See a key rotation, step by step.
Replay a synthetic run. See what changed, what was checked, and what remains unproven.
Published sample, not live customer evidence
Key rotation
0 of 6 events replayedPlayback only. This click authorizes nothing and makes no provider call.
Replacement
NOT CREATEDBefore revocationCheck pendingReplacement credential created
Create a replacement with a different synthetic fingerprint.
Evidence for this step
· CREATE REPLACEMENT
A distinct synthetic fingerprint becomes ACTIVE. Verifier v1 confirms that the supplied evidence contains no forbidden credential-value fields.
View sample scope
Synthetic credential rotation
One suspected key. One consumer. Six permitted operations. Stop on any deviation.
- Provider
- Northstar API (synthetic)
- Tenant
- sandbox_tenant_001
- Consumer
- billing_worker_demo
- Authority
- Declared approval · 12:00:10Z
- Old key identifier
- sk_demo_old_7F2C91
- Replacement identifier
- sk_demo_new_C3A901
- Suspected fingerprint
- sha256:457612e…dbf06885d5
- Recorded run
- 2026-08-27 · fixed public specimen
Permitted
Create · migrate · probe · revoke · probe · read back
Declared hard stops
Wrong target · readable secret · failed canary · 60s timeout
This is a fixed, hash-pinned synthetic specimen. Its evidence contains fingerprints and key identifiers, never credential values. No real provider, credential, compromise, customer, or production system was used or checked.
Checks cover this synthetic specimen only. No real provider action was checked.
Inspect the evidenceWhat if the evidence changes?
Change one evidence byte. The overall verdict must fail.
Want your own agent action reviewed?
One consequential agent or automation action. Prioritised fixes.
€2,500 fixed · excluding VATWithin 10 working days after evidence rules are agreed.
Inspect the evidence
The browser checks the pinned bundle digest, receipt signature and manifest-bound evidence with the separately pinned public verifier.
See all verification checks
Hashing and verifying the public specimen…
Inspect hashes and source
- Bundle SHA-256
- bb921133a6d06db471b0a8f5015fd6f7a734c2c1721de4e0007fa34397c11f9c
- Verifier SHA-256
- 7ac872446e384f40d82eaf63e7a0d5ca4604eb06a0fdb8e872a9240400377f41
- Demo signer fingerprint
- sha256:72a03b6fdacaad90dfc58c0e782ec51e111dfecbc1b841b6cb7a68d0a557f6e4
- Source commit
- d4ad234bd815
Browser execution is gated by Subresource Integrity using this displayed pin.
Inspect the fixed source specimen at commit d4ad234bd815 ↗The specimen source commit pins the evidence package. The same-origin browser verifier is separately owned by this website and gated by the SHA-256 pin shown above.
Download files and verify offline
Verify the sample offline
Download three files, disconnect networking, and reproduce the same structured verdict with Node’s built-in cryptography. No package install. No WitnessOps API.
node verify.mjs BUNDLE.wops.json DEMO_KEY_REGISTRY.jsonReproduced with Node 24.19.0. Exit 0 means valid, 1 means invalid or untrusted, and 2 means malformed or unreadable input.