Cloud and BYOC for Orca Agent Engine are in Private Preview — request an invite
Docs

Signed tapes

Understand the signed-tape format and current runtime limitation in Orca AI Gateway.

A tape is a signed sequence of request and response chunks. Each tape records the previous tape id, so a verifier can detect modified, removed, or reordered files.

Live gateway requests do not produce tapes. The server constructs a configured signed_tape exporter, but request paths emit only spans and never send a tape to it. Do not configure tapes as an audit or compliance control.

File format

The implemented writer stores one JSON Lines file per tape under <base_dir>/YYYY-MM-DD/<tape_id>.jsonl. A file contains:

header  tape id, previous tape id, signer id, creation time
chunk   request, response chunk, or completion payload
footer  Ed25519 signature and payload SHA-256

The tape id covers the canonical body, previous tape id, and signer id. The signature covers the deterministic header and chunk payload. Verification checks the digest, signature, and chain.

Exporter configuration

This configuration initializes the writer, but does not connect live requests to it:

plugins:
  trace_exporters:
    - name: tapes
      kind: signed_tape
      base_dir: /var/lib/orca-gateway/tapes
      signer_id: local
      signer_key_pem: /var/lib/orca-gateway/keys/tape.pem

base_dir is required. signer_key_pem points to a PKCS#8 Ed25519 private key. If it is omitted, the server generates an ephemeral test key and logs a warning. The separate plugins.signers[] slot is not used by this exporter construction path.

Verify an existing tape

You can verify tape files produced by a test or another component:

orca-gateway tape verify /var/lib/orca-gateway/tapes/ \
  --signer-key /etc/orca-gateway/keys/tape-public.pem \
  --signer-id local

path is a tape file or directory. --signer-id defaults to local. Omitting --signer-key checks framing and chain integrity in accept-any-signer mode, but does not establish that a trusted key signed the tape.

Inspect a tape

orca-gateway tape replay <tape-id> \
  --target openai-primary \
  --path /var/lib/orca-gateway/tapes/

replay resolves and verifies the tape, then prints its recorded request and response.

Replay does not issue a live request. --target is accepted but is not dispatched, and the command does not compare a new response with the recording.

On this page