Provenance
Verify a manifest
Every authorised output carries a manifest naming the creator, the boundary-set version it was authorised under, the requester and the time — signed with HMAC-SHA256. Check one here, or look one up by generation id.
Look up by generation id
Verify a manifest you are holding
Checks the signature against this deployment’s key. Nothing is stored.