[AVAILABLE], published:
@parmana/sign on
npm, version 0.2.0, Apache
License 2.0. Source:
github.com/pavancharak/parmana-sign.@parmana/sign checks a signed Parmana record using only the record and Parmana’s public
keys. It makes no network calls, reads no files or environment variables, and needs no
Parmana account. An auditor, a regulator or a counterparty can run it without trusting
Parmana’s servers or database.
It checks three things, and reports each one separately:
- The record’s hash matches its content.
- The record’s Ed25519 signature is valid for the named key.
- If the record is hybrid signed, every entry in its
signaturesarray (Ed25519 and ML-DSA-65) is valid.
Install
node:crypto starts at 24.6.0.
Quick start
1
Get the record
Fetch it from the API, or use one exported from Parmana as JSON.
2
Get the public key
The record names its key in See Public keys for hybrid records and caching.
signature.keyId. Public keys need no API key.3
Verify
verify.mjs
What you can verify
How it relates to the other SDKs
The TypeScript SDK (@parmana/sdk) calls the Parmana API and also
includes offline verifiers. @parmana/sign is the standalone verifier: no API client,
no dependency on any other Parmana package, and an open source license. Use it when the
party verifying a record should not depend on Parmana’s own client code.
Both use the same field mappings as the server’s signer. @parmana/sign is tested against
records signed by the server’s own signing code, including hybrid records and large records
signed through AWS KMS.
Versioning and support
- Follows Semantic Versioning. Below 1.0.0, a minor release may include breaking changes, always listed in the changelog.
- Supported Node.js versions: 24.6.0 and later, on Linux, Windows and macOS.
- Releases carry SLSA provenance and a Sigstore signature on the GitHub release. See RELEASING.md to check them.
- Report bugs in GitHub issues, and security issues as described in its SECURITY.md.