Skip to main content
New

1 minute read

Trooth command-line tool 0.8.0: bundles, statement v3, schemas and libraries

trooth verify can keep everything it checked in one file and check that file later with no network. It also checks statement v3, and the same checks now run as a library in JavaScript, Python and Go.

What changed

--save-bundle writes the statement, the evidence manifest, the key list with the time it was read, and the exact mapping bytes to one file; --bundle checks that file and sends nothing. Every result names the statement by the SHA-256 of its signed bytes. Statement v3 is signed in the canonical form RFC 8785 defines, with the subject named by a stable id and the signing key named inside the signed bytes; Trooth keeps signing v2 until every surface that shows a statement checks v3. Published schemas describe every field of the statement, the key list, the manifest, the bundle and the result, and of the company record itself, and are served under trooth.co/schemas. The Python and Go libraries pass the same 27 test cases and 7 bundles as the command.

Why it changed

A check you cannot repeat later is hard to rely on, and a checker that exists only as a command forces every integrator to rewrite it. One portable file and one set of rules in three languages fix both.

Who is affected

  • Affected: Anyone who keeps a record of what they checked, and developers who check Trooth readings inside their own software.
  • Availability: npm, as trooth 0.8.0; the Python and Go code in the trooth-cli repository. No account.
  • Release stage: Available.
  • Areas: CLI, API.

What to do

No action required. Nothing is required. Statements Trooth already published check exactly as before.

Versions and migration

  • trooth: 0.8.0

Dates

  • Announced: October 6, 2026, the day this entry was written. Entries are never backdated.
  • Released: October 6, 2026.

What this does not fix

A bundle is only as fresh as the key list inside it: a key compromise announced after it was saved is not in it. Witness statements are not yet in a public transparency log, and the signed time is asserted by Trooth.

Read more

Follow what changes at Trooth

Every entry by email, or a feed narrowed to one area or to the changes that need you to act.

Product updates by email

Occasional notes when something on this page changes. You get one confirmation email when you subscribe, every email carries an unsubscribe link, and the address is never sold or shared.

RSSCLI onlyNeeds action

View as agent