Metadata-Version: 2.4
Name: primust-verify
Version: 1.9.1
Summary: Offline verifier for Primust VPECs. Free forever. No account required.
Project-URL: Homepage, https://primust.com
Project-URL: Documentation, https://docs.primust.com
Project-URL: Verify, https://verify.primust.com
Author-email: "Primust, Inc." <eng@primust.com>
License-Expression: Apache-2.0
License-File: LICENSE
Classifier: Development Status :: 5 - Production/Stable
Classifier: Intended Audience :: Developers
Classifier: License :: OSI Approved :: Apache Software License
Classifier: Programming Language :: Python :: 3
Classifier: Programming Language :: Python :: 3.11
Classifier: Programming Language :: Python :: 3.12
Classifier: Programming Language :: Python :: 3.13
Classifier: Topic :: Security :: Cryptography
Requires-Python: >=3.11
Requires-Dist: cryptography>=41.0
Requires-Dist: httpx>=0.27.0
Requires-Dist: primust-artifact-core>=1.0.3
Requires-Dist: pypdf>=4.0.0
Requires-Dist: pyyaml>=6.0
Description-Content-Type: text/markdown

# primust-verify

**Free forever. No account required. Apache-2.0.**

Offline verifier for Primust VPECs (Verifiable Process Execution Credentials).

```bash
pip install primust-verify
```

## Verify a VPEC

```python
from primust_verify import verify

result = verify(vpec_json)
assert result.valid
```

Or from the command line:

```bash
primust-verify vpec.json
```

Exit codes:
- `0` — valid
- `1` — invalid (signature mismatch, tampered, or failed checks)
- `2` — system error

## Zero-network verification

Use `--trust-root` to verify without any network calls:

```bash
primust-verify vpec.json --trust-root ./primust-pubkey.pem
```

This fetches no external resources. The public key PEM is the only trust anchor needed.

Download the Primust public key from:
`https://primust.com/.well-known/primust-pubkey.pem`

## Deferred math-tier proofs (PACs)

A governance run's ZK (Noir/UltraHonk) proof is computed asynchronously and
isn't ready at the instant the VPEC is sealed, so the sealed envelope marks that
proof artifact `unresolved_at_seal`. The envelope alone therefore can't
self-prove the math-tier claim — by default the verifier reports it as
unresolved and tells you to consult the live API.

To verify the math tier **fully offline**, supply the **PAC** (Proof Attestation
Certificate) — a separately-signed certificate that carries the completed proof
bundle and binds it to the VPEC:

```bash
# Fetch the PAC(s) for a VPEC (public, no auth):
curl https://api.primust.com/api/v1/vpecs/<vpec_id>/pacs > pacs.json

primust-verify vpec.json --trust-root ./primust-pubkey.pem --pacs pacs.json
```

The verifier resolves a deferred proof at one of two trust levels:

- **trustless** — the ZK proof is **re-verified locally** against the circuit's
  pinned verification key and its public input is bound to the VPEC's record
  root. Zero trust in Primust. Requires the Barretenberg `bb` CLI (see below).
- **attested** — only the PAC's issuer signature is checked (e.g. when `bb`
  isn't installed). Same trust basis as the live-API consult, but offline. The
  verifier emits an SI-13 disclosure noting the proof was not independently
  re-verified.

Pass `--require-reverified-proofs` to refuse the attested fallback — a deferred
proof then only clears if it is genuinely re-verified (trustless).

### Enabling trustless re-verification (`bb`)

Trustless re-verification shells out to the Barretenberg `bb` CLI. Install it
with [`bbup`](https://github.com/AztecProtocol/aztec-packages) (installs to
`~/.bb/bb`, which the verifier finds automatically) or point the verifier at a
specific binary with `PRIMUST_BB=/path/to/bb`. Without `bb`, the verifier
degrades to the attested path (or fails the artifact under
`--require-reverified-proofs`).

## You don't need a Primust account to verify a VPEC

This tool is free, open source (Apache-2.0), and works offline. Anyone can verify a VPEC — regulators, auditors, counterparties — without creating an account or contacting Primust.

## Verification paths

- `primust-verify` CLI — canonical local/offline verifier
- Evidence Pack `verify.html` — bundled local browser verifier
- `verify.primust.com` — hosted convenience verifier

The hosted site is useful for shared links and quick review, but it is not the
canonical zero-network / trust-minimized path.

## Options

| Flag | Description |
|------|-------------|
| `--production` | Reject VPECs issued with test keys |
| `--skip-network` | Skip Rekor transparency log check |
| `--trust-root <path>` | Use a local PEM file as trust anchor (zero-network mode) |
| `--pacs <path>` | Supply Proof Attestation Certificate(s) to resolve deferred math-tier proofs offline |
| `--require-reverified-proofs` | Refuse the attested fallback: a deferred proof clears only if re-verified (trustless, needs `bb`) |
| `--json` | Output structured JSON instead of human-readable text |

## Requirements

- Python 3.11+
- Optional: Barretenberg `bb` CLI — only for **trustless** re-verification of
  deferred math-tier proofs (see "Deferred math-tier proofs" above). Not needed
  for signature, schema, surface, gap, or attested-PAC verification.

## License

Apache-2.0

---

[Docs](https://docs.primust.com) | [Verify online](https://verify.primust.com) | [Primust](https://primust.com)
