@metamynd/magp-trust
v0.1.0
Published
Zero-dependency offline verifier for a MetaMynd Trust Index record — re-derive the HCS-28 weighted-mean score from the published adapter breakdown and verify the Ed25519 issuer signature. No call to MetaMynd required.
Maintainers
Readme
@metamynd/magp-trust — offline Trust Index verifier
Zero-dependency verifier for a MetaMynd Trust Index record. A published record is independently checkable with no call to MetaMynd:
- Re-derive the score from the record's own adapter breakdown — the same deterministic
HCS-28 weighted mean the issuer ran (weights travel in the record) — and confirm it matches
the claimed
score/denominator. - Verify the Ed25519
proofagainst MetaMynd's known issuer key.
Both must pass. Uses only Node ≥ 18 built-ins.
Use
import { verifyTrustRecord } from "@metamynd/magp-trust";
// record = the object from GET /api/v1/trust-index/:did (or an HCS-28 topic message)
const r = verifyTrustRecord(record, { publicKey: METAMYND_ISSUER_KEY_HEX });
// → { ok, scoreOk, signatureOk, derived: { score, denominator, coverage }, reasonCode }Pin publicKey to MetaMynd's known issuer key (from GET /trust-index/:did → issuerKey, or the
policy pubkey endpoint) for real trust — otherwise the record's self-claimed key is used (convenience
only). reDeriveTrustScore(record) returns just the recomputed { score, denominator, coverage }.
CLI
node magp-trust.mjs record.json [issuerPublicKeyHex] # exit 0 = VERIFIED, 1 = failedHow records are published
MetaMynd anchors the signed record to an HCS-28 Agent Transparency topic
(POST /api/v1/trust-index/:did/publish, owner/admin). Fetch it from the Hedera mirror node and run
it through this verifier — the score is tamper-evident (re-derivation) and the issuer is
authenticated (signature), with MetaMynd offline.
See docs/design/metamynd-trust-index.md for the scoring model and adapter catalog.
