Implementations
Implementations that pass the SignedReceipt conformance test suite. Every entry below is currently self-attested by its vendor — the conformance corpus is not published yet, so no result here has been independently reproduced.
Reference implementations
Maintained by CloakAPI, the project’s current sole steward. Apache-2.0 licence.
Rust crate
MSRV 1.75. Features: std, fips (aws-lc-rs), wasm. Built from source; not released on crates.io, and no SLSA provenance is published (build provenance is currently SLSA Level 0).
TypeScript package
Node 20+. Browser ESM build with SubtleCrypto. Zero runtime dependencies. Built from source; not released on npm.
signedreceipts.org/source/reference-typescript →Verifier CLI
Binary signedreceipt. Commands: verify, verify-chain, show, canonicalise. Built from source; there is no crates.io, Homebrew, Scoop, or winget release at this time.
Product implementations
| Product | Vendor | Language | Licence | Status | Badge |
|---|---|---|---|---|---|
| CloakAPI Desktop | CloakAPI | Rust + Svelte | Proprietary | v1 compatible | SignedReceipt v1 |
| CloakAPI Gateway | CloakAPI | PHP (Laravel) | Proprietary | v1 compatible | SignedReceipt v1 |
| CloakAPI Browser Extension | CloakAPI | TypeScript | Proprietary | v1 compatible | SignedReceipt v1 |
| CloakAPI Browser Portal | CloakAPI | TypeScript | Proprietary | v1 compatible | SignedReceipt v1 |
Submit your implementation
Is your product compatible? There is no public pull-request workflow yet — email your conformance run to open-source@cloakapi.io. Registry format: source/badges The registry entry carries your CI results and signed conformance report. See the badge program for acceptance criteria.