeeds action

View as agent