Local record verification
Verify a Warden record
Check an APA attestation or WARDEN BREAKER certificate in this
browser. The verifier uses canonical signed bytes and WebCrypto
Ed25519; it does not accept an API's verified flag as
proof.
Verification result
Load a public record, use the dated sample, or paste your own material. The result separates signature validity, freshness, record status, and the limits of the claim.
Verification pending
PendingLocal check completed .
Record and cryptographic details
- Issuer
- Pending
- Matched key
- Pending
- Signature state
- Not checked
- Issuer signature
Pending- Endpoint host
- Pending
- Tier
- Pending
- Scans
- Pending
- Signed status
- Pending
- Effective status
- Pending
- Verified at
- Pending
- Expires at
- Pending
Verification pending
PendingLocal check completed .
Certificate and log inclusion details
- Issuer
- Pending
- Matched key
- Pending
- Signature state
- Not checked
- Signature
Pending- Award
- WARDEN BREAKER
- Certificate ID
Pending- Finder
- Pending
- Confirmed
- Pending
- Threat class
- Pending
- Benchmark case
Pending- Payload SHA-256
Pending- Payload scope
- Pending
- Log sequence
- Pending
- Log state
- Not checked
- Signed checkpoint head
Pending
How local verification works
-
01Parse
Reject malformed or unsupported material.
-
02Resolve key
Select the applicable current or recent key by signed time.
-
03Verify
Check canonical bytes with WebCrypto Ed25519.
-
04Freshness
Evaluate expiry and signed record status.
-
05Read boundary
Separate what the record establishes from what it cannot.
Verification limits
What a valid signature does—and does not—prove
APA claim
A valid, fresh attestation proves that the host serving endpoint_host controlled the key pub when the issuer verified a live APA-conformant Protection Proof. The endpoint signed that proof, including its rolling 24-hour screened-payload count or an explicit unavailable state; the issuer separately signed the attestation. It does not prove that every request is routed through the guard or independently audit the endpoint owner's local counter state.
TOFU
First registration is trust-on-first-use: the issuer records the first valid endpoint key. An independently anchored log checkpoint makes later silent re-binding detectable; an unanchored chain cannot expose a complete rewrite or remove first-use trust.
Key theft
A stolen endpoint private key can produce valid endpoint proofs for the victim host. Revocation and key rotation can surface compromise; signature validity alone cannot rule out key theft.