Implementations

Implementations that pass the SignedReceipt conformance test suite. Every entry below is currently self-attested by its vendor — the conformance corpus is not published yet, so no result here has been independently reproduced.

Reference implementations

Maintained by CloakAPI, the project’s current sole steward. Apache-2.0 licence.

Rust crate

MSRV 1.75. Features: std, fips (aws-lc-rs), wasm. Built from source; not released on crates.io, and no SLSA provenance is published (build provenance is currently SLSA Level 0).

signedreceipts.org/source/reference-rust →

TypeScript package

Node 20+. Browser ESM build with SubtleCrypto. Zero runtime dependencies. Built from source; not released on npm.

signedreceipts.org/source/reference-typescript →

Verifier CLI

Binary signedreceipt. Commands: verify, verify-chain, show, canonicalise. Built from source; there is no crates.io, Homebrew, Scoop, or winget release at this time.

signedreceipts.org/source/verifier-cli →

Product implementations

ProductVendorLanguageLicenceStatusBadge
CloakAPI Desktop CloakAPIRust + SvelteProprietary v1 compatible SignedReceipt v1
CloakAPI Gateway CloakAPIPHP (Laravel)Proprietary v1 compatible SignedReceipt v1
CloakAPI Browser Extension CloakAPITypeScriptProprietary v1 compatible SignedReceipt v1
CloakAPI Browser Portal CloakAPITypeScriptProprietary v1 compatible SignedReceipt v1

Submit your implementation

Is your product compatible? There is no public pull-request workflow yet — email your conformance run to open-source@cloakapi.io. Registry format: source/badges The registry entry carries your CI results and signed conformance report. See the badge program for acceptance criteria.