Skip to main content
[AVAILABLE], every command below runs against the repo’s actual code.

Goal

See every stage of how Parmana thinks fire for one real transaction: policy decision, the signed authorization envelope itself (not just its effects), gateway re-verification, and the resulting trust record.

Prerequisites

  • Completed Quickstart once, or at least read it, this guide assumes the server and keys are already set up the same way.
  • Read Execution authorization, this guide shows the envelope that page describes.

Steps

1. See the authorization envelope directly

Over HTTP, the envelope comes back inside the Trust Record, in its authorization field, after the gateway has verified and consumed it. To see it produced step by step, use the Runtime library directly, which is what examples/tutorials/11-execution-authorization/run.ts does: build a Runtime with a FilePolicyRepository, execute a transaction, and print result.context.authorization.
Real output (run again on 2026-10-02):
Content Hash is businessTransactionHash, the field The gateway independently recomputes and compares before releasing execution. Expires At is two minutes after Authorized At, the envelope’s TTL.

2. Run the same shape of request through the full server

This library call skips the gateway and connector entirely, it’s the Runtime in isolation. To see the whole pipeline, authorization through gateway verification through credential issuance through a connector, run Quickstart steps 3 and 5 if you haven’t: start the server, then execute a transaction over HTTP.

Verify

Compare what each path returns. The library call above hands you the SignedExecutionAuthorization on its own. The HTTP call hands you the final ExecutionTrustRecord, which carries the same envelope in authorization (with its payload: authorizationId, nonce, policyContentHash, signalsHash, expiresAt, businessTransactionHash and the rest) and covers it with the record’s signature. Both paths produce a record whose executions[0].decision.outcome is "APPROVED" for the same input signals and policy.

Troubleshoot

  • Execution Authorization was not generated thrown by the tutorial. The transaction’s Decision came back REJECTED, an authorization is signed only after approval, see Write your first policy for what a rejected decision actually does (it throws, it doesn’t return a REJECTED object).
  • The HTTP path’s trust record has no authorization field. Records created before the field was added have none; every new approved record has it.
  • Content Hash differs between two runs with identical-looking transaction JSON. Check timestamps and generated IDs (businessTransactionId, intentId, etc.), the hash covers the full executable content, any field that differs between runs changes it.

Next

Detect tampering

Mutate this same content and watch the hash comparison reject it.

Verify a trust record independently

Check the resulting trust record’s signature without Parmana running at all.