Browse documentation
Docs target stable release v0.9.1.Stable vs main checked 2026-10-09

Signed attestations and gates

tine attest and tine evaluate accept HMAC-SHA256 or Ed25519 keys. A tine-attest/1 signature binds target, claim, signer, evidence IDs, and signature header. A signer label alone is self-asserted.

Terminal
# Supply the key through the operator environment
tine attest heads/main --repo . --signer release-team --claim '{"approved":true}' --key-env OPENTINE_SIGNING_KEY
tine repo-verify heads/main --repo . --key-env OPENTINE_SIGNING_KEY --signer release-team --claim '{"approved":true}' --json
tine repo-search --repo . --signed-only --json

Scoped approval gates

--signer is repeatable. --claim JSON selects the claim being checked. A scoped gate passes when at least one selected attestation verifies; others neither pass nor block it. JSON rows expose claim and selected. Unscoped verification checks all targeted attestations.

Keys and verdicts

Choose exactly one key source: HMAC, Ed25519 public key, or explicit embedded-key trust. Verdicts are verified, verified-tofu, unsigned, no-key, mismatch, and error. Embedded trust does not establish an external identity. Key flags, embedded trust, or --require-signature arm the fail-closed exit check.

Unsigned attestations remain valid stored objects. Search ranks signed evaluations first and reports score_signed; signature presence still requires trusted-key verification. Signing and key material stay operator-only, with no MCP equivalent.

The format specification defines canonical signed bytes.