Skip to main content
New

2 minute read

Trooth command-line tool 0.14.0: a company's own signed declaration, and the proof behind each tie in the public record

A company can now sign and publish its own declaration at /.well-known/trooth.json on its domain, naming its keys, products, application programming interfaces (APIs) and code repositories, and trooth declare makes, signs and checks it. Each public record reading now names the proof behind each tie between a domain and a company, a key, a product or a repository.

What changed

trooth declare init makes the Ed25519 key for a domain's declaration, trooth declare sign writes and signs the file, and trooth declare check fetches a domain's declaration, or reads a saved file, and checks its domain, its dates, the addresses in it, its signature and an optional Domain Name System (DNS) TXT (text) record at _trooth-key that names the key. It exits 11 when the declaration has expired. Each public record reading now records the proof behind each tie: a DNS TXT record in the domain's zone, the site's signed declaration, a sign-in through the company's identity provider at the domain, a code sent to a mailbox at the domain, or control of a code repository organization that its code host shows as holding the domain. It carries what a declaration that checks names as subjects (the company's key, its products and its APIs), the representative Trooth recorded at claim time under an id that holds no personal data, and records when a declaration appears, changes key or disappears. The guard can now require domain control: a proof that binds the domain to the company's record or to its declared key, confirmed by a DNS TXT record, a mailbox code, an identity provider sign-in or a declaration that checks, is a claim the guard reads from the signed public record. The company record at trooth.co/api/network/profile now carries Trooth's own record of the domain claim in authority.claim. The declaration has a published JSON Schema, a machine-readable description of every field.

Why it changed

A reader needs to know how a domain is tied to a company, a key or a product before relying on the tie. A file the company signs at its own domain, read and logged by Trooth, makes the company's own key and every later change to it public, and naming the proof behind each tie lets a reader weigh it.

Who is affected

  • Affected: Companies that want to state their own keys and subjects at their domain, and anyone relying on a company's public record or running the guard.
  • Availability: npm, as trooth 0.14.0. No account.
  • Release stage: Available.
  • Areas: CLI, API.

What to do

No action required. Nothing is required. To publish a declaration, run trooth declare init and trooth declare sign, place the file at /.well-known/trooth.json on your domain, and run trooth declare check.

Versions and migration

  • trooth: 0.14.0

Dates

  • Announced: October 7, 2026, the day this entry was written. Entries are never backdated.
  • Released: October 7, 2026.

What this does not fix

A declaration is signed by the company itself: it shows who controlled the site's content when Trooth read it, not the legal entity or a person's authority to act for it. Trooth does not yet offer a sign-in through a company's identity provider as a way to claim a domain, so no claim record carries that proof today. An outside security review of the guard and production use by teams outside Trooth are still open.

Read more

Follow what changes at Trooth

Every entry by email, or a feed narrowed to one area or to the changes that need you to act.

Product updates by email

Occasional notes when something on this page changes. You get one confirmation email when you subscribe, every email carries an unsubscribe link, and the address is never sold or shared.

RSSCLI onlyNeeds action

View as agent