0x7f/pst-validator

★ 0Forks 0TypeScriptGitHub ↗Compare

README

Private State Token Validator

A tiny CLI that verifies whether a Private State Token key‑commitment (issuer directory) endpoint is implemented correctly.

It checks:

  • URL uses HTTPS
  • HTTP status = 200
  • Content-Type: application/pst-issuer-directory (params allowed)
  • JSON body against a strict JSON Schema (uint32 id and batchsize as numbers; keys 1..6; base64 Y; uint64‑string expiry)
  • Section key equals its inner protocol_version

Note: This tool currently validates the directory (key‑commitment) endpoint only at the moment. It will be extended to cover other parts of the spec as well.

Requirements

  • Node.js 18+
  • npm (or pnpm/yarn)
  • Internet access from the machine running the CLI

Install

# in the project directory
npm install

Run

The project is configured to run via ts-node in ESM mode.

npm run start <URL>

Example:

npm run start https://issuer.example/.well-known/private-state-token/key-commitment

Example outputs

✅ Success

Using a public demo endpoint:

npm run start https://privatetokens.dev/tt/k/

Output:

✅ Success: key-commitment endpoint is valid.

❌ Failure

If the endpoint uses a wrong protocol and responds with the wrong content type and a malformed body:

❌ Validation failed:
  - Endpoint must be HTTPS, got: http:
  - Content-Type must be "application/pst-issuer-directory" (params allowed). Got "application/json; charset=utf-8"
  - /PrivateStateTokenV1VOPRF/id: must be integer

(Your exact errors will reflect what’s wrong with the endpoint.)

Contributors

0x7f

Issues