verify.warmloop.com

The release record of WarmLoop's setup files

This host is where WarmLoop Ltd. publishes what it has released for WarmLoop setup: the list of the files an AI assistant installs on a computer during setup, each with its size and its SHA-256 hash; the public key that signs that list; and the setup files themselves. WarmLoop's own servers cannot change anything here. It is published from a separate place so that a computer can check what the WarmLoop service sends against what WarmLoop released.

What it holds

How to check a release by hand

Three commands, run in one window, in order. They use only what the computer already has.

Windows, PowerShell 7

  1. Fetch the newest record, its signature, its hash list and the release key into a temporary folder:
    $d = (New-Item -ItemType Directory -Force "$env:TEMP\warmloop-check").FullName; $h = 'https://verify.warmloop.com'; $c = Invoke-RestMethod "$h/release/current.json"; $v = $c.versions | Where-Object manifest_version -eq $c.newest; foreach ($p in $v.record, $v.signature, $v.sums) { Invoke-WebRequest "$h$p" -OutFile (Join-Path $d (Split-Path $p -Leaf)) }; $k = (Invoke-RestMethod "$h/key/keys.json").current; Invoke-WebRequest "$h/key/$k.der" -OutFile "$d\key.der"
  2. Print the key's fingerprint, then check the signature. The fingerprint must equal the one in the WarmLoop block of your CLAUDE.md or AGENTS.md file, and the second line must say True:
    (Get-FileHash "$d\key.der" -Algorithm SHA256).Hash.ToLower(); $e = [Security.Cryptography.ECDsa]::Create(); $e.ImportSubjectPublicKeyInfo([IO.File]::ReadAllBytes("$d\key.der"), [ref]$null); $e.VerifyData([IO.File]::ReadAllBytes("$d\release.json"), [Convert]::FromBase64String((Get-Content -Raw "$d\release.json.sig")), 'SHA256', 'Rfc3279DerSequence')
  3. Compare each installed WarmLoop file with the record. Each line says MATCH or NOT IN RECORD:
    $sums = Get-Content "$d\SHA256SUMS"; Get-ChildItem "$HOME\.claude\commands\wl-*.md", "$HOME\.claude\agents\wl-*.md", "$HOME\.claude\warmloop-templates\*" -File -ErrorAction SilentlyContinue | ForEach-Object { $x = (Get-FileHash $_.FullName -Algorithm SHA256).Hash.ToLower(); $n = $_.Name; $hit = $sums | Where-Object { $_.StartsWith("$x  ") -and ($_.EndsWith("/$n") -or $_.EndsWith("  $n")) }; '{0}  {1}' -f $(if ($hit) { 'MATCH        ' } else { 'NOT IN RECORD' }), $n }

macOS or Linux, in a terminal

  1. Fetch the newest record, its signature, its hash list and the release key into a temporary folder:
    d=$(mktemp -d) && cd "$d" && h=https://verify.warmloop.com && v=$(curl -fsS "$h/release/current.json" | tr -d ' \n' | sed -E 's/.*"newest":([0-9]+).*/\1/') && for f in release.json release.json.sig SHA256SUMS; do curl -fsS -o "$f" "$h/release/v$v/$f"; done && k=$(curl -fsS "$h/key/keys.json" | tr -d ' \n' | sed -E 's/.*"current":"([0-9a-f]+)".*/\1/') && curl -fsS -o key.pem "$h/key/$k.pem"
  2. Print the key's fingerprint, then check the signature. The fingerprint must equal the one in the WarmLoop block of your CLAUDE.md or AGENTS.md file, and the last line must say Verified OK:
    openssl pkey -pubin -in key.pem -outform DER | shasum -a 256 && openssl base64 -d -A -in release.json.sig -out release.json.sig.der && openssl dgst -sha256 -verify key.pem -signature release.json.sig.der release.json
  3. Compare each installed WarmLoop file with the record. Each line says MATCH or NOT IN RECORD:
    for f in ~/.claude/commands/wl-*.md ~/.claude/agents/wl-*.md ~/.claude/warmloop-templates/*; do [ -f "$f" ] || continue; n=$(basename "$f"); x=$(shasum -a 256 < "$f" | cut -d' ' -f1); if grep -Eq "^$x  (.*/)?$n\$" SHA256SUMS; then echo "MATCH          $n"; else echo "NOT IN RECORD  $n"; fi; done

On Linux, sha256sum does what shasum -a 256 does. The WarmLoop block in CLAUDE.md is not a file of its own, because it holds your practice-profile lines as well: your assistant compares the block when it writes it, against the record's entry claude-md-block.md. Files installed in a project folder rather than your home folder are checked the same way, from that folder.

What the check proves, and what it does not

Where this host runs

WarmLoop's own systems, which hold accounts and documents, run in Canada. This host is served by Cloudflare, the same service that serves warmloop.com. It holds no personal information: it sets no cookie, runs no analytics and writes no log of its own. Cloudflare keeps its own records of the requests it serves, as it does for any website it serves.