Documentation
Start with the safe API, then follow the guide for your use case. Each guide has a runnable example with its own tests.
Start here
The safe API has two entry points. What you import says where your code runs, and what key it may hold:
| Import | Runs in | Holds a log’s private key |
|---|---|---|
webtessera/server | your server's private environment: Node.js 22.18+, Deno, Bun, Cloudflare Workers, Vercel Edge and other edge runtimes | yes: imported from your secret store, held by WebCrypto |
webtessera/browser | the browser's public environment: windows, workers, service workers | only a device key generated in that browser, which cannot be exported |
Open a log on a server, append an entry and verify its receipt:
src/README_test.ts lines 58–60 and 232–243 import { DatabaseSync } from "node:sqlite";
import { importLogKey, openServerLog, verifyReceipt } from "webtessera/server";
import { fromSqliteSync } from "webtessera/storage/sqlite";// The key comes from your secret store, never from source code.
const log = await openServerLog({
key: await importLogKey(process.env.LOG_SKEY),
storage: { sqlite: fromSqliteSync(new DatabaseSync("log.db")) },
});
// append resolves once a published checkpoint covers the entry, with a verified receipt.
const entry = new TextEncoder().encode("hello");
const receipt = await log.append(entry);
// Anyone with the log's vkey and the entry can check the receipt, offline.
const { index, checkpoint } = verifyReceipt(receipt.text, { vkey: log.vkey, data: entry });
To make the key, call generateKey(undefined, "example.com/log") from webtessera/note once.
Keep the skey it returns in your secret store, and publish the vkey.
The safe API guide explains each default, and what each entry point refuses.
Guides
One guide per use case, each walking through an example:
- A client-only log
- A browser keeps its own tamper-evident log in IndexedDB, signed by a device key that no script can export. Runs on browsers.
- Session receipts
- The browser records every exchange with your server; the server witnesses the record and commits it, verified, to a bucket. Neither side can rewrite it alone. Runs on browser + Node, Bun, Deno.
- A notary
- A service that logs document digests with their submitters' signatures, and returns receipts anyone can verify offline. Runs on Node, Bun, Deno.
- A log server
- A public log:
POST /addand the tlog-tiles read API, on any SQLite. Runs on Node, Bun, Deno. - A monitor
- A process that follows a log, proves it only grows, and reports forks and rollbacks. Runs on Node, Bun, Deno.
- At the edge
- The log server as a Worker on a SQLite-backed Durable Object, one deployment target among several. Runs on Cloudflare Workers.
And one per topic:
- The safe API:
webtessera/serverandwebtessera/browser - Read this guide before you open your first log: it covers the safe API’s environment model, key custody, the log
object and its errors, and when to drop down to the ported API. Receipts covers what
appendreturns and how anyone verifies it. - Receipts
appendandprovereturn a receipt: everything a verifier needs to check, offline, that an entry is in the log. This guide covers its format, how to verify one, and the data it can carry. It follows the safe API.- Choosing storage
- This guide compares the storage that webtessera supports and explains how locking keeps a log from forking; read it before you decide where a log lives.
- The ported API
- This guide walks through Tessera’s own API as webtessera ports it, and maps every package to its Go counterpart; read it when you need what the safe API leaves out, such as custom storage, migration, antispam, witness policies, key rotation or Static CT.
- Serving, witnessing and mirroring
- This guide covers serving a log (
webtessera/http), witnessing other logs (webtessera/witness) and mirroring a log into storage you control (webtessera/mirror); read it when you deploy a log, run a witness, or keep a copy of someone else’s log.
Concepts
Transparency logs, explained covers the design of a transparency log: Merkle trees, tiles, checkpoints, proofs, receipts and witnesses, with the specifications they come from.
Reference
The API reference has a page for each of the 22 entry points, with its exports, its Go counterpart and its source.