Auditor kit

Check a customer's evidence yourself, offline, without trusting CAIN. You need Python 3.9 or newer and the cryptography package. The three scripts below import nothing from CAIN.

1. Get the pack from the customer

The customer exports their own evidence with their API key:

curl -X POST https://cainstudio.online/fabric/scitt/auditor-pack \
  -H "X-API-Key: $CAIN_API_KEY" -H "Content-Type: application/json" \
  -d '{"since_tree_size": 0}' -o pack.json

For a follow-up audit, set since_tree_size to the tree_size of the checkpoint you kept last time.

2. Pin the keys yourself

Get the notary keys from GET /fabric/scitt/keys and the contract root key from GET /fabric/contracts/trust, ideally out of band. Keep them. If you don't pin them, the result says SELF_ASSERTED: that shows the pack is internally consistent, not who signed it.

3. Verify

python3 auditor_pack_verify.py pack.json --scitt-keys keys.json --root-key BASE64 \
  [--previous-checkpoint last_checkpoint.json]

Downloads (keep all three in one folder):

Checksums are in MANIFEST.json. The publisher countersignature is in _publisher/auditor-kit.json.

What it checks

What it does not prove

That the recorded events are true. It proves the evidence was not altered or rewritten after it was logged. It is not a certification. The same operator runs the log; there are no external witnesses yet.