trooth verify checks a record's signed witness statement on your own machine: the signature, the key's status, the domain it was signed for, the counts, and the check mapping and evidence manifest digests.
What changed
The rules are written in docs/VERIFY.md in the trooth-cli repository, with 18 test cases, valid and deliberately broken, that any other checker must agree on. With saved files and --offline the command sends nothing. New exit codes: 8 when the signature or key is not trusted, 9 when the domain, a digest or the counts do not match. The release was published from GitHub with npm provenance, through npm trusted publishing, so no npm token is stored anywhere.
Why it changed
Until now the CLI printed signature_checked: false and pointed elsewhere for the check. A reader should be able to check the one object Trooth signs with a single command and written rules.
Who is affected
- Affected: Anyone who relies on a Trooth reading and wants to check it without trusting Trooth's own summary, including agents and pipelines that call the command-line interface (CLI).
- Availability: npm, as trooth 0.7.0. No account.
- Release stage: Available.
- Areas: CLI.
What to do
No action required. Nothing is required. Run npx trooth verify with a domain to try it; trooth check is unchanged apart from its closing line.
Versions and migration
- trooth:
0.7.0
Dates
- Announced: October 6, 2026, the day this entry was written. Entries are never backdated.
- Released: October 6, 2026.
What this does not fix
A checked reading shows Trooth's key signed that reading for that domain. Witness statements are not yet in a public transparency log, and the signed time is asserted by Trooth, not independently established.