1. POST /replay (what the SDKs and HTTP API expose)
This is what client.replay.replay(transaction_id) actually calls. Its real
implementation, ExecutionTrustApplication.replay()
(packages/runtime/src/ExecutionTrustApplication.ts:142-171):
replay-shaped response, not deterministic execution reconstruction.
2. packages/replay (the deterministic reconstruction engine)
A separate, real package: ReplayEngine, ReplayPipeline, ReplayExecutor,
ReplayBuilder, proven deterministic regardless of input order
(ReplayDeterminism.test.ts, “should produce identical output regardless of input order”;
ReplayEngine.test.ts; 9 tests total).
ReplayEngine.replay() genuinely re-evaluates the original policy against the recorded
signals, using a real PolicyEngine, not just a signature or hash recheck:
examples/tutorials/06-replay/run.ts: it prints a Recorded Decision and a
Replayed Decision and reports Replay Match: true when they agree. This is real semantic
re-evaluation, scoped to one execution’s decision outcome, not the fuller claim below.
What “semantic verification” still withholds
“Replay semantically verifies every trust artifact” is a future goal, not current behavior. That’s broader than whatReplayEngine does today: “every trust artifact” implies
re-evaluating every execution across a record and every artifact type, not one execution’s
decision outcome. ReplayEngine’s real, narrower behavior above is a scoped piece of that
future goal, not the whole of it. See Roadmap.