Not a claim, a re-run. Below, two genuinely independent sovereign identities federate: one asks, the other answers from its own expertise, and the value is settled with a bounded provenance royalty upstream. Every signature is verified here, on your machine, against nothing but the public keys. Then a live version runs over a real WebRTC datachannel. And separately, the estate's mutation gate is run against a real external repo we don't own.
This exchange was produced cold with real Ed25519 (Node). The bundle below carries the two identities, the contributor's signed lineage, the signed query, the signed answer bound to that query, and the settlement. Press the button — your browser re-verifies every signature with WebCrypto. No secrets, no trust in our machine.
loading…
../evidence.json — the exact bytes, independently checkable.
This spins up two independent identities and connects them peer-to-peer over a real WebRTC datachannel (STUN for the public reflexive address — the sovereign way, no relay). One signs a query, sends it over the wire; the other verifies it, answers, signs; the first verifies and settles the payout. All in your browser, live. Same machine here, real transport — a second physical machine/human is the follow-on step (below).
The same witness gate that proves the estate's own code was run against left-pad — the public package that famously broke npm in 2016 — using its own passing test suite (35 tests). A mutation gate alters one operator at a time and requires the suite to catch it; a survivor means a line the green suite does not actually pin. This is a real, reproducible verdict on code we don't control.
Reproduce it: git clone https://github.com/left-pad/left-pad && cd left-pad && npm i, then run the estate's witness Action: witness mutate index.js --test node test.js. Result file: ../witness-external.json.
witness into a real external team's CI (a FAIL on a push to a repo we don't own) needs a willing external maintainer — a warm intro, not a stranger's repo spammed with a PR.