Colosseum · World’s Fair 2026

EVIDENCE
BEFORE
ACTION.

Real libraries. The same bytes. Different answers.

Compare three published versions of Solana Kit in your browser. See exactly where their decisions differ, inspect the bytes, and take the report with you.

Runs locally in your browser. No wallet, upload or installation.

Real libraries / Same inputSynthetic version-3 example

One input.
Three real readers.

Kit 3.0.3 decodes a message version that later releases reject. Run the published libraries and inspect the difference yourself.

@solana/kit 3.0.3ACCEPT · version 3
@solana/kit 4.0.0REJECT
@solana/kit 8.3.0REJECT
Reproduce this difference ↗

Expected example outcomes, not a live result. The comparison page executes the real libraries in your browser. Two decoder calls per version; synthetic bytes; impact unassessed.

Inspect the claim.Reproduce the result.Keep the limits visible.

The hackathon submission

Real comparisons.
Reproducible evidence.

00

Start here / Published Solana libraries

Replay the same bytes
across Kit versions.

Run Kit 3.0.3, 4.0.0 and 8.3.0 on identical input. Try a canonical control, reproduce the version-3 difference, or paste your own public hex or base64 bytes.

Fresh browser execution, exact API composition and downloadable unsigned results. A parse difference is evidence to investigate, not automatically a bug or a safety verdict.

Run the real-library comparison ↗
One exact byte sequenceThree pinned library versionsInspect & export the difference
01

In your browser

Find where a reader disagrees.

Run the deliberately broken reader and the reference against the same 30 recorded cases. Inspect expected versus observed decisions, then replay the report.

The finite experimental profile includes proposed Solana v1 behavior. A disagreement is against that profile, not a universal security verdict.

Open Raven Conformance ↗
Choose a targetInspect the differencesExport & replay
02

Offline · from the repository

Change one field.
Lose the trust.

An agent verifies a signed receipt against a pinned key. The valid fixture produces PROCEED; change one field without re-signing, and it produces REFUSE.

These are the demo agent’s policy outcomes. This uses a deterministic offline fixture, not a live-chain fetch or permission to transact.

Get the setup instructions ↗
After recursive checkout · Node 22.18.0
$ npm run demo
Valid receipt: PROCEEDOne-field tamper: REFUSE

Expected output · run locally to verify.

Explore the separate 30-case demonstration harness
01 / ConformanceExpected fixture outcomes

Same bytes.
Different answers.

Explore the guide’s expected results, then run the actual test.

  1. V01matches
  2. V02matches
  3. V03differs
  4. V04matches
  5. V05matches
  6. V06matches
  7. V07matches
  8. V08matches
  9. V09matches
  10. V10differs
  11. V11matches
  12. V12matches
  13. V13matches
  14. V14matches
  15. V15matches
  16. V16differs
  17. V17matches
  18. V18matches
  19. V19matches
  20. V20matches
  21. V21matches
  22. V22matches
  23. V23matches
  24. V24matches
  25. V25matches
  26. V26matches
  27. V27matches
  28. V28matches
  29. V29matches
  30. V30matches
27 / 30 match3 divergences

V03 & V16: proposed v1 layout (SIMD-0385). V10: non-canonical length.

Run these targets in the live demo ↗

Illustration of the judge guide, not a live result. Raven-owned targets · experimental profile · unsigned reports.

For the judges

Go straight
to the proof.

Start with a real-library difference. The retained research explains the wider decoder campaign; the guide covers the separate demonstration harnesses.

  1. 01

    Try it

    Open the real-library comparison. Run the synthetic version-3 example against all three Kit versions.

  2. 02

    Compare it

    Inspect the differing decisions, then run a canonical control. Download the report with the exact input bytes.

  3. 03

    Reproduce it

    Read the retained decoder research and the guide for the separate Conformance and offline Agent Trust demonstrations.

Trust has boundaries

The small print.
In plain sight.

A match is not a safety verdict.

Conformance and saved-case Replay reports are unsigned. They describe observed behavior within a stated scope, not universal correctness.

A signature is not authorization.

Signature validity, key trust and freshness are separate questions. Signed evidence receipts state their scope and coverage gaps; your policy decides what happens next.

A demo is not an external audit.

Hosted targets belong to Raven. Reviews are internal and bounded. Testing your decoder requires a local adapter and scoped engineering.

Beyond the hackathon

Evidence you can carry.
Claims you can inspect.

Raven’s hosted receipt-v1 API issues signed, scope-bounded evidence for Solana tokens. Alpha access is by request. Explore the product, verification process and archived examples.

Raven emblem
For developers: current API and receipt verification

Trust comes from your own pin.

New integrations use POST /receipt/v1. The POST /verify is legacy v2 compatibility only. The local developer path is unsigned; use the hosted receipt-v1 API for signed customer deliverables.

Recompute payloadHash using canonical JSON, check that receiptId matches it, and verify the domain-separated signature against your independently authenticated key. The receipt-v1 test vector contains the exact recipe.

/pubkey is discovery and cross-check only. Registry key ID rvk_c2997e90215279c2 belongs to legacy v2 metadata; it does not establish trust by itself. See the full verification guide and key policy.