API key required. Checks an `authToken` from an ALLOW response:
signature, expiry (90 seconds from mint), and — when `verb`,
`target`, or `purpose` are supplied — that the token is bound to
exactly that write. Anything else is purpose drift and returns
`valid: false`. **Important:** an invalid token is HTTP 200 with
`{"valid": false, "reason": "..."}` — only a bad API key is a 401.
Call this at commit time, after the agent performs the write, to
prove the write matches what Writ allowed.
Request
This endpoint expects an object.
tokenstringRequired
The writ_at_… auth token from an ALLOW response.
verbstringOptional
If given, the token must be bound to exactly this verb.
targetstringOptional
If given, the token must be bound to exactly this target.
purposestringOptional
If given, the token must be bound to exactly this purpose.