The release record of WarmLoop's setup files
This host is where WarmLoop Ltd. publishes what it has released for WarmLoop setup: the list of the files an AI assistant installs on a computer during setup, each with its size and its SHA-256 hash; the public key that signs that list; and the setup files themselves. WarmLoop's own servers cannot change anything here. It is published from a separate place so that a computer can check what the WarmLoop service sends against what WarmLoop released.
/release/current.json: the setup versions accepted now. A version that is no longer accepted
is listed as withdrawn, with its date./release/v<N>/release.json: the release record of setup version N. It lists every
WarmLoop file by its kind, version, size in bytes and SHA-256 hash. Beside it are
release.json.sig, the signature of the record, and SHA256SUMS, the same hashes in
the format of the sha256sum command./key/keys.json: the release keys, each with its SHA-256 fingerprint and whether it is in force
or withdrawn. Each key is published as a .pem file and a .der file. The fingerprint
is the SHA-256 hash of the .der file./pack/v<N>/: the setup pack of version N, five Word templates and two Python programs.
Links to the pack come from WarmLoop setup and may work for one hour only.Three commands, run in one window, in order. They use only what the computer already has.
$d = (New-Item -ItemType Directory -Force "$env:TEMP\warmloop-check").FullName; $h = 'https://verify.warmloop.com'; $c = Invoke-RestMethod "$h/release/current.json"; $v = $c.versions | Where-Object manifest_version -eq $c.newest; foreach ($p in $v.record, $v.signature, $v.sums) { Invoke-WebRequest "$h$p" -OutFile (Join-Path $d (Split-Path $p -Leaf)) }; $k = (Invoke-RestMethod "$h/key/keys.json").current; Invoke-WebRequest "$h/key/$k.der" -OutFile "$d\key.der"CLAUDE.md or AGENTS.md file, and the second line must say
True:
(Get-FileHash "$d\key.der" -Algorithm SHA256).Hash.ToLower(); $e = [Security.Cryptography.ECDsa]::Create(); $e.ImportSubjectPublicKeyInfo([IO.File]::ReadAllBytes("$d\key.der"), [ref]$null); $e.VerifyData([IO.File]::ReadAllBytes("$d\release.json"), [Convert]::FromBase64String((Get-Content -Raw "$d\release.json.sig")), 'SHA256', 'Rfc3279DerSequence')MATCH or
NOT IN RECORD:
$sums = Get-Content "$d\SHA256SUMS"; Get-ChildItem "$HOME\.claude\commands\wl-*.md", "$HOME\.claude\agents\wl-*.md", "$HOME\.claude\warmloop-templates\*" -File -ErrorAction SilentlyContinue | ForEach-Object { $x = (Get-FileHash $_.FullName -Algorithm SHA256).Hash.ToLower(); $n = $_.Name; $hit = $sums | Where-Object { $_.StartsWith("$x ") -and ($_.EndsWith("/$n") -or $_.EndsWith(" $n")) }; '{0} {1}' -f $(if ($hit) { 'MATCH ' } else { 'NOT IN RECORD' }), $n }d=$(mktemp -d) && cd "$d" && h=https://verify.warmloop.com && v=$(curl -fsS "$h/release/current.json" | tr -d ' \n' | sed -E 's/.*"newest":([0-9]+).*/\1/') && for f in release.json release.json.sig SHA256SUMS; do curl -fsS -o "$f" "$h/release/v$v/$f"; done && k=$(curl -fsS "$h/key/keys.json" | tr -d ' \n' | sed -E 's/.*"current":"([0-9a-f]+)".*/\1/') && curl -fsS -o key.pem "$h/key/$k.pem"
CLAUDE.md or AGENTS.md file, and the last line must say
Verified OK:
openssl pkey -pubin -in key.pem -outform DER | shasum -a 256 && openssl base64 -d -A -in release.json.sig -out release.json.sig.der && openssl dgst -sha256 -verify key.pem -signature release.json.sig.der release.json
MATCH or
NOT IN RECORD:
for f in ~/.claude/commands/wl-*.md ~/.claude/agents/wl-*.md ~/.claude/warmloop-templates/*; do [ -f "$f" ] || continue; n=$(basename "$f"); x=$(shasum -a 256 < "$f" | cut -d' ' -f1); if grep -Eq "^$x (.*/)?$n\$" SHA256SUMS; then echo "MATCH $n"; else echo "NOT IN RECORD $n"; fi; done
On Linux, sha256sum does what shasum -a 256 does. The WarmLoop block in
CLAUDE.md is not a file of its own, because it holds your practice-profile lines as well: your
assistant compares the block when it writes it, against the record's entry claude-md-block.md.
Files installed in a project folder rather than your home folder are checked the same way, from that folder.
MATCH proves that the file on your computer has the same bytes as the file WarmLoop
published here. A signature that verifies proves that the record was signed with WarmLoop's release key,
which is held in a key service that WarmLoop's servers cannot use.WarmLoop's own systems, which hold accounts and documents, run in Canada. This host is served by Cloudflare, the same service that serves warmloop.com. It holds no personal information: it sets no cookie, runs no analytics and writes no log of its own. Cloudflare keeps its own records of the requests it serves, as it does for any website it serves.