Five-minute proof
Five-minute proof
Prove Writ against the live gate in about five minutes. No deploy, no
--push-policy — only the public sandbox/check APIs as a normal client.
Repo mirror (same commands, plus a runnable script):
scripts/demo-five-minute.mdand./scripts/demo-five-minute.sh.
Install
pip
curl
Command sequence
Keep sponsor, agent, verb, target, purpose identical across sandbox and check — the grant matches on all five fields.
Or: WRIT_API_KEY=writ_... ./scripts/demo-five-minute.sh
Without a key the script dry-runs (prints commands + hits keyless sandbox).
ALLOW vs DENY
A second identical check after ALLOW is DENY again — the grant was spent.
Sandbox ↔ require_grant
demo_write(and unknown verbs) default torequire_grant.- Check with no grant → DENY (receipt still written).
writ sandbox→POST /v1/sandboxmints a 90s grant fordemo_writeon ademo-*target. No API key.- Matching check spends the grant → ALLOW.
- Real verbs use
writ grant --sponsor-token ...(or the dashboard).
See Concepts for modes (allow | deny | require_grant |
step_up) and Audit log for receipts / verify-chain.
CLI gaps
--keyis required on each subcommand; the CLI does not readWRIT_API_KEYforcheck/receipts/verify-chain(the scanner helper does). Pass--key "$WRIT_API_KEY"or use the script.- Output is raw JSON — parse
decision,receiptId,ok. - Sandbox is keyless; seeing receipts and verifying the chain needs your key.