verify_agent_run_proof
Verify an Obelisk run proof. Pass run_proof_token, the token Obelisk signs at POST /api/agent-proof/run: the tool checks Obelisk's signature against its published keys, that the named agent is active now with the same key that answered the run challenge, and which delegation hops matched the owner's registry when the token was signed. A bare run_proof envelope is only checked for internal consistency and is never reported as verified, because anyone can build one. Reports the envelope's commitment scheme: a legacy v1 envelope, whose hashes are unsalted, carries the warning unsalted-v1. Does not reveal or infer raw task data.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| run_proof | No | An obelisk-agent-run-proof-v2 envelope (a legacy v1 envelope is accepted and flagged unsalted-v1). Alone it is checked for consistency only; next to run_proof_token it must equal the signed copy. | |
| run_proof_token | No | The run_proof_token returned by POST /api/agent-proof/run. The only input that can verify. | |
| expected_agent_id | No | Optional expected agt_ subject. | |
| expected_audience | No | Optional: require the run token's audience to equal this value. |