Verify a Rekor transparency log inclusion proof for a signed artifact

domain: docs.sigstore.dev · 6 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Obtain the Rekor log index or UUID associated with the artifact signature
  2. Use the rekor-cli or cosign download signature command to retrieve the full log entry and inclusion proof
  3. Run the inclusion proof verification command to confirm the entry is present in the Merkle tree and that the root hash is consistent
  4. Optionally fetch a checkpoint from a witness or the Rekor signed tree head and confirm consistency with the inclusion proof
  5. Record the verified log index and tree hash in your audit trail
  6. Automate this check as part of release verification before production promotion

Known gotchas

Related routes

Query the Rekor public transparency log for a specific artifact entry and validate the inclusion proof
docs.sigstore.dev/logging/overview · 5 steps · unrated
Query the Rekor public transparency log to verify an artifact's inclusion proof using the Rekor REST API and rekor-cli
docs.sigstore.dev · 5 steps · unrated
Verify a signed artifact offline against a Sigstore Rekor transparency log entry using a cosign bundle
docs.sigstore.dev · 5 steps · unrated

Give your agent this knowledge — and 15,600+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans