Test vectors
Both verifier libraries are held to the same files: good cases every verifier must accept, and a corpus of deliberately broken artefacts every verifier must refuse, for the reason named. If you write your own verifier, hold it to them too. All keys in them are test keys derived from public seeds; the anchors they trust are in context.json.
| File | Cases | What it holds |
|---|---|---|
context.json |
— | The shared context of every vector: trust anchors, MasterDB key sets, and one fictional business (key register, certificate history, AI policy history, mandates). All keys are TEST keys derived from public seeds. |
keysets.json |
3 | Signed key sets that every verifier must ACCEPT from the named anchors. |
certificates.json |
8 | ADL Certificates that every verifier must ACCEPT against the named key set. |
seals.json |
17 | Records and their seals that every verifier must ACCEPT, with the context of context.json (business keys, certificates, AI policy history, mandates); a case whose input carries certificates is checked against that certificate history instead of the context’s. Seal format 2 (seal.v2, batch-seal.v2: ai_policy_version) and format 1 (v1: terms_version) both verify. |
ai-policy.json |
4 | The ai_policy_bits a search row carries, each with the exact bytes of the sealed AI policy record a fetch returns (record_base64; null at version 0) and the fetch’s ai_policy.version: every verifier must ACCEPT these — the bits derived from the sealed booleans, blocked contexts bc1 to bc10 at bits 0 to 9, the purchase bit alone allowed to be withheld. |
rows.json |
5 | Served index rows that every verifier must ACCEPT against the production key set. |
receipts.json |
6 | Receipts that every verifier must ACCEPT against the production key set: format 3 (ai_policy_version rows), format 2 and format 1. |
mandates.json |
2 | Mandates that every verifier must ACCEPT, sealed by the business’s passkeys. |
merkle.json |
7 | RFC 6962 inclusion proofs that every verifier must ACCEPT. |
log.json |
4 | Transparency-log checkpoints, inclusion proofs (a seal leaf; a receipt, two-level) and a consistency proof that every verifier must ACCEPT, made by MasterDB’s log with the log_checkpoint key of the production key set. |
statements.json |
2 | MasterDB’s public statements that every verifier must ACCEPT against the production key set, each under its own payload type: the verify page’s signed JSON (kind verify_page, verify-page.v1) and the key directory (kind key_directory, key-directory.v1). |
projections.json |
— | Every projection version (adl_proj hash) a verifier of this release knows, with the fields its row signature leaves out. |
key-custody.json |
17 | Key custody statements (key-custody.v1): who holds each business key, hosted (MasterDB holds it for the business) or self, signed by the issuance key pair (P-256 and ML-DSA-65, both required) and published beside the certificate (GET /v1/certificates/{uuid}/key-custody). Kind key_custody checks one statement against the named key set; kind key_custody_seal checks a seal of the business of context.json with its key_custody (the route document or a list of envelopes) and names the custody of the seal key at sealed_at (unstated when no statement names it). expect.valid says whether each must be accepted or REFUSED for the reason named. |
broken.json |
106 | The broken-record corpus: every input here must be REFUSED, for the reason named (the reason codes are shared by every MasterDB verifier). |
The broken-record corpus
Section titled “The broken-record corpus”Every one of these 106 inputs must be refused with the reason in the last column.
| Case | Kind | What is wrong | Reason |
|---|---|---|---|
broken/seal/hosted-key-without-grant |
seal | A hosted-key seal whose sidecar’s resolved grant does not include publish.products. | out_of_scope |
broken/seal/hosted-key-checked-against-mandates |
seal | The same hosted-key seal judged as an integration key would be, against mandates: none covers it. | out_of_scope |
broken/seal/published-keys-by-sidecar-key |
seal | A published key list signed by a MasterDB key that is not the statement key. | key_unknown |
broken/seal/published-keys-edited |
seal | A published key list with a key removed after signing. | signature_invalid |
broken/seal/published-keys-another-business |
seal | Validly published keys of another business, offered for this business’s certificate. | key_unknown |
broken/seal/byte-flipped |
seal | One bit of the record flipped. | hash_mismatch |
broken/seal/re-serialised |
seal | The record parsed and re-serialised (same values, different bytes): a seal is over bytes, never over a re-serialisation. | hash_mismatch |
broken/seal/batch-member-re-serialised |
seal | A Path A record re-serialised: its leaf no longer proves into the sealed root. | inclusion_invalid |
broken/seal/key-swapped-in-payload |
seal | The payload’s key_id swapped for another registered key; the signature is over the original payload. | signature_invalid |
broken/seal/key-swapped-signer |
seal | Signed (validly) by one registered passkey while the payload names another. | key_mismatch |
broken/seal/key-swapped-keyid |
seal | The signature entry relabelled with another registered passkey’s key id. | signature_invalid |
broken/seal/unregistered-key |
seal | Sealed by a key that is not in the business’s register. | key_unknown |
broken/seal/payload-type |
seal | A seal envelope relabelled as a receipt. | payload_type_mismatch |
broken/seal/unknown-member |
seal | An envelope member DSSE does not define. | envelope_malformed |
broken/seal/unknown-seal-version |
seal | A seal payload of v 3, validly signed: a verifier refuses a version it does not know rather than guessing. | version_unknown |
broken/seal/format-2-payload-under-v1-type |
seal | A v 2 payload (ai_policy_version) signed under the format 1 payload type (seal.v1): the payload and its type disagree. | payload_malformed |
broken/seal/format-1-member-under-v2 |
seal | A seal.v2 payload of v 2 that still names terms_version: format 2 names the version ai_policy_version. | payload_malformed |
broken/seal/unknown-ai-policy-schema |
seal | A validly sealed AI policy record at an ai_policy_schema this verifier does not know (3). | version_unknown |
broken/seal/unknown-record-schema |
seal | A validly sealed record whose schema version is unknown (masterdb/products/9). | version_unknown |
broken/seal/record-type-mismatch |
seal | A product record sealed as an event. | record_type_mismatch |
broken/seal/duplicate-payload-key |
seal | A validly signed seal payload with a duplicated member (parsers disagree on which wins, so it is never read). | payload_malformed |
broken/seal/expired-certificate |
seal | Sealed on 12 October naming the certificate, after the revocation that took effect on 10 October: not in force at sealed_at. | certificate_not_in_force |
broken/seal/names-revoked-certificate |
seal | A seal naming the revoked issuance itself. | certificate_not_in_force |
broken/seal/after-withdrawal |
seal | Sealed on 12 October naming the certificate, after MasterDB withdrew it (a reversed approval) with effect from 10 October: refused as withdrawn, not as a compromise. | certificate_withdrawn |
broken/seal/names-withdrawn-certificate |
seal | A seal naming the withdrawn issuance itself. | certificate_withdrawn |
broken/seal/unknown-certificate |
seal | A seal naming a certificate that was never issued. | certificate_unknown |
broken/seal/wrong-ai-policy-version |
seal | Sealed on 1 October binding AI policy version 2, which went live on 5 October. | ai_policy_version_mismatch |
broken/seal/format-1-wrong-terms-version |
seal | A format 1 seal binding terms_version 2 on 1 October, before version 2 went live: refused for the same reason. | ai_policy_version_mismatch |
broken/seal/ai-policy-record-wrong-version |
seal | An AI policy record’s seal naming a version it cannot create (5). | ai_policy_version_mismatch |
broken/seal/out-of-scope-country |
seal | A pushed record for France under a mandate for the US and Ireland only. | out_of_scope |
broken/seal/out-of-scope-type |
seal | An integration key sealing an events document under a products-only mandate. | out_of_scope |
broken/seal/out-of-scope-mandate-expired |
seal | Sealed on 9 October, after the key’s mandate ended on 8 October. | out_of_scope |
broken/seal/sidecar-format-mismatch |
seal | A v 2 sidecar signed under the format 1 sidecar type (sidecar.v1). | payload_malformed |
broken/seal/out-of-scope-grant |
seal | Path B: the sidecar says the person’s grant at acceptance did not include publish.products. | out_of_scope |
broken/seal/revoked-key |
seal | Sealed on 30 September with a passkey revoked with effect from 25 September. | key_not_valid |
broken/seal/webauthn-wrong-origin |
seal | A passkey assertion made on an origin outside the allow-list. | signature_invalid |
broken/seal/webauthn-sign-in-challenge |
seal | A sign-in assertion (“mdb-signin” || nonce) replayed as a seal. | signature_invalid |
broken/seal/webauthn-no-user-verification |
seal | A passkey assertion without the user-verification flag. | signature_invalid |
broken/seal/webauthn-rs256-signature-flipped |
seal | An RS256 passkey seal with one bit of its RSA signature flipped. | signature_invalid |
broken/seal/webauthn-rs256-relabelled-es256 |
seal | An RS256 passkey assertion relabelled with an ES256 passkey’s key id (and the payload’s key_id left as the RS256 key’s). | signature_invalid |
broken/seal/batch-proof-tampered |
seal | A Path A record whose inclusion proof was altered. | inclusion_invalid |
broken/seal/batch-wrong-leaf-index |
seal | A Path A record presented at another leaf index. | inclusion_invalid |
broken/ai-policy/blocked-bit-cleared |
ai_policy | Served bits with a blocked context the business set (bc8 politics_elections) cleared. | ai_policy_bits_mismatch |
broken/ai-policy/blocked-bit-added |
ai_policy | Served bits with a blocked context the business never set (bc1). | ai_policy_bits_mismatch |
broken/ai-policy/action-widened |
ai_policy | Served bits granting reserve (action bit 2), which the sealed record does not. | ai_policy_bits_mismatch |
broken/ai-policy/wrong-version |
ai_policy | Bits naming a version other than the fetched record’s. | ai_policy_bits_mismatch |
broken/ai-policy/wrong-schema |
ai_policy | Bits claiming ai_policy_schema 1 for a schema 2 record (so the blocked contexts would be read as absent). | ai_policy_bits_mismatch |
broken/ai-policy/version-0-with-bits |
ai_policy | No sealed AI policy (version 0), yet bits that permit answering. | ai_policy_bits_mismatch |
broken/mandate/scope-widened |
mandate | The mandate’s countries widened after it was sealed. | signature_invalid |
broken/mandate/sealed-by-integration-key |
mandate | A mandate signed by the machine key itself: a mandate is a person’s act, sealed by a passkey. | key_unknown |
broken/entitlement/expired |
entitlement | The same entitlement checked twenty minutes after it was issued: it lapsed at expires. | entitlement_expired |
broken/entitlement/other-vendor |
entitlement | An entitlement presented to another AI company. | entitlement_invalid |
broken/entitlement/other-listing |
entitlement | An entitlement for another of the vendor’s listings. | entitlement_invalid |
broken/entitlement/seat-changed |
entitlement | The seat changed after signing. | signature_invalid |
broken/entitlement/signed-by-statement-key |
entitlement | An entitlement signed by the verify statement key, which may not issue entitlements. | key_unknown |
broken/entitlement/extra-member |
entitlement | A validly signed entitlement carrying a member the format does not have. | payload_malformed |
broken/statement/key-directory-as-verify-page |
verify_page | A genuine key directory offered where a verify page is expected. | payload_type_mismatch |
broken/statement/verify-page-as-key-directory |
key_directory | A genuine verify page offered where the key directory is expected. | payload_type_mismatch |
broken/statement/verify-page-as-verify-statement |
verify_page | The verify page’s answer in its first form: a verify-statement.v1 (the type of POST /v1/verify’s answer) told apart by a kind member. | payload_type_mismatch |
broken/statement/key-directory-as-verify-statement |
key_directory | The key directory in its first form: a verify-statement.v1 told apart by a kind member. | payload_type_mismatch |
broken/statement/verify-page-kind-member |
verify_page | A validly signed verify-page.v1 still carrying the kind member the format no longer has. | payload_malformed |
broken/statement/verify-page-verdict-changed |
verify_page | A verify page whose signed verdict was flipped from valid to not valid after signing. | signature_invalid |
broken/statement/key-directory-by-sidecar-key |
key_directory | A key directory signed by a MasterDB key that is not the statement key. | key_unknown |
broken/certificate/tampered |
certificate | The legal name changed after signing. | signature_invalid |
broken/certificate/signed-by-working-key |
certificate | A certificate signed by the sidecar key, which may not issue certificates. | key_unknown |
broken/certificate/sandbox-under-production |
certificate | A sandbox certificate checked against the production anchors. | key_unknown |
broken/certificate/reason-on-active |
certificate | A validly signed active certificate carrying a status_reason, which only a withdrawn issuance has. | payload_malformed |
broken/certificate/unknown-member |
certificate | The format is closed. A validly signed certificate with a member that is not in the format (here extra_member) is refused; a new member is a new format. | payload_malformed |
broken/certificate/unknown-version |
certificate | A validly signed certificate of format v 2. | version_unknown |
broken/certificate/classical-only |
certificate | An ADL Certificate is hybrid-signed (P-256 and ML-DSA-65, both required): one carrying only the P-256 signature is refused. | post_quantum_required |
broken/certificate/ml-dsa-only |
certificate | A certificate carrying only the ML-DSA-65 signature of the issuance key is refused, however valid that signature. | post_quantum_required |
broken/certificate/two-classical-signatures |
certificate | Two signatures, but not the two halves: a second signature by a root key (which does not issue certificates) is ignored, so the certificate still lacks its ML-DSA-65 half. | post_quantum_required |
broken/keyset/wrong-anchors |
keyset | The production key set checked against anchors that are not MasterDB’s. | trust_chain_broken |
broken/keyset/compromise-mark-removed |
keyset | The compromised_from mark removed from the signed payload. | signature_invalid |
broken/keyset/key-without-certificate |
keyset | A validly signed set listing a key with no certificate chaining to the anchors. | trust_chain_broken |
broken/keyset/classical-only |
keyset | The key set is hybrid-signed: one signed by the P-256 issuance key alone is refused. | post_quantum_required |
broken/keyset/ml-dsa-only |
keyset | A key set signed by the ML-DSA-65 issuance half alone (all else genuine) is refused. | post_quantum_required |
broken/keyset/key-certified-by-ml-dsa-only |
keyset | A set listing a receipt key whose key certificate carries only the ML-DSA-65 issuance signature. The key is not trusted; the whole set is refused. | post_quantum_required |
broken/keyset/key-certified-by-classical-only |
keyset | A set listing a receipt key whose key certificate carries only the P-256 issuance signature: refused. | post_quantum_required |
broken/keyset/successor-root-certified-by-classical-only |
keyset | A successor root certified by the old root P-256 key alone: it is not trusted, and nothing certified under it is. | post_quantum_required |
broken/row/v3-ai-policy-version-changed |
row | A v3 row whose signed ai_policy_version was changed. | row_signature_invalid |
broken/row/v2-price-changed |
row | A v2 row whose US price changed. | row_signature_invalid |
broken/row/v2-under-v1-rules |
row | A v2 row relabelled as a v1 row: the adl_proj is part of the signed bytes, so the signature no longer verifies. | row_signature_invalid |
broken/row/price-changed |
row | The US price on a served row changed. | row_signature_invalid |
broken/row/unknown-projection |
row | A row naming a projection version nobody published. | projection_unknown |
broken/row/signed-by-receipt-key |
row | A row signed by a MasterDB key that is not a projection key. | key_unknown |
broken/receipt/row-changed |
receipt | The receipt’s row origin changed after signing (“you served me the old price”). | signature_invalid |
broken/receipt/expired-key |
receipt | Signed at 09:30 on 1 October by a receipt key whose window ended at midnight. | key_not_valid |
broken/receipt/compromised-key |
receipt | Signed after the receipt key’s compromised_from. | key_compromised |
broken/receipt/signed-by-projection-key |
receipt | A receipt signed by a MasterDB key that is not a receipt key. | key_unknown |
broken/receipt/v2-another-caller |
receipt | A leaked format 2 receipt presented by a caller it was not issued to. | receipt_caller_mismatch |
broken/receipt/v1-when-caller-required |
receipt | A format 1 receipt where the checker requires the caller to be named (it names none). | receipt_caller_mismatch |
broken/receipt/v2-without-caller |
receipt | Format 2 claimed without caller_key_id. | payload_malformed |
broken/receipt/v3-terms-version-row |
receipt | Format 3 claimed with a row still naming terms_version. | payload_malformed |
broken/receipt/v2-ai-policy-version-row |
receipt | Format 2 claimed with rows naming ai_policy_version, which only format 3 has. | payload_malformed |
broken/receipt/v3-without-caller |
receipt | Format 3 claimed without caller_key_id. | payload_malformed |
broken/receipt/other-region |
receipt | A receipt claiming one region, signed by another region’s receipt key. | key_unknown |
broken/receipt/served-row-differs |
receipt | A genuine receipt, checked against a served row whose origin differs from what the receipt says was served. | receipt_row_mismatch |
broken/merkle/wrong-tree-size |
merkle | A genuine proof checked against a tree size other than the one that was signed. | inclusion_invalid |
broken/log/checkpoint-size-changed |
checkpoint | A checkpoint whose tree size was changed after signing. | checkpoint_invalid |
broken/log/checkpoint-other-origin |
checkpoint | A note validly signed by the log key for another origin. | checkpoint_invalid |
broken/log/checkpoint-unknown-key |
checkpoint | A checkpoint signed by a key named masterdb-log that is not the log key. | checkpoint_invalid |
broken/log/inclusion-wrong-index |
log_inclusion | A genuine seal-leaf proof presented at another leaf index. | inclusion_invalid |
broken/log/receipt-minute-size |
log_inclusion | A receipt proof whose minute-tree size was changed: the first level no longer verifies. | inclusion_invalid |
broken/log/consistency-wrong-older |
log_consistency | A consistency proof checked against a different older checkpoint (the newer one itself as older). | checkpoint_invalid |
broken/log/consistency-tampered |
log_consistency | A consistency proof with one hash replaced. | consistency_invalid |