Reference

Commands & protocol

The full command surface, the stdout directives K-Veritas recognizes, and platform support.

CLI commands

kveritas init [--local] [--harness]Start a session.
--disclosure redacted|names|openHow much the report reveals (default redacted).
--show-namesKeep real file names (same as --disclosure names).
kveritas run [--files f1,f2] -- <cmd>Wrap and record an experiment run.
kveritas seal [-o path]Sign the session into a report (plus bundle at open). Waits until every run has reached the server.
kveritas verify <report.pdf | session.json | proof.json>Auto-detects the type. A report gets local crypto checks plus the full server audit; an agent session or a proof is verified directly.
--bundle <bundle.kvbundle.zip>Also confirm the code matches and run the AI code audit.
--paper <manuscript.pdf>Also crosscheck the paper's claims against the sealed telemetry.
--offlineLocal checks only, no network.
kveritas prove <report.pdf> <file> [file...]Prove one or more files were in a signed snapshot (one self-contained proof).
kveritas verify-proof <proof.json>Check a self-contained proof (or pass the report too).
kveritas record --type <t> --input <s> --output <s>Append one agent action to the session chain (--hook pre|post|prompt for Claude Code).
kveritas harness-prove <session.json> <index | --tool-use-id ID>Prove one recorded prompt or output (--input / --output-content) was in a signed agent session, revealing nothing else.
kveritas verify-harness-proof <proof.json>Check a harness prompt/output proof: chain authentic and the revealed content matches its committed hash.
kveritas checkout <bundle> <[run:]snapshot> <dir> [--report r.pdf]Reconstruct a snapshot's files.
kveritas check --claims c.json --report r.pdfCheck paper claims against a report.
kveritas generate-claims --report r.pdfDerive a claims file from a report.
kveritas statusShow the session state. Sends any queued run anchors.
kveritas updateSelf-update the CLI.
kveritas cleanRemove the session directory.

Protocol lines

K-Veritas recognizes these directives when printed to stdout, in any language. Everything captured this way is bound into the signed record.

KVERITAS_METRIC name=<id> value=<float> [step=<label>]Record a metric.
KVERITAS_PHASE name=<phase>Mark a phase boundary (snapshot + hardware).
KVERITAS_CLAIM metric=<id> value=<float> [phase=<phase>]Commit an inline claim.
KVERITAS_INPUT src=seed:<value>Commit a seed.
KVERITAS_MODEL params=<int> arch=<name> precision=<fp16|bf16|fp32>Declare the model card.
KVERITAS_WORKLOAD dataset_size=<int> epochs=<float> batch_size=<int> [seq_len=<int>]Declare the workload.
KVERITAS_ARTIFACT role=model|dataset [name=<ref>] path=<file> visibility=public|privateAttest a model or dataset.

Verification layers

verify first runs local checks that need no account: the data hash, the RSA-PSS signature, the visual PDF hash, the provenance chain, and (for an agent session) the server-signed genesis, the full hash chain, and the server-signed seal, pointing any inconsistency to the exact entry.

By default it then runs the full server audit, the same checks the web verifier performs: the ledger confirmation that the server signed this exact hash, the run anchors, hardware consistency (HMCA), and, when you pass --bundle or --paper, the source-bundle match, the AI code audit, and the paper crosscheck. Add --offline to skip the server and verify locally only.

Authenticity vs self-attested

A valid signature proves a report was not modified, but not who produced it. K-Veritas checks the signing key against its own key: a report signed by the server reads VERIFIED, while a report signed with any other key (for example a --local self-signing key) reads SELF-ATTESTED, a valid signature whose origin cannot be confirmed. Only a VERIFIED report is evidence that the results came through K-Veritas.

The transparency ledger records every hash the server has signed as a hash chain: each entry commits to the one before it, so a recorded entry cannot be altered, reordered, or removed without breaking the chain. The audit reports whether a report's hash is in the ledger.

Run anchors

When a run ends, its digest goes to the server. From then on the run cannot change: the seal is refused if it does, and verify flags it.

No connection? The run still finishes. The digest waits on disk and is sent later, and the report shows how long the run went unwitnessed. Failed and interrupted runs are counted too.

Platform support

Verify / seal / proofs / checkout / benchmarksCross-platform (Linux, macOS, Windows).
Provenance timeline & disclosure levelsCross-platform.
Activity map (file reads/writes, subprocesses)Linux only. macOS / Windows: coming.
Per-process hardware & HMCA attributionLinux only. Falls back to system-wide elsewhere; per-OS support coming.