Try it
- Load the example, then Verify. The result is valid.
- Load the example, changed: the same record with the amount changed from 100 to 100000. Verify reports that the hash no longer matches. Changing any signed field has the same effect.
- Check a record of your own. Run the Playground to get a real signed record from the public sandbox, paste it, click Use the sandbox key, then Verify.
scripts/generate-offline-verifier-fixture.ts. The same script produces the fixture that the
Python SDK’s offline verifier is tested against.
What is checked
The code is
docs/site/snippets/record-verifier.jsx.
A test in the repository runs that exact code against records signed by Parmana’s signer,
including a large record signed as a commitment, and checks that it agrees with Parmana’s
offline verifier and rejects changed records.
What this page does not check
- Who holds the key. A valid signature proves the record was signed by that key. Get the
key from the deployment you trust, for example
GET /keys/default, not from the person who sent you the record. - Hybrid signatures. A record can also carry an ML-DSA-65 signature in a
signaturesarray. Browsers have no ML-DSA support yet, so this page checks only the Ed25519 signature and says so. - Other record types. Execution Intents are signed too; verify them with
@parmana/sign. Refusal Records are checked withPOST /refusal/verify(Refusal Records). - That the action was authorized. A signature shows what Parmana recorded and that it was not altered. It does not show that nothing bypassed Parmana. See the Audit guide.
@parmana/sign or
Verify independently.