Home / Code
Illustrative, non-normative
Code examples
Minimal, dependency-light examples of the primitives VAP composes: canonical hashing, chained events, Ed25519 signatures, Merkle proofs, and RFC 3161 anchoring. Field names are illustrative — consult the specification for the normative schema, and GitHub for reference implementations.
1 · The shape of an event
{
"event_id": "0198f3a2-7c1e-7d2a-9b1e-2f6a0c9d4e11",
"event_type": "DECISION_MADE",
"occurred_at": "2026-08-19T02:14:07.412Z",
"actor": { "actor_id": "model:risk-scorer", "actor_class": "AI_SYSTEM" },
"policy": { "policy_id": "POL-2026-014" },
"payload_hash": "sha256:9f2b…c41a",
"prev_hash": "sha256:5d80…7e0c",
"event_hash": "sha256:b7a1…22f9",
"signature": { "alg": "Ed25519", "key_id": "op-2026-01", "value": "…" }
}
2 · Chain and sign events (Python)
Canonical JSON → SHA-256 → prev_hash chaining → Ed25519 signature
(pip install cryptography).
"""Illustrative, non-normative. Consult VAP v1.2 for the normative schema."""
import json, hashlib
from cryptography.hazmat.primitives.asymmetric.ed25519 import Ed25519PrivateKey
def canonical(obj) -> bytes:
return json.dumps(obj, sort_keys=True, separators=(",", ":"),
ensure_ascii=False).encode()
def sha256_hex(b: bytes) -> str:
return "sha256:" + hashlib.sha256(b).hexdigest()
key = Ed25519PrivateKey.generate()
def append_event(chain: list, body: dict) -> dict:
prev = chain[-1]["event_hash"] if chain else "sha256:" + "0" * 64
core = {**body, "prev_hash": prev}
event_hash = sha256_hex(canonical(core))
sig = key.sign(event_hash.encode()).hex()
event = {**core, "event_hash": event_hash,
"signature": {"alg": "Ed25519", "value": sig}}
chain.append(event)
return event
def verify_chain(chain: list) -> bool:
prev = "sha256:" + "0" * 64
for ev in chain:
core = {k: v for k, v in ev.items()
if k not in ("event_hash", "signature")}
if ev["prev_hash"] != prev: return False
if sha256_hex(canonical(core)) != ev["event_hash"]: return False
prev = ev["event_hash"]
return True
3 · Merkle root and inclusion proof (Python)
import hashlib
def h(b: bytes) -> bytes: return hashlib.sha256(b).digest()
def merkle_root(leaves: list[bytes]) -> bytes:
level = [h(l) for l in leaves]
while len(level) > 1:
if len(level) % 2: level.append(level[-1]) # duplicate last
level = [h(level[i] + level[i+1]) for i in range(0, len(level), 2)]
return level[0]
def verify_inclusion(leaf: bytes, proof: list[tuple[str, bytes]],
root: bytes) -> bool:
node = h(leaf)
for side, sib in proof: # side: "L" | "R"
node = h(sib + node) if side == "L" else h(node + sib)
return node == root
4 · External anchoring with RFC 3161 (shell)
Anchoring the signed batch root with a public time-stamping authority satisfies the lightweight end of INT-006. Keep the request, response, and TSA certificate in the Evidence Pack.
# Anchor a signed Merkle root with an RFC 3161 time-stamping authority
openssl ts -query -data anchor_root.bin -sha256 -cert -out req.tsq
curl -s -H "Content-Type: application/timestamp-query" \
--data-binary @req.tsq https://tsa.example.org/ -o resp.tsr
openssl ts -reply -in resp.tsr -text # inspect the token
# Keep req.tsq + resp.tsr + the TSA certificate in the Evidence Pack
5 · What a verifier checks
- Recompute event hashes from canonical JSON and compare.
- Walk the chain — every
prev_hashmatches its predecessor; no unexplained breaks. - Check signatures (Ed25519 / RFC 8032) against registered operator keys.
- Verify Merkle inclusion of each event in its batch root.
- Validate the anchor — RFC 3161 token (or transparency-log proof) over the signed root.
- Check INT-008 bindings — event count, first/last event IDs, and policy identifier declared in the AnchorRecord match what is presented. A mismatch is omission / split-view evidence.
A passing verification means the records are intact, complete at anchor granularity, and attributable. Per §1.6, it says nothing about whether the underlying decisions were correct, fair, or safe.