Delivery & integration#

Ways to consume HashWatch verified known-good hashes in your own tooling.

  • CLIhashwatch verify a file, a URL, or a digest; exit-code driven so it fails a build on an unverified artifact.
  • Pull feeds — JSON, RSS, STIX 2.1, and a read-only TAXII 2.1 server (require an API key). Any HTTP client, or any TAXII 2.1 client, can poll them on a schedule and use the hashes as a known-good allowlist.

All feeds link the signed transparency root so you can verify the data was not tampered with.