@maatara/veritas-chain
v2.2.1
Published
Ma'atara Veritas Chain SDK — tamper-evident signed provenance records, receipts, epoch commitments, and anchoring helpers
Readme
@maatara/veritas-chain
Ma'atara's provenance SDK for tamper-evident signed Veritas Chain records, receipts, Merkle proofs, owner-authorised epoch and anchor control blocks, EIP-712 mint-voucher payloads, marketplace metadata, and typed chain data.
Version 2.1.0 is provenance-only. Secure-channel establishment, pairwise encryption, and key-ratcheting APIs are not
part of this package. Product code uses the private @maatara/secure-channel orchestration boundary, backed by
@maatara/pqc-toolkit/pairwise-channel where a low-level cryptographic adapter is required.
Call initVeritas() once before using WASM-backed operations. The package accepts typed operation objects for legal
context, custody, evidence, signing keys, timestamps, unsigned EIP-712 typed-data and hash generation, and marketplace
metadata. It does not produce an ECDSA signature, redeem a voucher, submit a transaction, mint a token, or establish
marketplace compatibility.
The native block profile is maatara/veritas/block/v4 (version "4"). It is a flat, exact-key camelCase envelope:
every numeric value is a canonical decimal string, every digest is lowercase SHA3-384 hexadecimal, and the owner DID
is derived from the ML-DSA-65 public key. JCS covers every field except blockHash and signature; blockHash and
the ML-DSA signature both cover that same UTF-8 preimage.
Native block validation is structural and crypto-agnostic: callers inject deriveDid and, for transfer or lifecycle
operations, a typed authority verifier. User content is never represented as plaintext: contentType is the exact
closed profile application/maatara.ciphertext.v1, and lifecycle/transfer details remain content-addressed encrypted
payload commitments (urn:maatara:ciphertext:sha3-384:<payloadHash>). Legacy recovery is not part of
this package or Core; it belongs only to the separately sunset-bound migration worker.
The enterprise-audit export provides the shared enterprise.audit.v1 envelope, strict event validator, tenant-window
Merkle commitment builder, and webhook/SIEM delivery-state types. It is a contract and verifier foundation; it is not
an ingestion service, endpoint agent, SIEM, or claim that a downstream SOC received or reviewed an event. Its optional
references are SHA3-384 opaque/ciphertext URNs, optional metadata is commitment-only, and the validators reject
free-text metadata and plaintext references before an event can be hashed or persisted.
PATENT PENDING — Ma'atara Protocol.
