Skip to main content
New

1 minute read

Trooth command-line tool 0.9.0: a public log of every signed reading

Every witness statement Trooth publishes, and every correction it issues, now goes into one public log that can only grow. trooth verify checks each statement's place in it, and anyone can check that the log was never rewritten.

What changed

The log follows the tree Certificate Transparency uses (RFC 9162) and the checkpoint and tile formats of C2SP, so existing tools can read it. Its checkpoints are signed by a key used for nothing else, and trooth 0.9.0 carries that key. A reading that was never published is never logged. When a reading was wrong, Trooth signs a correction and logs it; the original stays in the log, and trooth verify reports it as superseded, exit code 10. trooth log monitor checks a consistency proof from the last checkpoint you saw, and the trooth-cli repository runs it on a schedule, in public. The Python and Go libraries check receipts and corrections too. How the keys are made, held, rotated and revoked is written down in docs/KEY-CEREMONY.md.

Why it changed

A signature shows Trooth signed a reading. It cannot show that Trooth did not sign a different one for someone else, or quietly drop one later. A public log that only grows, with proofs anyone can check, can.

Who is affected

  • Affected: Anyone who relies on a Trooth reading, and anyone who wants to watch that Trooth does not change its history.
  • Availability: npm, as trooth 0.9.0; the log at api.trooth.co/scan/log/v1. No account.
  • Release stage: Available.
  • Areas: CLI, API.

What to do

No action required. Nothing is required. Statements published before today enter the log at their next reading.

Versions and migration

  • trooth: 0.9.0

Dates

  • Announced: October 6, 2026, the day this entry was written. Entries are never backdated.
  • Released: October 6, 2026.

What this does not fix

The log has one operator and no independent co-signers yet, so monitors can detect a rewritten history but cannot prevent one. Its key is held in software as an encrypted secret, not yet in a hardware module.

Read more

Follow what changes at Trooth

Every entry by email, or a feed narrowed to one area or to the changes that need you to act.

Product updates by email

Occasional notes when something on this page changes. You get one confirmation email when you subscribe, every email carries an unsubscribe link, and the address is never sold or shared.

RSSCLI onlyNeeds action

View as agent