---
title: "KYE Protocol™ — Self-audit fixture · publicly verifiable proof of mechanism"
description: "Signed JSON artefacts proving the KYE™ Reference Gateway™ governs and audits itself with its own primitives"
url: https://kyeprotocol.com/trust-self-audit/
lang: en
source: "KYE Protocol"
---

> Signed JSON artefacts proving the KYE™ Reference Gateway™ governs and audits itself with its own primitives

Self-audit fixture

# A signed proof that the engine governs and audits itself.

Three JSON artefacts — a self-audit run record, an engine-health snapshot and an audit-chain integrity check — signed with EdDSA over a canonical payload, verifiable by anyone using the published JWKS. The fixture is deterministic: the same inputs produce the same artefact, byte-for-byte. Production-grade self-audit runs (the live ones inside the KYE™ Reference Gateway™) sign with a key whose private half lives in HSM/KMS — [see protocol § self-govern](https://kyeprotocol.com/protocol/#self-govern).

1 · The three artefacts

## Three signed JSON files. Fetch them.

### self-audit-run.json

run record Outcome of a canonical 17-area run over the protocol's reference state. `schema_version`, `self_audit_id`, `profiles_tested`, `summary.tests_*`, `findings`, `evidence_refs`.

### engine-health.json

engine health Point-in-time snapshot of every engine: `schema_validator`, `dictionary_resolver`, `profile_resolver`, `registry_resolver`, `authority_engine`, `state_engine`, `policy_adapter`, `decision_engine`, `audit_engine`, `evidence_engine`, `graph_engine`, `webhook_engine`, `recovery_engine`.

### audit-integrity-check.json

chain integrity Hash-chain replay verification: events checked, orphan events, missing reason codes, missing evidence refs, overall result.

**JWKS** for verification: `trust/self-audit-jwks.json` — a single Ed25519 public key with kid `kye:key:self-audit-fixture-2026-05`.

2 · Verify it yourself

## One command. Zero credentials.

The verifier is a 90-line Node script in the public repo. It fetches the three artefacts and the JWKS, recomputes the canonical payload (sorted keys, no whitespace), and verifies the EdDSA signature. Node 18+ only — no `npm install`.

### A · Run the verifier (recommended)

```
curl -fsSL https://raw.githubusercontent.com/KYE-Protocol/app/main/scripts/verify-self-audit.mjs -o /tmp/verify-self-audit.mjs
node /tmp/verify-self-audit.mjs

# Expected output:
#   Loaded JWKS — 1 key(s): kye:key:self-audit-fixture-2026-05
#   ✓ self-audit-run.json  alg=EdDSA kid=kye:key:self-audit-fixture-2026-05
#   ✓ engine-health.json  alg=EdDSA kid=kye:key:self-audit-fixture-2026-05
#   ✓ audit-integrity-check.json  alg=EdDSA kid=kye:key:self-audit-fixture-2026-05
#   All artefacts verified.
```

### B · Or: roll your own

For each artefact: parse JSON, extract `payload` and `signature`, canonicalise `payload` (sorted keys, no whitespace), base64url-decode `signature.sig`, look up `signature.kid` in `self-audit-jwks.json`, and verify EdDSA. The fixture is small enough (< 4 kB) that a Python or Go verifier is ~30 lines.

3 · What this proves

## A real, working self-audit pipeline.

- **The mechanism is implemented and reproducible.** The same script that produces these fixtures runs in CI on every commit (`npm run test:self-audit-snapshot`); a regression in the schema, the audit-chain integrity check, or the engine-health snapshot would fail PR CI. Public visitors don't have to take our word for it.
- **The signing path is real.** EdDSA over canonical JSON, with a published JWKS, with a working verifier — not a mocked-up signature blob. The same construction is used by the live Reference Gateway™ for webhook signing and self-audit run records.
- **The schema is normative and stable.** `kye.self_audit_run.v1`, `kye.engine_health.v1`, `kye.audit_integrity_check.v1`. Schema drift would break the verifier.
- **The KYE™-on-KYE™ wiring exists in code, not just slides.** See [protocol § self-govern](https://kyeprotocol.com/protocol/#self-govern) — `POST /v1/self-audit:run` on the KYE™ Reference Gateway™ emits the same shape this fixture uses.

4 · Where to go next

## For procurement, regulator and security teams.

The reproducible fixture above proves the mechanism. Operational detail and the full hardening register are part of the procurement pack delivered to design partners under NDA.

[Protocol § self-govern](https://kyeprotocol.com/protocol/#self-govern) [Trust Center](https://kyeprotocol.com/trust/) [Procurement pack (NDA)](https://kyeprotocol.com/engage/#procurement-pack)

## Ready to see your AI agents flagged?

Start in shadow mode. We’ll deliver your first Evidence Pack™ in 4–8 weeks.

[Apply for pilot →](https://kyeprotocol.com/pilot-apply/) [Try the sandbox →](https://kyeprotocol.com/sandbox/demos/)

Canonical KYE™ surfaces referenced on this page: [Evidence Pack™](https://kyeprotocol.com/evidence-pack/) · [KYE Protocol™](https://kyeprotocol.com/).
