VAP · veritaschain.org

Home / Code

Illustrative, non-normative

Code examples

Minimal, dependency-light examples of the primitives VAP composes: canonical hashing, chained events, Ed25519 signatures, Merkle proofs, and RFC 3161 anchoring. Field names are illustrative — consult the specification for the normative schema, and GitHub for reference implementations.

1 · The shape of an event

{
  "event_id":  "0198f3a2-7c1e-7d2a-9b1e-2f6a0c9d4e11",
  "event_type": "DECISION_MADE",
  "occurred_at": "2026-08-19T02:14:07.412Z",
  "actor": { "actor_id": "model:risk-scorer", "actor_class": "AI_SYSTEM" },
  "policy": { "policy_id": "POL-2026-014" },
  "payload_hash": "sha256:9f2b…c41a",
  "prev_hash":  "sha256:5d80…7e0c",
  "event_hash": "sha256:b7a1…22f9",
  "signature": { "alg": "Ed25519", "key_id": "op-2026-01", "value": "…" }
}

2 · Chain and sign events (Python)

Canonical JSON → SHA-256 → prev_hash chaining → Ed25519 signature (pip install cryptography).

"""Illustrative, non-normative. Consult VAP v1.2 for the normative schema."""
import json, hashlib
from cryptography.hazmat.primitives.asymmetric.ed25519 import Ed25519PrivateKey

def canonical(obj) -> bytes:
    return json.dumps(obj, sort_keys=True, separators=(",", ":"),
                      ensure_ascii=False).encode()

def sha256_hex(b: bytes) -> str:
    return "sha256:" + hashlib.sha256(b).hexdigest()

key = Ed25519PrivateKey.generate()

def append_event(chain: list, body: dict) -> dict:
    prev = chain[-1]["event_hash"] if chain else "sha256:" + "0" * 64
    core = {**body, "prev_hash": prev}
    event_hash = sha256_hex(canonical(core))
    sig = key.sign(event_hash.encode()).hex()
    event = {**core, "event_hash": event_hash,
             "signature": {"alg": "Ed25519", "value": sig}}
    chain.append(event)
    return event

def verify_chain(chain: list) -> bool:
    prev = "sha256:" + "0" * 64
    for ev in chain:
        core = {k: v for k, v in ev.items()
                if k not in ("event_hash", "signature")}
        if ev["prev_hash"] != prev:                       return False
        if sha256_hex(canonical(core)) != ev["event_hash"]: return False
        prev = ev["event_hash"]
    return True

3 · Merkle root and inclusion proof (Python)

import hashlib

def h(b: bytes) -> bytes: return hashlib.sha256(b).digest()

def merkle_root(leaves: list[bytes]) -> bytes:
    level = [h(l) for l in leaves]
    while len(level) > 1:
        if len(level) % 2: level.append(level[-1])     # duplicate last
        level = [h(level[i] + level[i+1]) for i in range(0, len(level), 2)]
    return level[0]

def verify_inclusion(leaf: bytes, proof: list[tuple[str, bytes]],
                     root: bytes) -> bool:
    node = h(leaf)
    for side, sib in proof:                            # side: "L" | "R"
        node = h(sib + node) if side == "L" else h(node + sib)
    return node == root

4 · External anchoring with RFC 3161 (shell)

Anchoring the signed batch root with a public time-stamping authority satisfies the lightweight end of INT-006. Keep the request, response, and TSA certificate in the Evidence Pack.

# Anchor a signed Merkle root with an RFC 3161 time-stamping authority
openssl ts -query -data anchor_root.bin -sha256 -cert -out req.tsq
curl -s -H "Content-Type: application/timestamp-query" \
     --data-binary @req.tsq https://tsa.example.org/ -o resp.tsr
openssl ts -reply -in resp.tsr -text        # inspect the token
# Keep req.tsq + resp.tsr + the TSA certificate in the Evidence Pack

5 · What a verifier checks

  1. Recompute event hashes from canonical JSON and compare.
  2. Walk the chain — every prev_hash matches its predecessor; no unexplained breaks.
  3. Check signatures (Ed25519 / RFC 8032) against registered operator keys.
  4. Verify Merkle inclusion of each event in its batch root.
  5. Validate the anchor — RFC 3161 token (or transparency-log proof) over the signed root.
  6. Check INT-008 bindings — event count, first/last event IDs, and policy identifier declared in the AnchorRecord match what is presented. A mismatch is omission / split-view evidence.

A passing verification means the records are intact, complete at anchor granularity, and attributable. Per §1.6, it says nothing about whether the underlying decisions were correct, fair, or safe.