Delivery & integration#
Ways to consume HashWatch verified known-good hashes in your own tooling.
- CLI —
hashwatch verifya file, a URL, or a digest; exit-code driven so it fails a build on an unverified artifact. - Pull feeds — JSON, RSS, STIX 2.1, and a read-only TAXII 2.1 server (require an API key). Any HTTP client, or any TAXII 2.1 client, can poll them on a schedule and use the hashes as a known-good allowlist.
All feeds link the signed transparency root so you can verify the data was not tampered with.