TypeScript: @dnsid-ai/log-c2sp-tlog — functions
Part of Transparency log (@dnsid-ai/log-c2sp-tlog).
Functions
Section titled “Functions”advanceTrustedC2spCheckpoint()
Section titled “advanceTrustedC2spCheckpoint()”function advanceTrustedC2spCheckpoint( store, reference, checkpoint, witnessTime, options?): Promise<TrustedC2spCheckpoint>;Defined in: packages/log-c2sp-tlog/src/checkpoint-trust.ts:70
Advances the stored trusted checkpoint for a log origin to checkpoint,
guarding against split-view and rollback attacks: a same-size checkpoint
must have the same root, and a larger one must be proven consistent by a
consistency proof or a complete scan matching both checkpoint prefixes.
Parameters
Section titled “Parameters”reference
Section titled “reference”checkpoint
Section titled “checkpoint”witnessTime
Section titled “witnessTime”Date
options?
Section titled “options?”VerificationOptions & object = {}
Returns
Section titled “Returns”Promise<TrustedC2spCheckpoint>
A defensive copy of the newly trusted checkpoint.
Throws
Section titled “Throws”C2spTlogVerificationError on origin mismatch, rollback, root divergence, or missing/invalid consistency evidence.
assertCanonicalJsonBytes()
Section titled “assertCanonicalJsonBytes()”function assertCanonicalJsonBytes(bytes, value?): void;Defined in: packages/log-c2sp-tlog/src/canonical.ts:73
Asserts that bytes are exactly the canonical JSON serialization of value
(which defaults to the parsed content of bytes).
Parameters
Section titled “Parameters”Uint8Array
value?
Section titled “value?”unknown = ...
Returns
Section titled “Returns”void
Throws
Section titled “Throws”C2spTlogParseError when the bytes are not canonical.
c2spEnvelopeToEvent()
Section titled “c2spEnvelopeToEvent()”function c2spEnvelopeToEvent(obj): Promise<LogEvent>;Defined in: packages/log-c2sp-tlog/src/event-codec.ts:93
Converts a parsed c2sp-tlog JSON envelope back into a protocol
LogEvent, requiring a complete sigs object and consistent embedded
key material (distinct entity/operational keys, matching signature kids).
Parameters
Section titled “Parameters”unknown
Returns
Section titled “Returns”Promise<LogEvent>
Throws
Section titled “Throws”C2spTlogParseError when the envelope is malformed or inconsistent.
c2spEventId()
Section titled “c2spEventId()”function c2spEventId(signedBytes): string;Defined in: packages/log-c2sp-tlog/src/event-codec.ts:8
Logical ID of canonical signed bytes; signatures and Merkle indexes are excluded.
Parameters
Section titled “Parameters”signedBytes
Section titled “signedBytes”Uint8Array
Returns
Section titled “Returns”string
c2spTlogEntryBytes()
Section titled “c2spTlogEntryBytes()”function c2spTlogEntryBytes(prepared, context?): Promise<Uint8Array<ArrayBufferLike>>;Defined in: packages/log-c2sp-tlog/src/writer.ts:179
Finalizes a fully signed prepared event into its canonical log entry bytes, re-verifying all required signatures and the entry’s parseability.
Parameters
Section titled “Parameters”prepared
Section titled “prepared”context?
Section titled “context?”PreparedC2spVerificationContext = {}
Returns
Section titled “Returns”Promise<Uint8Array<ArrayBufferLike>>
Throws
Section titled “Throws”C2spTlogVerificationError when a required signature is missing or invalid.
Throws
Section titled “Throws”C2spTlogParseError when the entry is malformed or oversized.
canonicalBytes()
Section titled “canonicalBytes()”function canonicalBytes(value): Uint8Array;Defined in: packages/log-c2sp-tlog/src/canonical.ts:48
UTF-8 encoding of canonicalJson.
Parameters
Section titled “Parameters”unknown
Returns
Section titled “Returns”Uint8Array
canonicalizeC2spEvent()
Section titled “canonicalizeC2spEvent()”function canonicalizeC2spEvent(event, context?): Uint8Array;Defined in: packages/log-c2sp-tlog/src/event-codec.ts:210
Serializes a fully signed event to its canonical c2sp-tlog entry bytes, requiring every signature the event type demands.
Parameters
Section titled “Parameters”context?
Section titled “context?”C2spEventContext = {}
Returns
Section titled “Returns”Uint8Array
Throws
Section titled “Throws”C2spTlogParseError when signatures are incomplete or the entry is oversized.
canonicalJson()
Section titled “canonicalJson()”function canonicalJson(value): string;Defined in: packages/log-c2sp-tlog/src/canonical.ts:13
Serializes a JSON value to its RFC 8785 (JCS-style) canonical form: lexicographically sorted object members, no whitespace, valid Unicode.
Parameters
Section titled “Parameters”unknown
Returns
Section titled “Returns”string
Throws
Section titled “Throws”C2spTlogParseError for non-finite or negative-zero numbers, unpaired
surrogates, undefined members, or non-JSON values.
canonicalLogPrefix()
Section titled “canonicalLogPrefix()”function canonicalLogPrefix(raw): string;Defined in: packages/log-c2sp-tlog/src/lr.ts:82
Canonicalizes a log-prefix URL: lowercase scheme and host, default ports and trailing slash removed, percent-encoding normalized.
Parameters
Section titled “Parameters”string
Returns
Section titled “Returns”string
Throws
Section titled “Throws”C2spTlogParseError for userinfo, query/fragment, dot segments, encoded slashes, unsupported schemes, or TXT-delimiter characters.
checkpointOrigin()
Section titled “checkpointOrigin()”function checkpointOrigin(logPrefix): string;Defined in: packages/log-c2sp-tlog/src/lr.ts:103
Derives the C2SP checkpoint origin (host plus path, no scheme) from a canonical log prefix.
Parameters
Section titled “Parameters”logPrefix
Section titled “logPrefix”string
Returns
Section titled “Returns”string
checkpointPath()
Section titled “checkpointPath()”function checkpointPath(prefix): string;Defined in: packages/log-c2sp-tlog/src/tiles.ts:4
URL of a log’s current checkpoint under the C2SP tlog-tiles layout.
Parameters
Section titled “Parameters”prefix
Section titled “prefix”string
Returns
Section titled “Returns”string
createC2spTlogVerificationRegistry()
Section titled “createC2spTlogVerificationRegistry()”function createC2spTlogVerificationRegistry(options): Promise<LogRegistry>;Defined in: packages/log-c2sp-tlog/src/verification-registry.ts:93
Creates a LogRegistry ready to verify c2sp-tlog lifecycle
references. Trust policy is explicit and never inferred from an identity
record, its lr, or the log prefix.
The default resource fetcher rejects unsafe destinations and redirects, connects through the validated DNS result, requires HTTP 200, bounds decoded bodies while reading, and applies finite request deadlines. The default checkpoint store is restart-ephemeral; inject durable storage when rollback protection must survive process restarts.
Parameters
Section titled “Parameters”options
Section titled “options”Returns
Section titled “Returns”Promise<LogRegistry>
createDefaultC2spBoundedResourceFetcher()
Section titled “createDefaultC2spBoundedResourceFetcher()”function createDefaultC2spBoundedResourceFetcher(transport?): C2spBoundedResourceFetcher;Defined in: packages/log-c2sp-tlog/src/stream-source.ts:85
Creates the default public-resource fetcher. It uses connection-time SSRF
checks, rejects redirects, requires HTTP 200, and bounds the decoded body
while reading it. transport applies the same DNS server, CA bundle, and
private-address exceptions as DnsidConfig.transport, so a private registry
such as dnsid local is reachable for policy and log reads.
Parameters
Section titled “Parameters”transport?
Section titled “transport?”TransportConfig = {}
Returns
Section titled “Returns”createDnsidManagedVerificationRegistry()
Section titled “createDnsidManagedVerificationRegistry()”function createDnsidManagedVerificationRegistry(options?): Promise<LogRegistry>;Defined in: packages/log-c2sp-tlog/src/managed-verification-registry.ts:56
Creates a registry for the reviewed trust roots of DNSid-managed DNSid logs. Calling this separately named factory is an explicit application trust decision; the generic factory never selects these roots implicitly.
Trust snapshots are bundled with the SDK and selected only after parsing an
exact canonical (scope, logPrefix) pair. Managed verification prefers
signed stream bundles with safe raw-scan fallback.
Parameters
Section titled “Parameters”options?
Section titled “options?”DnsidManagedVerificationOptions = {}
Returns
Section titled “Returns”Promise<LogRegistry>
createFetchBackedC2spResourceFetcher()
Section titled “createFetchBackedC2spResourceFetcher()”function createFetchBackedC2spResourceFetcher(fetchImpl, guarantees): C2spBoundedResourceFetcher;Defined in: packages/log-c2sp-tlog/src/stream-source.ts:96
Adapts trusted deployment fetch infrastructure to the bounded C2SP contract. The caller is responsible for truthfully declaring DNS/connection security; the adapter itself enforces HTTPS, status, redirect, timeout, cancellation, and response-size behavior.
Parameters
Section titled “Parameters”fetchImpl
Section titled “fetchImpl”guarantees
Section titled “guarantees”Returns
Section titled “Returns”encodeEntryBundle()
Section titled “encodeEntryBundle()”function encodeEntryBundle(entries): Uint8Array;Defined in: packages/log-c2sp-tlog/src/tiles.ts:43
Encodes entries as a C2SP tlog-tiles entry bundle with 16-bit big-endian length prefixes.
Parameters
Section titled “Parameters”entries
Section titled “entries”Uint8Array<ArrayBufferLike>[]
Returns
Section titled “Returns”Uint8Array
Throws
Section titled “Throws”C2spTlogParseError when an entry exceeds 65535 bytes.
enforceCheckpointPolicy()
Section titled “enforceCheckpointPolicy()”function enforceCheckpointPolicy( checkpoint, origin, policy, scope, nowMs?, maxClockSkewMs?): CheckpointPolicyResult;Defined in: packages/log-c2sp-tlog/src/policy.ts:114
Enforces the local trust policy on a parsed checkpoint: origin and scope
match, a valid signature from an accepted log key, and a satisfied witness
quorum of timestamped cosignatures no further than maxClockSkewMs in the
future. Public scope additionally requires a non-empty quorum rule.
Parameters
Section titled “Parameters”checkpoint
Section titled “checkpoint”origin
Section titled “origin”string
policy
Section titled “policy”string
nowMs?
Section titled “nowMs?”number = ...
maxClockSkewMs?
Section titled “maxClockSkewMs?”number = 0
Returns
Section titled “Returns”The accepted witness timestamps and derived checkpoint witness time.
Throws
Section titled “Throws”C2spTlogVerificationError when any requirement is not met.
entryBundlePath()
Section titled “entryBundlePath()”function entryBundlePath( prefix, n, width?): string;Defined in: packages/log-c2sp-tlog/src/tiles.ts:8
URL of entry bundle n under the C2SP tlog-tiles layout; width selects a partial bundle.
Parameters
Section titled “Parameters”prefix
Section titled “prefix”string
number
width?
Section titled “width?”number
Returns
Section titled “Returns”string
eventToC2spEnvelope()
Section titled “eventToC2spEnvelope()”function eventToC2spEnvelope( event, context?, includeSigs?): C2spJsonEvent;Defined in: packages/log-c2sp-tlog/src/event-codec.ts:34
Converts a protocol LogEvent into its c2sp-tlog JSON envelope
(v: 1, kind: 'dnsid.lifecycle') with per-type payload fields, the log
binding from context, and optionally the event’s existing signatures.
Parameters
Section titled “Parameters”context?
Section titled “context?”C2spEventContext = {}
includeSigs?
Section titled “includeSigs?”boolean = true
Returns
Section titled “Returns”Throws
Section titled “Throws”C2spTlogParseError for unsupported event types, malformed lifecycle keys, or missing public-scope binding fields.
generateC2spTlogStreamId()
Section titled “generateC2spTlogStreamId()”function generateC2spTlogStreamId(): string;Defined in: packages/log-c2sp-tlog/src/lr.ts:27
Generates an opaque identity-instance stream ID using 128 bits of cryptographically secure randomness, encoded as unpadded base64url.
Returns
Section titled “Returns”string
inclusionRoot()
Section titled “inclusionRoot()”function inclusionRoot( leaf, index, treeSize, proof): Uint8Array;Defined in: packages/log-c2sp-tlog/src/merkle.ts:26
Recomputes the Merkle tree root implied by a leaf hash, its index, the tree size, and an RFC 6962 inclusion proof path.
Parameters
Section titled “Parameters”Uint8Array
number
treeSize
Section titled “treeSize”number
Uint8Array<ArrayBufferLike>[]
Returns
Section titled “Returns”Uint8Array
Throws
Section titled “Throws”Error when the index or tree size is out of range.
leafHash()
Section titled “leafHash()”function leafHash(entryBytes): Uint8Array;Defined in: packages/log-c2sp-tlog/src/merkle.ts:11
RFC 6962 leaf hash: SHA-256(0x00 || entry bytes).
Parameters
Section titled “Parameters”entryBytes
Section titled “entryBytes”Uint8Array
Returns
Section titled “Returns”Uint8Array
merkleRootFromEntries()
Section titled “merkleRootFromEntries()”function merkleRootFromEntries(entries): Uint8Array;Defined in: packages/log-c2sp-tlog/src/merkle.ts:49
Computes the RFC 6962 Merkle root of an ordered list of entries (empty-tree root for no entries).
Parameters
Section titled “Parameters”entries
Section titled “entries”Uint8Array<ArrayBufferLike>[]
Returns
Section titled “Returns”Uint8Array
nodeHash()
Section titled “nodeHash()”function nodeHash(left, right): Uint8Array;Defined in: packages/log-c2sp-tlog/src/merkle.ts:16
RFC 6962 interior node hash: SHA-256(0x01 || left || right).
Parameters
Section titled “Parameters”Uint8Array
Uint8Array
Returns
Section titled “Returns”Uint8Array
normalizedOriginPolicy()
Section titled “normalizedOriginPolicy()”function normalizedOriginPolicy(policy, origin): NormalizedOriginPolicy;Defined in: packages/log-c2sp-tlog/src/policy.ts:63
Resolves and validates the policy for origin: parses key strings, checks
signature types (0x01 for log keys, 0x04 for witness cosignature keys),
requires distinct underlying public keys, and normalizes the quorum rule.
Parameters
Section titled “Parameters”policy
Section titled “policy”origin
Section titled “origin”string
Returns
Section titled “Returns”NormalizedOriginPolicy
Throws
Section titled “Throws”C2spTlogVerificationError when the origin has no policy or the policy is invalid.
parseC2spEventEntry()
Section titled “parseC2spEventEntry()”function parseC2spEventEntry(bytes, context?): Promise<LogEvent>;Defined in: packages/log-c2sp-tlog/src/event-codec.ts:155
Parses a raw c2sp-tlog log entry (canonical JSON bytes, 1..65535 bytes) into
a LogEvent, verifying the bytes are canonical and, for public scope,
that the signed log binding matches context.
Parameters
Section titled “Parameters”Uint8Array
context?
Section titled “context?”C2spEventContext = {}
Returns
Section titled “Returns”Promise<LogEvent>
Throws
Section titled “Throws”C2spTlogParseError when the entry is oversized, non-canonical, or malformed.
parseC2spPolicyFile()
Section titled “parseC2spPolicyFile()”function parseC2spPolicyFile(text): C2spTlogPolicy;Defined in: packages/log-c2sp-tlog/src/policy.ts:136
Parses a C2SP tlog-policy file (log, witness, group, and exactly one
quorum directive) into a C2spTlogPolicy keyed by log-key origin.
All configured logs share the declared witnesses and quorum rule.
Parameters
Section titled “Parameters”string
Returns
Section titled “Returns”Throws
Section titled “Throws”C2spTlogVerificationError when a line is malformed, names collide, key types are unsupported, or the quorum directive is missing or repeated.
parseC2spSignatures()
Section titled “parseC2spSignatures()”function parseC2spSignatures( value, type, requireComplete?): C2spSignatures;Defined in: packages/log-c2sp-tlog/src/event-codec.ts:297
Parses and validates an envelope sigs object for an event type, rejecting
roles the type does not allow.
Parameters
Section titled “Parameters”unknown
string
requireComplete?
Section titled “requireComplete?”boolean = true
When true, every required role must be present.
Returns
Section titled “Returns”Throws
Section titled “Throws”C2spTlogParseError when the object, a role, or a signature value is invalid.
parseC2spStreamBundle()
Section titled “parseC2spStreamBundle()”function parseC2spStreamBundle(bytes, options): C2spStreamBundle;Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:121
Parses and structurally validates a canonical-JSON stream bundle without verifying any signatures, proofs, or freshness: exact member sets, canonical base64url fields, a canonical bound lr, and strictly increasing event indexes.
Parameters
Section titled “Parameters”Uint8Array
options
Section titled “options”Returns
Section titled “Returns”Throws
Section titled “Throws”C2spTlogParseError when the bundle is oversized or malformed.
parseC2spTlogLr()
Section titled “parseC2spTlogLr()”function parseC2spTlogLr(lr): ParsedC2spTlogLr;Defined in: packages/log-c2sp-tlog/src/lr.ts:39
Parses and validates a c2sp-tlog: log reference as published in an
identity record’s lr tag, requiring an already-canonical log prefix.
Parameters
Section titled “Parameters”string
Returns
Section titled “Returns”Throws
Section titled “Throws”C2spTlogParseError when any component is missing or non-canonical.
parseC2spTlogTrustProfile()
Section titled “parseC2spTlogTrustProfile()”function parseC2spTlogTrustProfile(bytes): C2spTlogTrustProfile;Defined in: packages/log-c2sp-tlog/src/trust-profile.ts:21
Parses and validates a dnsid-c2sp-tlog-trust-profile@v1 JSON document.
Parameters
Section titled “Parameters”Uint8Array
Returns
Section titled “Returns”parseCheckpoint()
Section titled “parseCheckpoint()”function parseCheckpoint(text): Checkpoint;Defined in: packages/log-c2sp-tlog/src/checkpoint.ts:16
Parses a C2SP checkpoint (c2sp.org/tlog-checkpoint) carried in a signed note: an origin line, decimal tree size, base64 root hash, then a blank line and signature lines. Signatures are parsed but not verified.
Parameters
Section titled “Parameters”string
Returns
Section titled “Returns”Throws
Section titled “Throws”C2spTlogParseError when the note body or a signature line is malformed.
parseEntryBundle()
Section titled “parseEntryBundle()”function parseEntryBundle(bytes): Uint8Array<ArrayBufferLike>[];Defined in: packages/log-c2sp-tlog/src/tiles.ts:23
Splits a C2SP tlog-tiles entry bundle (16-bit big-endian length prefix per entry) into individual entry byte strings.
Parameters
Section titled “Parameters”Uint8Array
Returns
Section titled “Returns”Uint8Array<ArrayBufferLike>[]
Throws
Section titled “Throws”C2spTlogParseError when a length prefix or entry is truncated.
parseJsonNoDuplicateMembers()
Section titled “parseJsonNoDuplicateMembers()”function parseJsonNoDuplicateMembers(bytes): unknown;Defined in: packages/log-c2sp-tlog/src/canonical.ts:58
Parses UTF-8 JSON bytes, rejecting duplicate object member names anywhere in the document.
Parameters
Section titled “Parameters”Uint8Array
Returns
Section titled “Returns”unknown
Throws
Section titled “Throws”C2spTlogParseError on invalid UTF-8, malformed JSON, or duplicate members.
parseNoteSignature()
Section titled “parseNoteSignature()”function parseNoteSignature(line): NoteSignature;Defined in: packages/log-c2sp-tlog/src/checkpoint.ts:40
Parses a single C2SP signed-note signature line (— name base64), splitting
the leading 4-byte key hash from the signature when present.
Parameters
Section titled “Parameters”string
Returns
Section titled “Returns”Throws
Section titled “Throws”C2spTlogParseError when the line does not match the signed-note format.
parsePreparedC2spTlogEvent()
Section titled “parsePreparedC2spTlogEvent()”function parsePreparedC2spTlogEvent( bytes, lr, context?): Promise<PreparedC2spTlogEvent>;Defined in: packages/log-c2sp-tlog/src/writer.ts:119
Reconstructs a prepared event from canonical envelope bytes (for example received from another signer), verifying canonical form, the log binding, ISSUANCE expectations, and every signature already present.
Parameters
Section titled “Parameters”Uint8Array
string
context?
Section titled “context?”PreparedC2spVerificationContext = {}
Returns
Section titled “Returns”Promise<PreparedC2spTlogEvent>
Throws
Section titled “Throws”C2spTlogParseError when the bytes or envelope are malformed.
Throws
Section titled “Throws”C2spTlogVerificationError when expectations or existing signatures fail.
parseSignedNoteVerifierKey()
Section titled “parseSignedNoteVerifierKey()”function parseSignedNoteVerifierKey(text): SignedNoteKey;Defined in: packages/log-c2sp-tlog/src/signed-note.ts:17
Parses a C2SP signed-note (c2sp.org/signed-note) verifier key in either the
name+keyid+base64 vkey form or the whitespace-separated name [ed25519] base64
form. The base64 payload may carry a leading signature-type byte before the
32-byte Ed25519 key.
Parameters
Section titled “Parameters”string
Returns
Section titled “Returns”Throws
Section titled “Throws”C2spTlogParseError when the key text is malformed.
parseTlogProofV1()
Section titled “parseTlogProofV1()”function parseTlogProofV1(text): TlogProofV1;Defined in: packages/log-c2sp-tlog/src/proof.ts:17
Parses a c2sp.org/tlog-proof@v1 document: magic line, optional extra
line, index line, inclusion proof hashes, then a blank line and the
embedded checkpoint.
Parameters
Section titled “Parameters”string
Returns
Section titled “Returns”Throws
Section titled “Throws”C2spTlogParseError when any line or the embedded checkpoint is malformed.
prepareC2spTlogEvent()
Section titled “prepareC2spTlogEvent()”function prepareC2spTlogEvent(event, context): C2spJsonEvent;Defined in: packages/log-c2sp-tlog/src/event-codec.ts:229
Builds the unsigned envelope for an event about to be signed, validating the
public-scope binding fields against context.
Parameters
Section titled “Parameters”context
Section titled “context”Returns
Section titled “Returns”Throws
Section titled “Throws”C2spTlogParseError when the event or its public binding is invalid.
prepareC2spTlogEventForSigning()
Section titled “prepareC2spTlogEventForSigning()”function prepareC2spTlogEventForSigning( event, lr, chain?): PreparedC2spTlogEvent;Defined in: packages/log-c2sp-tlog/src/writer.ts:96
Stages a lifecycle event for signing against a bound (index-free) log reference, deriving genesis chain metadata for public ISSUANCE and inbound MIGRATION events.
Parameters
Section titled “Parameters”string
chain?
Section titled “chain?”Returns
Section titled “Returns”Throws
Section titled “Throws”C2spTlogParseError when the reference, event, or chain metadata is invalid.
registerC2spTlog()
Section titled “registerC2spTlog()”function registerC2spTlog(registry, options): void;Defined in: packages/log-c2sp-tlog/src/index.ts:24
Registers the c2sp-tlog method on a protocol LogRegistry, constructing a C2spTlogReader per lr. Reader options are shared; this low-level registration does not propagate per-invocation signals.
Parameters
Section titled “Parameters”registry
Section titled “registry”options
Section titled “options”Returns
Section titled “Returns”void
requiredC2spResourceFetchGuarantees()
Section titled “requiredC2spResourceFetchGuarantees()”function requiredC2spResourceFetchGuarantees(): C2spResourceFetchGuarantees;Defined in: packages/log-c2sp-tlog/src/stream-source.ts:74
Returns a copy of the capabilities required by the safe standard-resource factory.
Returns
Section titled “Returns”requiredC2spSignatureNames()
Section titled “requiredC2spSignatureNames()”function requiredC2spSignatureNames(type): keyof C2spSignatures[];Defined in: packages/log-c2sp-tlog/src/event-codec.ts:283
Signature roles a lifecycle event type must carry: ae+op for ISSUANCE,
prev_op+new_op for KEY_ROTATION, ae for every other supported type.
Parameters
Section titled “Parameters”string
Returns
Section titled “Returns”keyof C2spSignatures[]
Throws
Section titled “Throws”C2spTlogParseError for unsupported event types.
signedC2spEntryBytes()
Section titled “signedC2spEntryBytes()”function signedC2spEntryBytes(bytes): Uint8Array;Defined in: packages/log-c2sp-tlog/src/event-codec.ts:197
Extracts the signed byte string of a stored entry: the canonical envelope
with the sigs member removed. These are the bytes each lifecycle signature
covers.
Parameters
Section titled “Parameters”Uint8Array
Returns
Section titled “Returns”Uint8Array
Throws
Section titled “Throws”C2spTlogParseError when the entry is oversized or non-canonical.
signedC2spEventBytes()
Section titled “signedC2spEventBytes()”function signedC2spEventBytes(event, context?): Uint8Array;Defined in: packages/log-c2sp-tlog/src/event-codec.ts:219
Canonical to-be-signed bytes for event: its envelope without signatures.
Parameters
Section titled “Parameters”context?
Section titled “context?”C2spEventContext = {}
Returns
Section titled “Returns”Uint8Array
signPreparedC2spTlogEvent()
Section titled “signPreparedC2spTlogEvent()”function signPreparedC2spTlogEvent( prepared, role, keyProvider, options?): Promise<PreparedC2spTlogEvent>;Defined in: packages/log-c2sp-tlog/src/writer.ts:143
Adds one role’s signature to a prepared event using the key provider, verifying the provider key matches the key the envelope requires for that role and that existing signatures remain valid.
Parameters
Section titled “Parameters”prepared
Section titled “prepared”keyProvider
Section titled “keyProvider”options?
Section titled “options?”Returns
Section titled “Returns”Promise<PreparedC2spTlogEvent>
A new prepared event carrying the added signature.
Throws
Section titled “Throws”C2spTlogVerificationError when the role is not required, already
signed (without replaceExisting), or key/signature checks fail.
stateHash()
Section titled “stateHash()”function stateHash(state): string;Defined in: packages/log-c2sp-tlog/src/stream-verifier.ts:379
Base64url hash of a lifecycle state object (domain-separated SHA-256 over canonical JSON), as used in prev_state_hash.
Parameters
Section titled “Parameters”unknown
Returns
Section titled “Returns”string
stitchVerifiedMigrationHistory()
Section titled “stitchVerifiedMigrationHistory()”function stitchVerifiedMigrationHistory( domain, currentEvents, migration): Promise<LogEvent[]>;Defined in: packages/log-c2sp-tlog/src/stream-verifier.ts:47
Stitches a verified prior-log history onto the current log’s events for an inbound MIGRATION: the current events must begin with the MIGRATION, the prior history must establish the imported entity and active operational keys (and contain the ISSUANCE genesis), and the combined lifecycle must snapshot cleanly.
Parameters
Section titled “Parameters”domain
Section titled “domain”string
currentEvents
Section titled “currentEvents”LogEvent[]
migration
Section titled “migration”Returns
Section titled “Returns”Promise<LogEvent[]>
The prior history followed by the current events, in order.
Throws
Section titled “Throws”C2spTlogVerificationError (INVALID_MIGRATION) when the prior
history does not establish the imported keys or the MIGRATION is
duplicated or missing.
tilePath()
Section titled “tilePath()”function tilePath( prefix, level, n, width?): string;Defined in: packages/log-c2sp-tlog/src/tiles.ts:6
URL of hash tile n at level under the C2SP tlog-tiles layout; width selects a partial tile.
Parameters
Section titled “Parameters”prefix
Section titled “prefix”string
number
number
width?
Section titled “width?”number
Returns
Section titled “Returns”string
validateC2spResourceFetcher()
Section titled “validateC2spResourceFetcher()”function validateC2spResourceFetcher(fetcher): void;Defined in: packages/log-c2sp-tlog/src/stream-source.ts:108
Throws a deterministic error when a fetcher cannot safely read public standard resources.
Parameters
Section titled “Parameters”fetcher
Section titled “fetcher”Returns
Section titled “Returns”void
verifiedCosignatureTimestamp()
Section titled “verifiedCosignatureTimestamp()”function verifiedCosignatureTimestamp(checkpoint, key): number | undefined;Defined in: packages/log-c2sp-tlog/src/signed-note.ts:45
Finds a valid C2SP tlog-cosignature (type 0x04) by key on the checkpoint
and returns its witnessed timestamp in epoch seconds.
Parameters
Section titled “Parameters”checkpoint
Section titled “checkpoint”Returns
Section titled “Returns”number | undefined
The cosignature timestamp, or undefined when the key is not a cosignature key or no valid cosignature is present.
verifyC2spConsistencyProof()
Section titled “verifyC2spConsistencyProof()”function verifyC2spConsistencyProof( fromSize, toSize, fromRoot, toRoot, proof): boolean;Defined in: packages/log-c2sp-tlog/src/checkpoint-trust.ts:100
Verifies an RFC 6962 consistency proof that the tree of size fromSize with
root fromRoot is a prefix of the tree of size toSize with root toRoot.
Returns false rather than throwing on invalid input.
Parameters
Section titled “Parameters”fromSize
Section titled “fromSize”number
toSize
Section titled “toSize”number
fromRoot
Section titled “fromRoot”Uint8Array
toRoot
Section titled “toRoot”Uint8Array
Uint8Array<ArrayBufferLike>[]
Returns
Section titled “Returns”boolean
verifyC2spStreamBundle()
Section titled “verifyC2spStreamBundle()”function verifyC2spStreamBundle(bytes, options): Promise<VerifiedC2spStreamBundle>;Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:200
Verifies offline lifecycle evidence for an expected identity and log reference: checks the expected agent FQDN and log reference, the producer signature, the policy hash, checkpoint policy and trusted-checkpoint advancement, freshness and expiry windows, each event’s inclusion proof, and the complete lifecycle history, then confirms the bundle’s asserted state summary. The caller must independently trust the policy, bundle keys, and entity key; this does not verify the DNS identity record or current status.
Parameters
Section titled “Parameters”Uint8Array
options
Section titled “options”Returns
Section titled “Returns”Promise<VerifiedC2spStreamBundle>
The verified bundle, lifecycle, and active operational key thumbprint.
Throws
Section titled “Throws”C2spTlogParseError when the bundle is malformed.
Throws
Section titled “Throws”C2spTlogVerificationError when any verification step fails.
verifyC2spTlogProof()
Section titled “verifyC2spTlogProof()”function verifyC2spTlogProof( entryBytes, proof, policy, origin?, scope?, nowMs?, maxClockSkewMs?): TlogProofV1;Defined in: packages/log-c2sp-tlog/src/proof.ts:55
Verifies an entry’s inclusion proof: enforces the local checkpoint policy (log signature and witness quorum) and checks the RFC 6962 inclusion path against the checkpoint root.
Parameters
Section titled “Parameters”entryBytes
Section titled “entryBytes”Uint8Array
string | TlogProofV1
Parsed proof or raw tlog-proof@v1 text.
policy
Section titled “policy”origin?
Section titled “origin?”string
scope?
Section titled “scope?”string = 'testnet'
nowMs?
Section titled “nowMs?”number = ...
maxClockSkewMs?
Section titled “maxClockSkewMs?”number = 0
Returns
Section titled “Returns”The parsed, verified proof.
Throws
Section titled “Throws”C2spTlogParseError when a textual proof is malformed.
Throws
Section titled “Throws”C2spTlogVerificationError when policy enforcement or the inclusion proof fails.
verifyCheckpointSignature()
Section titled “verifyCheckpointSignature()”function verifyCheckpointSignature(checkpoint, key): boolean;Defined in: packages/log-c2sp-tlog/src/signed-note.ts:34
Returns true when any checkpoint signature matches key by name/key ID and verifies over the signed note text.
Parameters
Section titled “Parameters”checkpoint
Section titled “checkpoint”Returns
Section titled “Returns”boolean
verifyInclusion()
Section titled “verifyInclusion()”function verifyInclusion( entryBytes, index, treeSize, rootHash, proof): boolean;Defined in: packages/log-c2sp-tlog/src/merkle.ts:44
Checks an RFC 6962 inclusion proof for entryBytes at index against the expected tree root.
Parameters
Section titled “Parameters”entryBytes
Section titled “entryBytes”Uint8Array
number
treeSize
Section titled “treeSize”number
rootHash
Section titled “rootHash”Uint8Array
Uint8Array<ArrayBufferLike>[]
Returns
Section titled “Returns”boolean
verifyLifecycle()
Section titled “verifyLifecycle()”function verifyLifecycle(events, options?): Promise<void>;Defined in: packages/log-c2sp-tlog/src/stream-verifier.ts:277
Verifies an ordered lifecycle: it must begin with ISSUANCE (or a verified inbound MIGRATION), every event signature must verify against the entity or operational key active at that point, KEY_ROTATION must prove possession of the new key, every scope must carry consistent seq/prev_* fields, and nothing may follow a terminal REVOCATION/RETIREMENT. MIGRATION is valid only as verified inbound genesis in the destination stream.
Parameters
Section titled “Parameters”events
Section titled “events”options?
Section titled “options?”Returns
Section titled “Returns”Promise<void>
Throws
Section titled “Throws”C2spTlogVerificationError on any structural or key-continuity violation.
Throws
Section titled “Throws”VerificationError (SignatureInvalid) when a signature fails to verify.
verifyLoggedEventSignature()
Section titled “verifyLoggedEventSignature()”function verifyLoggedEventSignature(item, signerKey): Promise<void>;Defined in: packages/log-c2sp-tlog/src/stream-verifier.ts:372
Verifies a single logged event’s primary signature against signerKey over
the entry’s signed bytes.
Parameters
Section titled “Parameters”signerKey
Section titled “signerKey”Returns
Section titled “Returns”Promise<void>
Throws
Section titled “Throws”C2spTlogVerificationError when the event has no signature.
Throws
Section titled “Throws”VerificationError (SignatureInvalid) when verification fails.
verifyNoteSignature()
Section titled “verifyNoteSignature()”function verifyNoteSignature( message, sig, key): boolean;Defined in: packages/log-c2sp-tlog/src/signed-note.ts:60
Verifies one signed-note signature over message with an Ed25519 key.
Supports plain log signatures (type 0x01) and timestamped C2SP cosignatures
(type 0x04, cosignature/v1 preimage). Returns false rather than throwing.
Parameters
Section titled “Parameters”message
Section titled “message”string
Returns
Section titled “Returns”boolean
verifyStreamLifecycle()
Section titled “verifyStreamLifecycle()”function verifyStreamLifecycle( entries, domain, options?): Promise<VerifiedLifecycleEvent[]>;Defined in: packages/log-c2sp-tlog/src/stream-verifier.ts:162
Extracts and verifies the lifecycle history for one agent domain from entries already authenticated by the accepted completeness mechanism: entries are processed in index order, other domains are skipped, identical signed payloads are deduplicated, and each candidate must keep the accumulated lifecycle valid under verifyLifecycle. A malformed entry that nevertheless carries a valid signatures for every role under verified predecessor authority is treated as a lifecycle violation, not skipped.
Parameters
Section titled “Parameters”entries
Section titled “entries”domain
Section titled “domain”string
options?
Section titled “options?”Returns
Section titled “Returns”Promise<VerifiedLifecycleEvent[]>
The accepted events in log order.
Throws
Section titled “Throws”C2spTlogVerificationError when the resulting lifecycle is invalid (for example no ISSUANCE event survives).
writePreparedEvent()
Section titled “writePreparedEvent()”function writePreparedEvent(prepared, options): Promise<string>;Defined in: packages/log-c2sp-tlog/src/writer.ts:209
Appends a finalized prepared event to the log via options.submit, running
the required chain validation for non-genesis events.
Parameters
Section titled “Parameters”prepared
Section titled “prepared”options
Section titled “options”Returns
Section titled “Returns”Promise<string>
The event’s log reference (<lr>@<index>).
Throws
Section titled “Throws”C2spTlogVerificationError when finalization, chain validation, or the returned index is invalid.