Skip to main content
Two commands, owned by two packages, and the split matters. An auditor never needs the write SDK. Verification lives in its own package with no account, no key and no network.

bundle

Assemble the hand-over pack for one producer over one period.
Same flags, same exit codes, same output in both languages. One shared fixture grades them, and neither passes by agreeing with the other.
--logs is optional to the parser and required in practice. The command reads your record objects to work out which events are this producer’s, because a minimum-disclosure envelope does not carry that name.
Authentication comes from SANNING_API_KEY in the environment. There is no flag for it. The key needs anchor:read. It verifies its own output before writing. If the assembled pack does not verify, nothing is written and the command exits non-zero. A pack that only fails at the auditor is a pack shipped broken.

verify

Check a pack. No account, no key, no relationship with Sanning.
sanning-proof on PyPI is the same kernel and ships no command line. Use its library API. See Verify at the command line.

Getting help

--help works on the top-level command in both languages. On a subcommand it exits 2 with unknown argument: --help, which is a rough edge rather than a failure.