verify_astranl
Verify any AstraNL reference without a key. Returns two separate layers: integrity (payload hash, Ed25519 signature, Merkle inclusion, recomputed live) and claim (what exactly is attested, by whom, from which source, when, under which method, with which validity limits and current status VALID/EXPIRED/REVOKED/UNKNOWN). Integrity never implies the claim is true for your purpose; you apply your own acceptance rules. Tells you when to re-verify and how to consume a VALID receipt for a next action. Read-only, deterministic, no model in the path.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| ref | Yes | Any AstraNL reference: action receipt ASTRA-A-..., policy receipt ASTRA-R-..., consumption ASTRA-C-..., log event alk_..., attestation att_/atr_..., ingress receipt RCPT-n |