Reference
Reference
The Concepts and Guides explain the model and how to wire it in. This page is the map to the authoritative material underneath them: the Go API documentation, the wire specification, the conformance vectors, and the source repositories. Reach for it when you want an exact signature, a byte-level rule, or the code itself.
Go API
The reference implementation is the module valiss.dev/valiss. Its generated
documentation is the exact API surface: every type, function, and option.
- valiss.dev/valiss - the core: token
issue and verify, the
VerifierandIdentity, the allowlist, keyring, replay cache, and message tokens. - valiss.dev/valiss/creds - the
credentials-file format:
Format,Parse,Load, and theCredsstruct a client authenticates with.
Credential transports and framework adapters
The <framework>auth packages carry credential authentication and grant a
verified identity:
- contrib/httpauth -
net/http middleware and a signing
RoundTripper; defines the HTTP extensionExt{Hosts, Methods, Paths}. - contrib/grpcauth -
gRPC server interceptors and per-RPC credentials; defines the gRPC extension
Ext{Methods}. - contrib/ginauth - Gin middleware over the httpauth verification core.
- contrib/echoauth - Echo middleware over the httpauth verification core.
Message-token transports
The <framework>sig packages carry message-token verification and grant no
identity (they expose MessageFrom, not an authenticated identity):
- contrib/httpsig - net/http message-token middleware and client transport.
- contrib/grpcsig - gRPC message-token interceptors; the checksum binds the deterministic protobuf encoding of the message.
- contrib/ginsig - Gin message-token middleware.
- contrib/echosig - Echo message-token middleware.
Wire specification
- SPEC-1 - the scheme at the byte and algorithm level: the JWS
envelope, nkey encoding,
jtiderivation, the signing inputs, the verification order, and the section 7 reason-code taxonomy. Normative and language-independent; the Go source is canonical where the two disagree.
Conformance vectors
- Conformance vectors - language-neutral, verify-side test vectors frozen with spec 1; each JSON file in the linked corpus pairs its artifacts with their expected verification outcome. An implementation conforms if it runs every vector and gets the expected outcome, so a port checks itself against these rather than against the Go library directly.
Repositories
All under the valiss-dev GitHub organization:
- valiss-go - the Go reference implementation and the source of truth for the scheme.
- valiss-py - the Python port: creds, issue, sign, verify, plus the Django and ASGI integrations.
- valiss-ts - the TypeScript/JavaScript port of the core wire layer.
- valiss-cli - the planned
issuer-side CLI (
valiss) for keys, tokens, creds, and allowlist management; early development, its command tree is designed but every command is currently a stub, not yet released. - spec - SPEC-1 and the conformance vectors.
- docs - the source of this documentation site.