ATEP

Quick start

Each snippet verifies the same test vector, vectors/verify-positive/signed-trust-doc-inline-bundle.cbor, at the reference time 1800000000. Run from the root of the ATEP repository. Build from the repository. Do not install from a package registry: the names crates.io atep, atep-core and atep-cli, npm @atep/core and @atep/mcp, and PyPI atep are reserved 0.0.1 placeholders that contain no functional code.

Rust CLI

cd rust
cargo build --release -p atep-cli
./target/release/atep verify \
  -i ../vectors/verify-positive/signed-trust-doc-inline-bundle.cbor \
  --now 1800000000

Prints OK, the signer Agent ID and the envelope fields. Building needs a C compiler or linker.

JavaScript

cd js
npm install
npm run build        # needs wasm-bindgen-cli 0.2.129 and the wasm32 target, see js/README.md
node -e 'import("./dist/index.js").then(async m => { await m.init();
  const b = require("fs").readFileSync(
    "../vectors/verify-positive/signed-trust-doc-inline-bundle.cbor");
  console.log(m.verify(new Uint8Array(b), {}, { now: 1800000000 })); })'

Prints { ok: true, signer: 'atep:...' }. The package is the Rust core compiled to WebAssembly. Node 18 or later; other runtimes are untested.

Python

cd python
python3 -c "
import json
from atep_py.verify import verify_json
n = '../vectors/verify-positive/signed-trust-doc-inline-bundle'
v = json.load(open(n + '.expected.json'))
print(verify_json(open(n + '.cbor', 'rb').read(), v['inputs']['policy']))"

Standard library only, Python 3.8 or later. python3 -m atep_py.vectors check ../vectors runs 431 of the 436 vectors (it skips by name the five for a log and a monitor) and takes about 30 seconds.

A rejection

./target/release/atep verify -i ../vectors/verify-negative/bad-eddsa-signature.cbor --now 1800000000
REJECTED at step 4 (eddsa_signature_invalid): signature does not verify

Rejections name the step of the ten step algorithm and a stable error code. Data envelopes must be encrypted, so the verification of data vectors also needs the recipient keys that each vector lists. See test vectors.

To see a rejection without installing anything, open the live simulator (opens in a new tab): four simulated units exchange real envelopes in your browser; one is revoked mid-run and refused at a named step, and you can take the fleet controller offline to see certified members keep verifying each other.