Five-minute proof

Prove Writ against the live gate in about five minutes. No deploy, no --push-policy — only the public sandbox/check APIs as a normal client.

Repo mirror (same commands, plus a runnable script): scripts/demo-five-minute.md and ./scripts/demo-five-minute.sh.

Install

pip install pywrit

Command sequence

Keep sponsor, agent, verb, target, purpose identical across sandbox and check — the grant matches on all five fields.

# 1. Key (sponsor token shown once for new tenants)
writ key --email you@company.com
export WRIT_API_KEY=writ_...
# 2. DENY — demo_write defaults to require_grant; no live grant
writ check \
--key "$WRIT_API_KEY" \
--sponsor you --agent demo-agent \
--verb demo_write --target demo-1 \
--purpose "five-minute proof"
# → "decision": "DENY" + receiptId. Do not run the write.
# 3. Sandbox grant — keyless, 90s, demo_write on demo-* only
writ sandbox \
--sponsor you --agent demo-agent \
--target demo-1 --purpose "five-minute proof"
# → grantId + expiresAt
# 4. ALLOW — grant matched and spent (one-shot)
writ check \
--key "$WRIT_API_KEY" \
--sponsor you --agent demo-agent \
--verb demo_write --target demo-1 \
--purpose "five-minute proof"
# → "decision": "ALLOW" + authToken + receiptId
# 5. Receipts + chain
writ receipts --key "$WRIT_API_KEY"
writ verify-chain --key "$WRIT_API_KEY"
# → {"ok": true, "checked": N, ...}

Or: WRIT_API_KEY=writ_... ./scripts/demo-five-minute.sh
Without a key the script dry-runs (prints commands + hits keyless sandbox).

ALLOW vs DENY

DENYALLOW
decision"DENY""ALLOW"
Why (this demo)require_grant, no live grantsandbox grant matched and spent
receiptIdyesyes
authTokenno90s, bound to this write
Next stepdo not writewrite once; optional token-verify

A second identical check after ALLOW is DENY again — the grant was spent.

Sandbox ↔ require_grant

  1. demo_write (and unknown verbs) default to require_grant.
  2. Check with no grant → DENY (receipt still written).
  3. writ sandbox → POST /v1/sandbox mints a 90s grant for demo_write on a demo-* target. No API key.
  4. Matching check spends the grant → ALLOW.
  5. Real verbs use writ grant --sponsor-token ... (or the dashboard).

See Concepts for modes (allow | deny | require_grant | step_up) and Audit log for receipts / verify-chain.

CLI gaps

  • --key is required on each subcommand; the CLI does not read WRIT_API_KEY for check / receipts / verify-chain (the scanner helper does). Pass --key "$WRIT_API_KEY" or use the script.
  • Output is raw JSON — parse decision, receiptId, ok.
  • Sandbox is keyless; seeing receipts and verifying the chain needs your key.