Synthetic demoNo live systems

See a key rotation, step by step.

Replay a synthetic run. See what changed, what was checked, and what remains unproven.

Published sample, not live customer evidence

Key rotation

0 of 6 events replayed

Playback only. This click authorizes nothing and makes no provider call.

Old key

ACTIVEAfter revocationCheck pending

Replacement

NOT CREATEDBefore revocationCheck pending
ConsumerUsing old key
Recorded step 1 of 6Not replayed yet

Replacement credential created

Create a replacement with a different synthetic fingerprint.

Evidence for this step

· CREATE REPLACEMENT

A distinct synthetic fingerprint becomes ACTIVE. Verifier v1 confirms that the supplied evidence contains no forbidden credential-value fields.

View sample scope

Synthetic credential rotation

One suspected key. One consumer. Six permitted operations. Stop on any deviation.

Provider
Northstar API (synthetic)
Tenant
sandbox_tenant_001
Consumer
billing_worker_demo
Authority
Declared approval · 12:00:10Z
Old key identifier
sk_demo_old_7F2C91
Replacement identifier
sk_demo_new_C3A901
Suspected fingerprint
sha256:457612e…dbf06885d5
Recorded run
2026-08-27 · fixed public specimen

Permitted

Create · migrate · probe · revoke · probe · read back

Declared hard stops

Wrong target · readable secret · failed canary · 60s timeout

This is a fixed, hash-pinned synthetic specimen. Its evidence contains fingerprints and key identifiers, never credential values. No real provider, credential, compromise, customer, or production system was used or checked.

Browser verificationVERIFYING EXACT PUBLIC BYTES…
0 pass0 fail0 not checked

Checks cover this synthetic specimen only. No real provider action was checked.

Inspect the evidence

What if the evidence changes?

Change one evidence byte. The overall verdict must fail.

The test runs locally. The published specimen stays unchanged.
Agent Action Security Review

Want your own agent action reviewed?

One consequential agent or automation action. Prioritised fixes.

€2,500 fixed · excluding VAT

Within 10 working days after evidence rules are agreed.

Check fitNon-secret fit check first.

Inspect the evidence

The browser checks the pinned bundle digest, receipt signature and manifest-bound evidence with the separately pinned public verifier.

See all verification checks

Hashing and verifying the public specimen…

Inspect hashes and source
Bundle SHA-256
bb921133a6d06db471b0a8f5015fd6f7a734c2c1721de4e0007fa34397c11f9c
Verifier SHA-256
7ac872446e384f40d82eaf63e7a0d5ca4604eb06a0fdb8e872a9240400377f41
Demo signer fingerprint
sha256:72a03b6fdacaad90dfc58c0e782ec51e111dfecbc1b841b6cb7a68d0a557f6e4
Source commit
d4ad234bd815

Browser execution is gated by Subresource Integrity using this displayed pin.

Inspect the fixed source specimen at commit d4ad234bd815 ↗

The specimen source commit pins the evidence package. The same-origin browser verifier is separately owned by this website and gated by the SHA-256 pin shown above.

Download files and verify offline

Verify the sample offline

Download three files, disconnect networking, and reproduce the same structured verdict with Node’s built-in cryptography. No package install. No WitnessOps API.

node verify.mjs BUNDLE.wops.json DEMO_KEY_REGISTRY.json

Reproduced with Node 24.19.0. Exit 0 means valid, 1 means invalid or untrusted, and 2 means malformed or unreadable input.

Synthetic API key rotation: verifiable proof specimen | WitnessOps