Skip to content

Test vectors

Both verifier libraries are held to the same files: good cases every verifier must accept, and a corpus of deliberately broken artefacts every verifier must refuse, for the reason named. If you write your own verifier, hold it to them too. All keys in them are test keys derived from public seeds; the anchors they trust are in context.json.

File Cases What it holds
context.json — The shared context of every vector: trust anchors, MasterDB key sets, and one fictional business (key register, certificate history, AI policy history, mandates). All keys are TEST keys derived from public seeds.
keysets.json 3 Signed key sets that every verifier must ACCEPT from the named anchors.
certificates.json 8 ADL Certificates that every verifier must ACCEPT against the named key set.
seals.json 17 Records and their seals that every verifier must ACCEPT, with the context of context.json (business keys, certificates, AI policy history, mandates); a case whose input carries certificates is checked against that certificate history instead of the context’s. Seal format 2 (seal.v2, batch-seal.v2: ai_policy_version) and format 1 (v1: terms_version) both verify.
ai-policy.json 4 The ai_policy_bits a search row carries, each with the exact bytes of the sealed AI policy record a fetch returns (record_base64; null at version 0) and the fetch’s ai_policy.version: every verifier must ACCEPT these — the bits derived from the sealed booleans, blocked contexts bc1 to bc10 at bits 0 to 9, the purchase bit alone allowed to be withheld.
rows.json 5 Served index rows that every verifier must ACCEPT against the production key set.
receipts.json 6 Receipts that every verifier must ACCEPT against the production key set: format 3 (ai_policy_version rows), format 2 and format 1.
mandates.json 2 Mandates that every verifier must ACCEPT, sealed by the business’s passkeys.
merkle.json 7 RFC 6962 inclusion proofs that every verifier must ACCEPT.
log.json 4 Transparency-log checkpoints, inclusion proofs (a seal leaf; a receipt, two-level) and a consistency proof that every verifier must ACCEPT, made by MasterDB’s log with the log_checkpoint key of the production key set.
statements.json 2 MasterDB’s public statements that every verifier must ACCEPT against the production key set, each under its own payload type: the verify page’s signed JSON (kind verify_page, verify-page.v1) and the key directory (kind key_directory, key-directory.v1).
projections.json — Every projection version (adl_proj hash) a verifier of this release knows, with the fields its row signature leaves out.
key-custody.json 17 Key custody statements (key-custody.v1): who holds each business key, hosted (MasterDB holds it for the business) or self, signed by the issuance key pair (P-256 and ML-DSA-65, both required) and published beside the certificate (GET /v1/certificates/{uuid}/key-custody). Kind key_custody checks one statement against the named key set; kind key_custody_seal checks a seal of the business of context.json with its key_custody (the route document or a list of envelopes) and names the custody of the seal key at sealed_at (unstated when no statement names it). expect.valid says whether each must be accepted or REFUSED for the reason named.
broken.json 106 The broken-record corpus: every input here must be REFUSED, for the reason named (the reason codes are shared by every MasterDB verifier).

Every one of these 106 inputs must be refused with the reason in the last column.

Case Kind What is wrong Reason
broken/seal/hosted-key-without-grant seal A hosted-key seal whose sidecar’s resolved grant does not include publish.products. out_of_scope
broken/seal/hosted-key-checked-against-mandates seal The same hosted-key seal judged as an integration key would be, against mandates: none covers it. out_of_scope
broken/seal/published-keys-by-sidecar-key seal A published key list signed by a MasterDB key that is not the statement key. key_unknown
broken/seal/published-keys-edited seal A published key list with a key removed after signing. signature_invalid
broken/seal/published-keys-another-business seal Validly published keys of another business, offered for this business’s certificate. key_unknown
broken/seal/byte-flipped seal One bit of the record flipped. hash_mismatch
broken/seal/re-serialised seal The record parsed and re-serialised (same values, different bytes): a seal is over bytes, never over a re-serialisation. hash_mismatch
broken/seal/batch-member-re-serialised seal A Path A record re-serialised: its leaf no longer proves into the sealed root. inclusion_invalid
broken/seal/key-swapped-in-payload seal The payload’s key_id swapped for another registered key; the signature is over the original payload. signature_invalid
broken/seal/key-swapped-signer seal Signed (validly) by one registered passkey while the payload names another. key_mismatch
broken/seal/key-swapped-keyid seal The signature entry relabelled with another registered passkey’s key id. signature_invalid
broken/seal/unregistered-key seal Sealed by a key that is not in the business’s register. key_unknown
broken/seal/payload-type seal A seal envelope relabelled as a receipt. payload_type_mismatch
broken/seal/unknown-member seal An envelope member DSSE does not define. envelope_malformed
broken/seal/unknown-seal-version seal A seal payload of v 3, validly signed: a verifier refuses a version it does not know rather than guessing. version_unknown
broken/seal/format-2-payload-under-v1-type seal A v 2 payload (ai_policy_version) signed under the format 1 payload type (seal.v1): the payload and its type disagree. payload_malformed
broken/seal/format-1-member-under-v2 seal A seal.v2 payload of v 2 that still names terms_version: format 2 names the version ai_policy_version. payload_malformed
broken/seal/unknown-ai-policy-schema seal A validly sealed AI policy record at an ai_policy_schema this verifier does not know (3). version_unknown
broken/seal/unknown-record-schema seal A validly sealed record whose schema version is unknown (masterdb/products/9). version_unknown
broken/seal/record-type-mismatch seal A product record sealed as an event. record_type_mismatch
broken/seal/duplicate-payload-key seal A validly signed seal payload with a duplicated member (parsers disagree on which wins, so it is never read). payload_malformed
broken/seal/expired-certificate seal Sealed on 12 October naming the certificate, after the revocation that took effect on 10 October: not in force at sealed_at. certificate_not_in_force
broken/seal/names-revoked-certificate seal A seal naming the revoked issuance itself. certificate_not_in_force
broken/seal/after-withdrawal seal Sealed on 12 October naming the certificate, after MasterDB withdrew it (a reversed approval) with effect from 10 October: refused as withdrawn, not as a compromise. certificate_withdrawn
broken/seal/names-withdrawn-certificate seal A seal naming the withdrawn issuance itself. certificate_withdrawn
broken/seal/unknown-certificate seal A seal naming a certificate that was never issued. certificate_unknown
broken/seal/wrong-ai-policy-version seal Sealed on 1 October binding AI policy version 2, which went live on 5 October. ai_policy_version_mismatch
broken/seal/format-1-wrong-terms-version seal A format 1 seal binding terms_version 2 on 1 October, before version 2 went live: refused for the same reason. ai_policy_version_mismatch
broken/seal/ai-policy-record-wrong-version seal An AI policy record’s seal naming a version it cannot create (5). ai_policy_version_mismatch
broken/seal/out-of-scope-country seal A pushed record for France under a mandate for the US and Ireland only. out_of_scope
broken/seal/out-of-scope-type seal An integration key sealing an events document under a products-only mandate. out_of_scope
broken/seal/out-of-scope-mandate-expired seal Sealed on 9 October, after the key’s mandate ended on 8 October. out_of_scope
broken/seal/sidecar-format-mismatch seal A v 2 sidecar signed under the format 1 sidecar type (sidecar.v1). payload_malformed
broken/seal/out-of-scope-grant seal Path B: the sidecar says the person’s grant at acceptance did not include publish.products. out_of_scope
broken/seal/revoked-key seal Sealed on 30 September with a passkey revoked with effect from 25 September. key_not_valid
broken/seal/webauthn-wrong-origin seal A passkey assertion made on an origin outside the allow-list. signature_invalid
broken/seal/webauthn-sign-in-challenge seal A sign-in assertion (“mdb-signin” || nonce) replayed as a seal. signature_invalid
broken/seal/webauthn-no-user-verification seal A passkey assertion without the user-verification flag. signature_invalid
broken/seal/webauthn-rs256-signature-flipped seal An RS256 passkey seal with one bit of its RSA signature flipped. signature_invalid
broken/seal/webauthn-rs256-relabelled-es256 seal An RS256 passkey assertion relabelled with an ES256 passkey’s key id (and the payload’s key_id left as the RS256 key’s). signature_invalid
broken/seal/batch-proof-tampered seal A Path A record whose inclusion proof was altered. inclusion_invalid
broken/seal/batch-wrong-leaf-index seal A Path A record presented at another leaf index. inclusion_invalid
broken/ai-policy/blocked-bit-cleared ai_policy Served bits with a blocked context the business set (bc8 politics_elections) cleared. ai_policy_bits_mismatch
broken/ai-policy/blocked-bit-added ai_policy Served bits with a blocked context the business never set (bc1). ai_policy_bits_mismatch
broken/ai-policy/action-widened ai_policy Served bits granting reserve (action bit 2), which the sealed record does not. ai_policy_bits_mismatch
broken/ai-policy/wrong-version ai_policy Bits naming a version other than the fetched record’s. ai_policy_bits_mismatch
broken/ai-policy/wrong-schema ai_policy Bits claiming ai_policy_schema 1 for a schema 2 record (so the blocked contexts would be read as absent). ai_policy_bits_mismatch
broken/ai-policy/version-0-with-bits ai_policy No sealed AI policy (version 0), yet bits that permit answering. ai_policy_bits_mismatch
broken/mandate/scope-widened mandate The mandate’s countries widened after it was sealed. signature_invalid
broken/mandate/sealed-by-integration-key mandate A mandate signed by the machine key itself: a mandate is a person’s act, sealed by a passkey. key_unknown
broken/entitlement/expired entitlement The same entitlement checked twenty minutes after it was issued: it lapsed at expires. entitlement_expired
broken/entitlement/other-vendor entitlement An entitlement presented to another AI company. entitlement_invalid
broken/entitlement/other-listing entitlement An entitlement for another of the vendor’s listings. entitlement_invalid
broken/entitlement/seat-changed entitlement The seat changed after signing. signature_invalid
broken/entitlement/signed-by-statement-key entitlement An entitlement signed by the verify statement key, which may not issue entitlements. key_unknown
broken/entitlement/extra-member entitlement A validly signed entitlement carrying a member the format does not have. payload_malformed
broken/statement/key-directory-as-verify-page verify_page A genuine key directory offered where a verify page is expected. payload_type_mismatch
broken/statement/verify-page-as-key-directory key_directory A genuine verify page offered where the key directory is expected. payload_type_mismatch
broken/statement/verify-page-as-verify-statement verify_page The verify page’s answer in its first form: a verify-statement.v1 (the type of POST /v1/verify’s answer) told apart by a kind member. payload_type_mismatch
broken/statement/key-directory-as-verify-statement key_directory The key directory in its first form: a verify-statement.v1 told apart by a kind member. payload_type_mismatch
broken/statement/verify-page-kind-member verify_page A validly signed verify-page.v1 still carrying the kind member the format no longer has. payload_malformed
broken/statement/verify-page-verdict-changed verify_page A verify page whose signed verdict was flipped from valid to not valid after signing. signature_invalid
broken/statement/key-directory-by-sidecar-key key_directory A key directory signed by a MasterDB key that is not the statement key. key_unknown
broken/certificate/tampered certificate The legal name changed after signing. signature_invalid
broken/certificate/signed-by-working-key certificate A certificate signed by the sidecar key, which may not issue certificates. key_unknown
broken/certificate/sandbox-under-production certificate A sandbox certificate checked against the production anchors. key_unknown
broken/certificate/reason-on-active certificate A validly signed active certificate carrying a status_reason, which only a withdrawn issuance has. payload_malformed
broken/certificate/unknown-member certificate The format is closed. A validly signed certificate with a member that is not in the format (here extra_member) is refused; a new member is a new format. payload_malformed
broken/certificate/unknown-version certificate A validly signed certificate of format v 2. version_unknown
broken/certificate/classical-only certificate An ADL Certificate is hybrid-signed (P-256 and ML-DSA-65, both required): one carrying only the P-256 signature is refused. post_quantum_required
broken/certificate/ml-dsa-only certificate A certificate carrying only the ML-DSA-65 signature of the issuance key is refused, however valid that signature. post_quantum_required
broken/certificate/two-classical-signatures certificate Two signatures, but not the two halves: a second signature by a root key (which does not issue certificates) is ignored, so the certificate still lacks its ML-DSA-65 half. post_quantum_required
broken/keyset/wrong-anchors keyset The production key set checked against anchors that are not MasterDB’s. trust_chain_broken
broken/keyset/compromise-mark-removed keyset The compromised_from mark removed from the signed payload. signature_invalid
broken/keyset/key-without-certificate keyset A validly signed set listing a key with no certificate chaining to the anchors. trust_chain_broken
broken/keyset/classical-only keyset The key set is hybrid-signed: one signed by the P-256 issuance key alone is refused. post_quantum_required
broken/keyset/ml-dsa-only keyset A key set signed by the ML-DSA-65 issuance half alone (all else genuine) is refused. post_quantum_required
broken/keyset/key-certified-by-ml-dsa-only keyset A set listing a receipt key whose key certificate carries only the ML-DSA-65 issuance signature. The key is not trusted; the whole set is refused. post_quantum_required
broken/keyset/key-certified-by-classical-only keyset A set listing a receipt key whose key certificate carries only the P-256 issuance signature: refused. post_quantum_required
broken/keyset/successor-root-certified-by-classical-only keyset A successor root certified by the old root P-256 key alone: it is not trusted, and nothing certified under it is. post_quantum_required
broken/row/v3-ai-policy-version-changed row A v3 row whose signed ai_policy_version was changed. row_signature_invalid
broken/row/v2-price-changed row A v2 row whose US price changed. row_signature_invalid
broken/row/v2-under-v1-rules row A v2 row relabelled as a v1 row: the adl_proj is part of the signed bytes, so the signature no longer verifies. row_signature_invalid
broken/row/price-changed row The US price on a served row changed. row_signature_invalid
broken/row/unknown-projection row A row naming a projection version nobody published. projection_unknown
broken/row/signed-by-receipt-key row A row signed by a MasterDB key that is not a projection key. key_unknown
broken/receipt/row-changed receipt The receipt’s row origin changed after signing (“you served me the old price”). signature_invalid
broken/receipt/expired-key receipt Signed at 09:30 on 1 October by a receipt key whose window ended at midnight. key_not_valid
broken/receipt/compromised-key receipt Signed after the receipt key’s compromised_from. key_compromised
broken/receipt/signed-by-projection-key receipt A receipt signed by a MasterDB key that is not a receipt key. key_unknown
broken/receipt/v2-another-caller receipt A leaked format 2 receipt presented by a caller it was not issued to. receipt_caller_mismatch
broken/receipt/v1-when-caller-required receipt A format 1 receipt where the checker requires the caller to be named (it names none). receipt_caller_mismatch
broken/receipt/v2-without-caller receipt Format 2 claimed without caller_key_id. payload_malformed
broken/receipt/v3-terms-version-row receipt Format 3 claimed with a row still naming terms_version. payload_malformed
broken/receipt/v2-ai-policy-version-row receipt Format 2 claimed with rows naming ai_policy_version, which only format 3 has. payload_malformed
broken/receipt/v3-without-caller receipt Format 3 claimed without caller_key_id. payload_malformed
broken/receipt/other-region receipt A receipt claiming one region, signed by another region’s receipt key. key_unknown
broken/receipt/served-row-differs receipt A genuine receipt, checked against a served row whose origin differs from what the receipt says was served. receipt_row_mismatch
broken/merkle/wrong-tree-size merkle A genuine proof checked against a tree size other than the one that was signed. inclusion_invalid
broken/log/checkpoint-size-changed checkpoint A checkpoint whose tree size was changed after signing. checkpoint_invalid
broken/log/checkpoint-other-origin checkpoint A note validly signed by the log key for another origin. checkpoint_invalid
broken/log/checkpoint-unknown-key checkpoint A checkpoint signed by a key named masterdb-log that is not the log key. checkpoint_invalid
broken/log/inclusion-wrong-index log_inclusion A genuine seal-leaf proof presented at another leaf index. inclusion_invalid
broken/log/receipt-minute-size log_inclusion A receipt proof whose minute-tree size was changed: the first level no longer verifies. inclusion_invalid
broken/log/consistency-wrong-older log_consistency A consistency proof checked against a different older checkpoint (the newer one itself as older). checkpoint_invalid
broken/log/consistency-tampered log_consistency A consistency proof with one hash replaced. consistency_invalid