Skip to main content
[AVAILABLE], published: @parmana/sign on npm, version 0.2.0, Apache License 2.0. Source: github.com/pavancharak/parmana-sign.
@parmana/sign checks a signed Parmana record using only the record and Parmana’s public keys. It makes no network calls, reads no files or environment variables, and needs no Parmana account. An auditor, a regulator or a counterparty can run it without trusting Parmana’s servers or database. It checks three things, and reports each one separately:
  1. The record’s hash matches its content.
  2. The record’s Ed25519 signature is valid for the named key.
  3. If the record is hybrid signed, every entry in its signatures array (Ed25519 and ML-DSA-65) is valid.
Changing any signed field, even one number, fails the hash and every signature.

Install

Requires Node.js 24.6.0 or later. ML-DSA-65 support in node:crypto starts at 24.6.0.

Quick start

1

Get the record

Fetch it from the API, or use one exported from Parmana as JSON.
2

Get the public key

The record names its key in signature.keyId. Public keys need no API key.
See Public keys for hybrid records and caching.
3

Verify

verify.mjs
Records from the sandbox only verify against the sandbox’s key, and production records only against production’s key.

What you can verify

How it relates to the other SDKs

The TypeScript SDK (@parmana/sdk) calls the Parmana API and also includes offline verifiers. @parmana/sign is the standalone verifier: no API client, no dependency on any other Parmana package, and an open source license. Use it when the party verifying a record should not depend on Parmana’s own client code. Both use the same field mappings as the server’s signer. @parmana/sign is tested against records signed by the server’s own signing code, including hybrid records and large records signed through AWS KMS.

Versioning and support

  • Follows Semantic Versioning. Below 1.0.0, a minor release may include breaking changes, always listed in the changelog.
  • Supported Node.js versions: 24.6.0 and later, on Linux, Windows and macOS.
  • Releases carry SLSA provenance and a Sigstore signature on the GitHub release. See RELEASING.md to check them.
  • Report bugs in GitHub issues, and security issues as described in its SECURITY.md.