Skip to content

The masterdb command line

masterdb checks what MasterDB signs, from a terminal, on the TypeScript verifier. Node 24 or later.

Terminal window
npm install --global @masterdb/cli
Command Does
masterdb verify <file> Verifies a fetch response (the record’s bytes taken verbatim from its record member) or a verify request ({record_base64, seal, sidecar?}). With --context FILE (the business’s key register, certificates, AI policy history and mandates) it verifies offline; otherwise it asks POST /v1/verify and, given anchors, checks MasterDB’s signed statement. A receipt in the response is verified too.
masterdb verify --url URL Fetches the record first — signed with RFC 9421 (tag="mdb-retrieval") when --sign-key names a test key — then as above.
masterdb receipt <file> Shows a receipt (or the one in a response) and, given anchors, verifies it and the served rows beside it.
masterdb jwks Fetches /.well-known/keys and, given anchors, verifies the whole chain; --out saves it for offline use with --keys.
masterdb keygen Makes a test key (--alg ed25519 or es256), marked x-masterdb-test.
masterdb sign <record> Seals a record’s exact bytes with a test key (--cert-id, --ai-policy-version, --record-type, --sealed-at) and prints the seal envelope. It refuses any key without the test mark: a production key belongs in the business’s own signing system.

Trust comes only from anchors: --anchors FILE (a JSON array of root public keys), or the pinned set. Without anchors the tool says plainly that nothing was verified. --sandbox points at the sandbox and its anchors; --api at any deployment; --json prints machine-readable results.

Exit status: 0 verified, 1 a check failed, 2 a usage error — so it drops into a script or a CI step.