Authenticated self-hosted

Durable review queue

Intake immutable offline artifacts, submit a human decision, and inspect independent receipt proof claims. Authentication is supplied by the self-hosted deployment; this client stores no token and never executes infrastructure.

This workbench connects to a self-hosted ChangeSafe server that you run. The public deployment at change-safe.vercel.app has none configured, so the queue below is empty by design — not broken.

Running your own server? Set CHANGESAFE_PUBLIC_SELF_HOSTED_GATEWAY_URL to its browser-visible HTTPS gateway URL. This public setting must contain no credential; authentication stays in an HttpOnly session cookie.

Self-hosting guideSource on GitHub

The gateway URL is public, browser-visible configuration. It must use HTTPS outside explicit loopback development and must never contain credentials; authentication remains in an HttpOnly session cookie.

What self-hosting adds

Beyond public replay

OIDC approver identity
A decision is bound to a real signed-in issuer and subject, not an anonymous click in a browser.
Server-recomputed findings
Policies are re-evaluated on every read from the server, so the UI can never show a stale or spoofed verdict.
Signed receipts
Every decision is written as an Ed25519-signed receipt, checkable out of band against a public key you control.
Ledger inclusion
Receipts append to a hash-chained ledger; a removed, altered, or reordered entry is detectable, not just implied.

What a resolved review looks like

Independent receipt proof

Example

Fictional claims for illustration only — not a real review, not signed by any key.

Content integrity
verified
eeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee
Signature presence
present
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
Out-of-band verification
valid
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
Ledger inclusion
included
Sequence 42
Ledger chain
verified
cccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccc