Readback now requires commit identity and live evidence before verifying a Cloudflare deployment. It applies host restrictions to every redirect, rejects credential-bearing URLs, masks recognized credentials in evidence, and reports truncated file or HTTP checks as indeterminate when unread content could contain the match. Successful GitHub Check Runs no longer remain pending because legacy statuses are empty. Output failures cannot report success.
Results include the checked condition alongside evidence. Terminal output shows concise evidence, discovery distinguishes beta and planned commands, and schema verify names the input and result schemas. The website and README explain the tool in plain English and include an actual JSON result.
Compatibility: exit codes and claim status names are unchanged. Results gain claim, the reason set gains response_truncated, and discovery JSON now uses compact summaries and named schemas. Health-only deployment checks need no Cloudflare API token; an explicitly requested Worker version check still does.
Validation includes Go checks, adversarial fixtures, before/after binary reproductions, desktop/mobile website checks, and independent Kimi K3 and GLM 5.3 correctness and code-Heaton reviews. Readback remains early software: choose required assertions and inspect the evidence before approving a release.