Implementations
Implementations that pass the SignedReceipt conformance test suite. Every entry below is currently self-attested by its vendor — the conformance corpus is not published yet, so no result here has been independently reproduced.
Reference implementations
Maintained by CloakAPI, the project’s current sole steward. Apache-2.0 licence.
Rust crate
MSRV 1.75. Features: std, fips (aws-lc-rs), wasm. Built from source; not released on crates.io, and no SLSA provenance is published (build provenance is currently SLSA Level 0).
TypeScript package
Signatures via @noble/curves; two runtime dependencies. Built from source; not released on npm.
Verifier CLI
Published binary cloak-receipt 0.1.0 for Linux x86_64 and Windows x86_64. Linux commands: verify, build, chain-verify, serve. No source tarball is published on this site.
Product implementations
| Product | Vendor | Language | Licence | Status | Badge |
|---|---|---|---|---|---|
| CloakAPI Desktop | CloakAPI | Rust + Svelte | Proprietary | v1 compatible | SignedReceipt v1 |
| CloakAPI Gateway | CloakAPI | PHP (Laravel) | Proprietary | v1 compatible | SignedReceipt v1 |
| CloakAPI Browser Extension | CloakAPI | TypeScript | Proprietary | v1 compatible | SignedReceipt v1 |
| CloakAPI Browser Portal | CloakAPI | TypeScript | Proprietary | v1 compatible | SignedReceipt v1 |
Submit your implementation
Is your product compatible? There is no public pull-request workflow yet — email your conformance run to open-source@cloakapi.io. Registry format: source/badges The registry entry carries your CI results and signed conformance report. See the badge program for acceptance criteria.