The issuer key (a public JWK, or the public keys of an AERE identity) is checked first: one that cannot be read, is private, or is not
a key for the algorithm asked exits 2 with the reason, instead of reporting the token INVALID. --json prints compact JSON (indented
output grew with the square of the claims' nesting depth). --at judges at a given time, as for verify. Test on the RFC 9901 example
presentation: valid at its own time, invalid now, a private key refused. Tests: SD-JWT 23/23, negative control 28/28; identity 44/44,
negative control 49/49.
- verify: --at <RFC 3339 UTC> judges on that clock (the verifier's clock in any case), so a verdict given at one moment can be checked
again later with the same result; a broken --trust-issuer or --max-age exits 2 with the reason instead of failing without a verdict;
the JSON result names the subject (type, credential, issuer, holder, presenter, delegations) when no check failed
- comply: --json [--with-record] prints the result and the record in one object; with --at the record's time is the same, so the same
command gives the same record byte for byte; a refused policy exits 2 with its reason
- Aere Cloud runs this command line unmodified behind POST /v1/identity/verify and POST /v1/compliance/check
Tests: identity 43/43, negative control 46/46.