Process a verdict yourself
Root Herald can enforce your policy for you, or hand your server what it found so you make the call yourself.
Build a policy that reports instead of blocking
In the dashboard, build an identity policy that lets devices through with a warning rather than refusing them. Accept every kind of chip you might want to judge, choose Warn for a chip not on the list, Admit as unverified for a chip no maker vouches for, and Warnings pass too. Devices outside what you'd normally accept now come back warn, with their facts, instead of fail. Policies walks through the builder.
Let the key disclose everything
On API keys, open the key and set its disclosure to Full.
Ask for everything on verify
On your server, pass requestedDisclosureClass: "full" to verify. Root Herald answers with every fact it found, up to the key's ceiling.
const result = await rh.verify(evidence, {
nonce,
requestedDisclosureClass: "full",
});Decide on your server
Now the decision is yours. Read the facts you care about and act on them. Claims are the sturdiest thing to gate on, because they mean the same on every platform; the device block adds the detail. The full list of fields is under Read the verdict.
const { device, assuranceClaimsMet = [] } = result;
if (!device.quoteVerified) {
return deny();
}
const realHardware = assuranceClaimsMet.includes(
"rootherald:assurance:real-device",
);
const secureBoot = device.secureBootVerified === true;
const commonSetup = device.novelProfile !== true;
if (realHardware && secureBoot && commonSetup) {
return allow();
}
return stepUp();A quote that doesn't verify, or a change your policy blocks, fails whatever else the policy allows, and most facts are left out of that verdict. verify doesn't say why a device failed.