Commands & protocol
The full command surface, the stdout directives K-Veritas recognizes, and platform support.
CLI commands
| kveritas init [--local] [--harness] | Start a session. |
| --disclosure redacted|names|open | How much the report reveals (default redacted). |
| --show-names | Keep real file names (same as --disclosure names). |
| kveritas run [--files f1,f2] -- <cmd> | Wrap and record an experiment run. |
| kveritas seal [-o path] | Sign the session into a report (plus bundle at open). Waits until every run has reached the server. |
| kveritas verify <report.pdf | session.json | proof.json> | Auto-detects the type. A report gets local crypto checks plus the full server audit; an agent session or a proof is verified directly. |
| --bundle <bundle.kvbundle.zip> | Also confirm the code matches and run the AI code audit. |
| --paper <manuscript.pdf> | Also crosscheck the paper's claims against the sealed telemetry. |
| --offline | Local checks only, no network. |
| kveritas prove <report.pdf> <file> [file...] | Prove one or more files were in a signed snapshot (one self-contained proof). |
| kveritas verify-proof <proof.json> | Check a self-contained proof (or pass the report too). |
| kveritas record --type <t> --input <s> --output <s> | Append one agent action to the session chain (--hook pre|post|prompt for Claude Code). |
| kveritas harness-prove <session.json> <index | --tool-use-id ID> | Prove one recorded prompt or output (--input / --output-content) was in a signed agent session, revealing nothing else. |
| kveritas verify-harness-proof <proof.json> | Check a harness prompt/output proof: chain authentic and the revealed content matches its committed hash. |
| kveritas checkout <bundle> <[run:]snapshot> <dir> [--report r.pdf] | Reconstruct a snapshot's files. |
| kveritas check --claims c.json --report r.pdf | Check paper claims against a report. |
| kveritas generate-claims --report r.pdf | Derive a claims file from a report. |
| kveritas status | Show the session state. Sends any queued run anchors. |
| kveritas update | Self-update the CLI. |
| kveritas clean | Remove the session directory. |
Protocol lines
K-Veritas recognizes these directives when printed to stdout, in any language. Everything captured this way is bound into the signed record.
| KVERITAS_METRIC name=<id> value=<float> [step=<label>] | Record a metric. |
| KVERITAS_PHASE name=<phase> | Mark a phase boundary (snapshot + hardware). |
| KVERITAS_CLAIM metric=<id> value=<float> [phase=<phase>] | Commit an inline claim. |
| KVERITAS_INPUT src=seed:<value> | Commit a seed. |
| KVERITAS_MODEL params=<int> arch=<name> precision=<fp16|bf16|fp32> | Declare the model card. |
| KVERITAS_WORKLOAD dataset_size=<int> epochs=<float> batch_size=<int> [seq_len=<int>] | Declare the workload. |
| KVERITAS_ARTIFACT role=model|dataset [name=<ref>] path=<file> visibility=public|private | Attest a model or dataset. |
Verification layers
verify first runs local checks that need no account: the data hash, the RSA-PSS signature, the visual PDF hash, the provenance chain, and (for an agent session) the server-signed genesis, the full hash chain, and the server-signed seal, pointing any inconsistency to the exact entry.
By default it then runs the full server audit, the same checks the web verifier performs: the ledger confirmation that the server signed this exact hash, the run anchors, hardware consistency (HMCA), and, when you pass --bundle or --paper, the source-bundle match, the AI code audit, and the paper crosscheck. Add --offline to skip the server and verify locally only.
Authenticity vs self-attested
A valid signature proves a report was not modified, but not who produced it. K-Veritas checks the signing key against its own key: a report signed by the server reads VERIFIED, while a report signed with any other key (for example a --local self-signing key) reads SELF-ATTESTED, a valid signature whose origin cannot be confirmed. Only a VERIFIED report is evidence that the results came through K-Veritas.
The transparency ledger records every hash the server has signed as a hash chain: each entry commits to the one before it, so a recorded entry cannot be altered, reordered, or removed without breaking the chain. The audit reports whether a report's hash is in the ledger.
Run anchors
When a run ends, its digest goes to the server. From then on the run cannot change: the seal is refused if it does, and verify flags it.
No connection? The run still finishes. The digest waits on disk and is sent later, and the report shows how long the run went unwitnessed. Failed and interrupted runs are counted too.
Platform support
| Verify / seal / proofs / checkout / benchmarks | Cross-platform (Linux, macOS, Windows). |
| Provenance timeline & disclosure levels | Cross-platform. |
| Activity map (file reads/writes, subprocesses) | Linux only. macOS / Windows: coming. |
| Per-process hardware & HMCA attribution | Linux only. Falls back to system-wide elsewhere; per-OS support coming. |