---
title: "Trooth command-line tool 0.11.0: witnesses for the log, and a signed public record: Trooth changelog - Trooth"
description: "Trooth's log now asks independent witnesses to cosign each checkpoint, every entry has a receipt in the COSE format, and each public record reading is signed and entered in the log. The public record is shown on Trust Profiles."
canonical_url: "https://trooth.co/changelog/2026-10-07-cli-0-11-0-witnesses"
markdown_url: "https://trooth.co/changelog/2026-10-07-cli-0-11-0-witnesses.md"
generated_from: "the rendered page, converted to Markdown when this was requested"
agent_index: "https://trooth.co/llms.txt"
---

[Back to changelog](https://trooth.co/changelog)

New

October 7, 20262 minute read

# Trooth command-line tool 0.11.0: witnesses for the log, and a signed public record

Trooth's log now asks independent witnesses to cosign each checkpoint, every entry has a receipt in the COSE format, and each public record reading is signed and entered in the log. The public record is shown on Trust Profiles.

## What changed

The log sends each new checkpoint, with a proof that it extends the last one, to the staging witnesses of the witness network run by Geomys, Mullvad and TrustFabric, and serves their cosignatures on the checkpoint. trooth log checkpoint and trooth log monitor say which of them cosigned, and --witnesses requires a number of them. trooth log receipt checks an entry's receipt in the COSE format (RFC 9942) against the log key published at api.trooth.co/.well-known/scitt-keys. Each public record reading is now named by its fingerprint in a statement Trooth signs and enters in the log, and trooth public-record checks that statement, its key and its log entry. The reading adds the legal entity's identifier, the domain's certificates in public certificate logs, its security contact, the pages its home page links to, an exact-name check against the US Treasury sanctions list, and a fingerprint of every response it read, which Trooth keeps so a disputed fact can be replayed. A Trust Profile shows the reading when one was taken in the last day, and a reader can ask for one there.

## Why it changed

A log checked only by its own operator and by monitors detects a rewritten history only later. Witnesses refuse to cosign one, so a reader who asks for cosignatures never accepts it. A public record that is not signed cannot be held to what it said.

## Who is affected

- **Affected:** Anyone relying on a Trooth reading or a company's public record, and anyone watching that Trooth does not change its history.
- **Availability:** npm, as trooth 0.11.0; on Trust Profiles, in the Identity section. No account.
- **Release stage:** Available.
- **Areas:** CLI, API.

## What to do

**No action required.** Nothing is required. Run trooth log checkpoint to see which witnesses cosigned, or open a company's Identity section to see its public record.

## Versions and migration

- **trooth:** `0.11.0`

## Dates

- **Announced:** October 7, 2026, the day this entry was written. Entries are never backdated.
- **Released:** October 7, 2026.

## What this does not fix

Cosignatures begin when the witness network accepts the log onto its staging list; the witnesses are staging services and the network has no production list yet. The log key is held in software and used by one person; hardware custody and a second approver are planned and described in docs/KEY-CEREMONY.md. A name match on the sanctions list is not an identification. Contractor registrations, patent and trademark records and state registers are not read.

## Read more

- [Witnesses and receipts in the CLI reference](https://trooth.co/docs/cli#log)
- [The log's rules, with witnesses and receipts](https://github.com/troothllc/trooth-cli/blob/main/docs/LOG.md)

On this page

- What changed
- Why it changed
- Who is affected
- What to do
- Versions and migration
- Dates
- What this does not fix
- Read more

[New](https://trooth.co/changelog?type=new)[CLI](https://trooth.co/changelog?area=cli)[API](https://trooth.co/changelog?area=api)

[Back to changelog](https://trooth.co/changelog)

## Related changes

- [OCT.07NewTrooth command-line tool 0.10.0: what a company published outside its own siteCLI +1](https://trooth.co/changelog/2026-10-07-cli-0-10-0-public-record)
- [OCT.06NewTrooth command-line tool 0.9.0: a public log of every signed readingCLI +1](https://trooth.co/changelog/2026-10-06-cli-0-9-0-log)
- [OCT.06NewTrooth command-line tool 0.8.0: bundles, statement v3, schemas and librariesCLI +1](https://trooth.co/changelog/2026-10-06-cli-0-8-0-bundles)
- [OCT.06NewTrooth command-line tool 0.7.0: check a signed reading yourselfCLI](https://trooth.co/changelog/2026-10-06-cli-0-7-0-verify)
- [OCT.05NewAgents can read your own workspace record after sign-inAPI +1](https://trooth.co/changelog/2026-10-05-signed-in-agent-access)
- [OCT.03ImprovementA reading limit that holds, token discovery for agents, and connected tracesAPI +3](https://trooth.co/changelog/2026-10-03-requirements-batch-17-50)

## Follow what changes at Trooth

Every entry by email, or a feed narrowed to one area or to the changes that need you to act.

## Product updates by email

Occasional notes when something on this page changes. You get one confirmation email when you subscribe, every email carries an unsubscribe link, and the address is never sold or shared.

Email address

[RSS](https://trooth.co/changelog/rss.xml)[CLI only](https://trooth.co/changelog/rss.xml?area=cli)[Needs action](https://trooth.co/changelog/rss.xml?action=required)

## Structured data

```json
{
  "@context": "https://schema.org",
  "@graph": [
    {
      "@type": "Organization",
      "@id": "https://trooth.co/#org",
      "name": "Trooth",
      "legalName": "Trooth, LLC",
      "alternateName": [
        "Trooth, LLC",
        "Trooth Network",
        "trooth.co"
      ],
      "url": "https://trooth.co",
      "logo": {
        "@type": "ImageObject",
        "@id": "https://trooth.co/#logo",
        "url": "https://trooth.co/brand/trooth-mark_black-on-white_1024.png",
        "contentUrl": "https://trooth.co/brand/trooth-mark_black-on-white_1024.png",
        "width": 1024,
        "height": 1024,
        "caption": "Trooth"
      },
      "image": {
        "@id": "https://trooth.co/#logo"
      },
      "description": "Trooth is an infrastructure and cybersecurity company providing Machine-Readable Trust. The Trooth Network keeps one current Machine-Readable Trust Profile per company, each fact sourced. Trooth signs what it witnessed; company declarations are unsigned.",
      "foundingDate": "2025-12-16",
      "address": {
        "@type": "PostalAddress",
        "streetAddress": "777 Brickell Ave, Suite 500, PMB 1174",
        "addressLocality": "Miami",
        "addressRegion": "FL",
        "postalCode": "33131",
        "addressCountry": "US"
      },
      "contactPoint": {
        "@type": "ContactPoint",
        "contactType": "customer support",
        "email": "hello@trooth.co",
        "url": "https://trooth.co/contact"
      },
      "sameAs": [
        "https://x.com/Troothllc",
        "https://github.com/troothllc",
        "https://www.crunchbase.com/organization/trooth",
        "https://www.wikidata.org/wiki/Q141292994",
        "https://www.youtube.com/@Troothllc",
        "https://www.trustpilot.com/review/trooth.co"
      ]
    },
    {
      "@type": "WebSite",
      "@id": "https://trooth.co/#website",
      "url": "https://trooth.co",
      "name": "Trooth",
      "alternateName": "Trooth Network",
      "inLanguage": "en",
      "publisher": {
        "@id": "https://trooth.co/#org"
      },
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://trooth.co/network?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@type": "ItemList",
      "@id": "https://trooth.co/#sitelinks",
      "name": "Trooth sitelinks",
      "itemListElement": [
        {
          "@type": "SiteNavigationElement",
          "position": 1,
          "name": "Join Trooth for free",
          "url": "https://trooth.co/signup"
        },
        {
          "@type": "SiteNavigationElement",
          "position": 2,
          "name": "Company, Trooth",
          "url": "https://trooth.co/network/company/trooth"
        },
        {
          "@type": "SiteNavigationElement",
          "position": 3,
          "name": "Trooth Network",
          "url": "https://trooth.co/network"
        }
      ]
    }
  ]
}
```

```json
{
  "@context": "https://schema.org",
  "@type": "BreadcrumbList",
  "itemListElement": [
    {
      "@type": "ListItem",
      "position": 1,
      "name": "Home",
      "item": "https://trooth.co/"
    },
    {
      "@type": "ListItem",
      "position": 2,
      "name": "Changelog",
      "item": "https://trooth.co/changelog"
    },
    {
      "@type": "ListItem",
      "position": 3,
      "name": "Trooth command-line tool 0.11.0: witnesses for the log, and a signed public record",
      "item": "https://trooth.co/changelog/2026-10-07-cli-0-11-0-witnesses"
    }
  ]
}
```
