Implementations

Implementations that pass the SignedReceipt conformance test suite. Every entry below is currently self-attested by its vendor — the conformance corpus is not published yet, so no result here has been independently reproduced.

Reference implementations

Maintained by CloakAPI, the project’s current sole steward. Apache-2.0 licence.

Rust crate

MSRV 1.75. Features: std, fips (aws-lc-rs), wasm. Built from source; not released on crates.io, and no SLSA provenance is published (build provenance is currently SLSA Level 0).

signedreceipts.org/source/reference-rust →

TypeScript package

Signatures via @noble/curves; two runtime dependencies. Built from source; not released on npm.

signedreceipts.org/source/reference-typescript →

Verifier CLI

Published binary cloak-receipt 0.1.0 for Linux x86_64 and Windows x86_64. Linux commands: verify, build, chain-verify, serve. No source tarball is published on this site.

signedreceipts.org/source/verifier-cli →

Product implementations

ProductVendorLanguageLicenceStatusBadge
CloakAPI Desktop CloakAPIRust + SvelteProprietary v1 compatible SignedReceipt v1
CloakAPI Gateway CloakAPIPHP (Laravel)Proprietary v1 compatible SignedReceipt v1
CloakAPI Browser Extension CloakAPITypeScriptProprietary v1 compatible SignedReceipt v1
CloakAPI Browser Portal CloakAPITypeScriptProprietary v1 compatible SignedReceipt v1

Submit your implementation

Is your product compatible? There is no public pull-request workflow yet — email your conformance run to open-source@cloakapi.io. Registry format: source/badges The registry entry carries your CI results and signed conformance report. See the badge program for acceptance criteria.