Skip to main content
Evaluation only. Reading, building and running Parmana to assess it is permitted. Any other use needs a separate written agreement with Parmana Systems. See License and evaluation.
This page is for anyone assessing Parmana: an engineer trying it, a security reviewer, or an auditor. It needs no accounts, credentials, database or network access beyond npm ci. Auditors should continue with the Audit guide after step 2.

Requirements

  • Node.js 24.6 or later. The hybrid Ed25519 and ML-DSA-65 signatures use node:crypto, which supports ML-DSA from 24.6.
  • npm, as bundled with Node.js.
  • Git, and Bash for two tests that syntax check shell scripts. On Windows, Git for Windows provides it.
  • Docker, only for the optional offline check in step 4.
Linux, macOS and Windows are supported.

1. Install, build and test

npm run build comes first because tests import the workspace packages from their built dist/ output; npm test refuses to run against stale output. No .env is needed. The test setup uses the same local defaults as CI: the committed ./policies, in memory storage, and local Ed25519 keys generated for the run. Suites that need live services (HubSpot, Supabase) skip. Expect about 2,880 passing tests and about 54 skipped.

2. Run every example

This runs each tutorial in examples/tutorials/ against local mock connectors, with throwaway keys deleted afterwards. Several tutorials print FAILED or ✗ on purpose: they show a forged, replayed or tampered request being refused. The run ends with All Parmana examples completed successfully. and exit code 0. To see the whole chain in one walkthrough (policy evaluation, signed authorization, envelope verification, credential isolation, connector execution and the signed Trust Record):
npm run preflight runs everything a contributor runs before a change: typecheck, lint, format check, the Python model check, every test, the build and every example.

3. Try the hosted sandbox (optional)

A public sandbox runs the same API with demo policies and a published demo approver key. Use the Playground, or the scripts in examples/sandbox-playground/ from cURL, PowerShell, TypeScript or Python. See Live API and demos.

4. Run the full stack with no internet route (optional, Docker)

This starts the server, Postgres and a stand in downstream system on a Docker network with no route to the internet, approves a policy through maker checker, runs an approved and a refused refund, and verifies the resulting Trust Record with only the public keys. See Offline verification. CI runs the same check on every change to the server image.

5. Verify a record without Parmana

Every approved action produces a signed Execution Trust Record. It can be checked with only the record and the public keys, using @parmana/sign (Apache 2.0, a separate repository) or this repository’s scripts/verify-trust-record.ts:
See Verify independently.

Questions and feedback

Email founder@parmanasystems.com for questions, a guided walkthrough or licensing. Report security issues privately as described in SECURITY.md.