Skip to main content

What are attestations?

An attestation is a cryptographically signed proof that a verification occurred. It:
  • Uses ES256 (ECDSA P-256) signatures
  • Is formatted as a JWT
  • Can be verified independently
  • Can be stored on-chain

Requesting attestations

Fail-closed contract

Since PR #194 (Issue #188): create_verification_attestation() never returns None. It always returns an AttestationResult with status set to ISSUED, BLOCKED, or UNVERIFIABLE. You MUST check result.is_issued before you treat the attestation as valid. A missing or failed attestation must hard-block the verification path. Never downgrade it to VERIFIED.

AttestationResult

AttestationStatus
required
Lifecycle state of the attestation. One of ISSUED, BLOCKED, or UNVERIFIABLE.
string | None
Signed JWT string. Present only when status == ISSUED; None otherwise.
string | None
Machine-readable failure code: "SIGNING_FAILURE" when signing failed, "CRYPTO_UNAVAILABLE" when the cryptography / PyJWT package is not installed, None on success.
string | None
Human-readable failure detail. None on success.
bool
Property. True only when status is AttestationStatus.ISSUED. You must check this flag before you use token.

AttestationStatus values

Caller pattern

Key lifecycle auditability

Every IssuerKeyPair records generated_at (epoch seconds) and key_continuity_policy. QWED emits a structured log entry (attestation.key_generated) on every new key generation, so you can audit continuity events.
string
default:"ephemeral"
Policy for the issuer key pair. Must be one of "ephemeral" (in-memory, non-persistent — default) or "persistent" (durably stored, e.g. external KMS). Any other value raises ValueError.
AttestationService.get_issuer_info() now includes key_generated_at and key_continuity_policy alongside the existing issuer registry fields.

Attestation structure

Payload

Verifying attestations

Using the API

Using the SDK

Trust anchors

QWED maintains a registry of trusted attestation issuers:

Attestation chains

Link multiple attestations together:

Use cases

  1. Audit Trails - Prove AI outputs were verified
  2. Compliance - Regulatory verification records
  3. Blockchain - Anchor proofs on-chain
  4. Badges - Show verification status in UIs

Badge integration

Embed attestation badges: