The masterdb command line
masterdb checks what MasterDB signs, from a terminal, on the TypeScript verifier. Node 24 or later.
npm install --global @masterdb/cli| Command | Does |
|---|---|
masterdb verify <file> |
Verifies a fetch response (the record’s bytes taken verbatim from its record member) or a verify request ({record_base64, seal, sidecar?}). With --context FILE (the business’s key register, certificates, AI policy history and mandates) it verifies offline; otherwise it asks POST /v1/verify and, given anchors, checks MasterDB’s signed statement. A receipt in the response is verified too. |
masterdb verify --url URL |
Fetches the record first — signed with RFC 9421 (tag="mdb-retrieval") when --sign-key names a test key — then as above. |
masterdb receipt <file> |
Shows a receipt (or the one in a response) and, given anchors, verifies it and the served rows beside it. |
masterdb jwks |
Fetches /.well-known/keys and, given anchors, verifies the whole chain; --out saves it for offline use with --keys. |
masterdb keygen |
Makes a test key (--alg ed25519 or es256), marked x-masterdb-test. |
masterdb sign <record> |
Seals a record’s exact bytes with a test key (--cert-id, --ai-policy-version, --record-type, --sealed-at) and prints the seal envelope. It refuses any key without the test mark: a production key belongs in the business’s own signing system. |
Trust comes only from anchors: --anchors FILE (a JSON array of root public keys), or the pinned set. Without anchors the tool says plainly that nothing was verified. --sandbox points at the sandbox and its anchors; --api at any deployment; --json prints machine-readable results.
Exit status: 0 verified, 1 a check failed, 2 a usage error — so it drops into a script or a CI step.