Validate the exact unsigned receipt, witness registry identity, UTC timing, and frozen 24-hour publication boundary.
prepareWitnessReceipt(receipt, key)Independent witness operators can produce RC1-compatible receipts without giving Embodied Arena—or this helper—access to a production signing key. The module validates registry identity, chronology, key lifecycle, root and log bindings, then hands exact RFC 8785 bytes to operator-owned secure signing infrastructure.
The witness independently observes the root and appends a transparency-log entry. The helper freezes the receipt bytes; an HSM, TPM, KMS, or secure enclave signs those bytes without exporting its key.
Validate the exact unsigned receipt, witness registry identity, UTC timing, and frozen 24-hour publication boundary.
prepareWitnessReceipt(receipt, key)Send only canonical signing bytes to operator-owned secure hardware or managed key infrastructure.
secureSigner.sign(bytes)Attach the returned 64-byte signature only after it verifies against the registered Ed25519 public key.
attachWitnessReceiptSignature(…)The library never accepts a private-key file or seed. Embedded integrations supply one callback that receives canonical bytes and returns exactly 64 signature bytes. A self-check rejects the receipt before it can be published if the signature, key, identity, or chronology does not match.
import { signWitnessReceipt } from "./wanted-root-witness-receipt.mjs";
const signedReceipt = await signWitnessReceipt(
unsignedReceipt,
frozenRegistryKey,
bytes => witnessHsm.signEd25519(bytes)
);
await transparencyArchive.store(signedReceipt);The CLI deliberately has no signing-key option. Prepare emits canonical bytes and their digest; attach accepts only an externally generated base64url signature and verifies it before returning the complete receipt. Verify checks any received receipt independently.
node wanted-root-witness-receipt.mjs \
--prepare unsigned.json witness-key.json
# Sign signing_bytes_base64url outside this tool.
node wanted-root-witness-receipt.mjs \
--attach unsigned.json signature.txt witness-key.json
node wanted-root-witness-receipt.mjs \
--verify receipt.json witness-key.json