Match witnessed
The declared value matches explicit provider readback after a documented normalization.
Read back. Compare. Keep the receipt.
Apply Witness checks every declared Supabase auth field against what the provider returns. Ignored fields stay visibly unknown—never green.
The false-success gap
A CLI can return success while sending none of a configuration section. A diff cannot show fields that never made the request.
Live proof desk
This browser demo runs locally. Edit either side, then witness it. Nothing leaves this page.
Run the witness to classify each declared field.
One binary. No daemon.
Use live provider readback after an apply, or a captured JSON response for deterministic tests. Exit code 2 blocks changed and unknown fields.
cargo install --git https://github.com/B-Divyesh/sf-config-apply-witness --locked
export SUPABASE_ACCESS_TOKEN="…"
apply-witness verify \
--config supabase/config.toml \
--project-ref abcdefghijklmnop \
--receipt witness.json
Three honest states
The declared value matches explicit provider readback after a documented normalization.
The provider returned the field, but its observed value differs from the declaration.
The API omitted the field or no audited mapping exists. Unknown always fails the policy.
Team Receipt Kit
Unlock manifest-based multi-project runs, compact CI summaries, and local daily license caching. Single-project verification, JSON export, redaction, and every safety check stay free.
Free CLI active. No license stored.
Privacy · Terms · Refunds are handled by the merchant of record and revoke the license.