Execution Attestation, format v1 (final)¶
Status: final, version 1. Test vectors: spec/xybern-formats-v1/vectors/attestation.json.
An execution attestation is the second side of a receipt: the party that executed an authorised action states what ran, and the issuer signs a body that binds that statement to the authorisation, the warrant, the stamp and the declared commitment.
Token¶
Body¶
| Field | Type | Meaning |
|---|---|---|
format |
string | "xybern-execution-v1" |
attestation_id |
string | xat_ followed by 12 hex characters |
issuer |
object | {"workspace_id", "key_id"} |
decision_id |
string | The authorisation the execution ran under |
action_type, agent_id |
string | As on the decision |
attester |
object | {"kind": gateway / relay / sdk / tool / system, "id": ...} |
status |
string | executed, failed, mismatched, skipped |
as_declared |
boolean | executed and the action's commitment was valid, or none was needed |
executed_at |
string | ISO 8601 UTC |
result_sha256 |
string or null | SHA-256 of the result (a string as given, anything else as canonical JSON); never the result |
result_summary |
string or null | At most 200 characters, optional |
warrant_id, stamp_id |
string or null | The warrant the action carried and the stamp it travelled with |
commitment |
object or null | {"commitment_id", "params_hash", "valid"} |
charter_hash |
string or null | The Charter version the decision was taken under |
decision_vault_entry_id |
string or null | The Vault entry of the decision |
extra |
object or null | Scalar extras from the attester (tool name, latency) |
Signature¶
As in the bundle: ECDSA P-256 over SHA-256 of the canonical body.
Checks¶
- Format and signature against the issuer's published key.
- The
decision_idmatches the receipt or stamp being checked, andstamp_id/warrant_idmatch the tokens in hand. statusandas_declareddecide what the receiver may conclude:executedwithas_declaredtrue means the tool ran exactly what was authorised and declared.
Issuer state (POST /v1/enforce/attest/verify) adds whether the body hash matches the issuer's record. One attestation per decision; a second attestation returns the first.
Reference implementations¶
package/xybern_api/execution_attestations.py; tools/xybern-verify/verify.py --attestation <token> --keys keys.json; SDK client.attest_execution, client.verify_attestation.