Verify the audit-log hash chain
Verify the audit-log hash chain
Authentication
Query parameters
Max receipts to verify, newest first. Clamped to 1-1000.
Verify the audit-log hash chain
Max receipts to verify, newest first. Clamped to 1-1000.
API key required. Recomputes every chained receipt’s HMAC and checks
each link, newest first, for the caller’s tenant only. Returns
{"ok": true, "checked": N, "tip": "<hash>", "tipReceipt": "<id>", "chainedFrom": "<id>", "legacyCount": M, "complete": true} when the
chain is intact, or {"ok": false, "checked": N, "tip": "<hash>", "brokenAt": "<receiptId>", "reason": "..."} at the first receipt
that fails. Each receipt carries prevHash (the previous receipt’s
chainHash, or GENESIS) and chainHash = HMAC-SHA256(canonical receipt fields + prevHash) keyed by the
deploy’s WRIT_CHAIN_SECRET (falls back to WRIT_TOKEN_SECRET).
Receipts written before chaining was enabled have no chain fields;
verification stops at them and reports them as legacyCount.
Supports NIST SP 800-53 AU-9 (protection of audit information):
tampering with a stored receipt breaks the chain and is detected
here. limit is clamped to 1-1000; non-numeric values fall back to
200.
Your Writ API key (writ_…) as an Authorization Bearer header. The sponsor token (writ_sp_…) is a separate credential used only for grants, revokes, and reinstate — it goes in the same Authorization header on those endpoints. In the Fern docs playground, paste the key here; it is stored in this browser only.