Skip to content
VylocoreBeta
Menu
Documentation

Tamper protection

Enable verification#

Enable Sign package in Advanced / Runtime & locks. Save the report's public key outside the ZIP.

Changed, missing or extra files fail verification.

Verify before shipping#

Use your saved key, not one from a suspicious copy: someone could replace both.

Verification command#

  1. Save security.verification.trusted_public_key.spki and security.build_id from your downloaded JSON report.
  2. Keep a trusted copy of security.verification.verifier_path outside future packages.
  3. Unpack the ZIP safely. Use security.verification.manifest_path inside that package. Keep only its original files; links are rejected.
  4. Run the trusted verifier:
node trusted-verify.mjs "$MANIFEST_PATH" "$PACKAGE_DIRECTORY" \
  "$TRUSTED_SPKI" "$EXPECTED_BUILD_ID"

Use your saved values. Success prints valid: true and exits zero. Never run an untrusted verifier.

Limits#

Signing detects changed files. It does not stop someone copying code or prove which JavaScript a browser runs.

Runtime checks are a separate optional layer.

Contact support

Documentation