PRE-GEN

Implement

Independent implementation kit · edition pre-gen-v5-rc1, 3 October 2026

No team other than the author has yet implemented PRE-GEN from the text alone. That is the main thing standing between a careful specification and a standard, and no amount of writing by the author can close it. This page is everything you need to do it.

What to build

The offline checks of the PRE-GEN v5 Verifier profile (PRE-GEN-SPEC.md §8.1), in any language:

  • canonical JSON and key fingerprints (§2, §2.1);
  • Ed25519 signature verification over canonical JSON;
  • a license: the subject's signature and the operator's countersignature over body, subject signature and license id (§1.2, V-9);
  • the signed registry directory (PG-CODE.md §9.1, V-12) and which key may sign in which namespace (V-10).

Minting PG codes is not part of it. A small library or command-line tool is enough.

Rules that keep it independent

  • Work from the edition below only: the text, the vectors and the runner. Do not read or port the reference code (the PRAMPTA backend, @prampta/sdk, @pregen/verify, pregen) until your run passes.
  • Ask questions in public, as GitHub issues. An answer that is not already in the text is an erratum, and the text gets fixed.
  • Write down what took long or was ambiguous. That is as valuable as passing.

The edition

Git tag pre-gen-v5-rc1. SHA-256 of the files that define it:

FileSHA-256
spec/PRE-GEN-SPEC.md8cb4829148089820…d4d81722
spec/PG-CODE.md716822e3b41e2d67…89f6dc5c
spec/test-vectors/vectors.jsoneaf94fa0af10507a…3f25010a
spec/conformance/README.md23f0285d789936f8…9aaa69ea
spec/conformance/level1/run_conformance.py6cba49c4d80fabf5…ce1cf241

Run it

Your implementation talks to the runner through a small adapter: one JSON request on stdin, one JSON answer on stdout, one process per call (conformance/README.md, Level 1). Five operations:

{"op": "canonical_json", "input": {…}}                  → {"canonical_utf8": "…", "sha256_hex": "…"}
{"op": "verify_signature", "message": {…}, "public_key_hex": "…", "signature_hex": "…"}  → {"valid": true}
{"op": "verify_license", "body": {…}, "license_id": "…", "subject_public_key_hex": "…",
 "subject_signature_hex": "…", "operator_public_key_hex": "…", "operator_signature_hex": "…"}
                                                       → {"subject_valid": true, "operator_valid": true}
{"op": "verify_directory", "directory": {…}, "steward_public_key_hex": "…", "min_sequence": 0}  → {"valid": true}
{"op": "check_namespace", "directory": {…}, "steward_public_key_hex": "…", "code": "…", "signer_key_id": "…"}
                                                       → {"result": "valid" | "issuer_mismatch" | "unknown_issuer"}
anything else                                          → {"unsupported": true}
git clone https://github.com/Pastheroza/PRE-GEN-site.git && cd PRE-GEN-site && git checkout pre-gen-v5-rc1
python3 spec/conformance/level1/run_conformance.py --adapter "<command that runs your adapter>" \
  --require-op canonical_json --require-op verify_signature --require-op verify_license \
  --require-op verify_directory --require-op check_namespace

Done when

  • the runner reports 0 failed with every required operation run (the pg_* code-minting operations are reported as skipped, which is expected);
  • you have filed an implementation report: language, size, hours, the runner's summary line, and every question you had to ask.

With your permission, the first passing independent implementation is named on pregen.org and in the next PRE-GEN version.

What this does not cover

The runner does not check what a provider does with a decision: matching it to the request, its lifetime and the user binding (V-3, V-4, V-13) are client behaviour, listed as not checked in §8.2. The Provider and Registry profiles need the Level 2 checks against a running registry. Passing this kit is a first independent result, not a full conformance claim.