oap audit
Verify the tamper-evident audit log of a session
oap audit verify <session>
Verify recomputes each publisher's hash chain and Ed25519 signatures over the session's append-only memory entries, using the K8s-witnessed audit public key (AgentSession.status), component publisher keys (the publisher-keys ConfigMap), and any retired session key an operator-signed record in the scope attests — the keys of AgentSessions that held this name before, whose own status went with them. It detects tampered payloads (bad signature), dropped entries (gap), duplicate/relinked entries (fork), entries signed by untrusted keys (unknown key), and — for ended sessions whose chain heads were anchored on status — tail truncation.
Exit status is non-zero when any hard finding is present, and also when a publisher's recorded chain head cannot be decoded — that head is what makes tail truncation detectable at all, so an undecodable one leaves the tail unverified. Unsigned entries (pre-provenance or written by an unsigned writer) are reported as a warning and do NOT, on their own, fail verification.
Flags:
--json Emit the per-publisher reports as JSON