Self-hosted · CloakAPI-stewarded

Source artefacts.

The SignedReceipts open-source artefacts are stewarded here, on signedreceipts.org. Reference libraries, the verifier CLI, the conformance corpus, the badge registry, and the normative spec source. The downloadable source distribution is still being prepared and is not yet published — the pages below describe each artefact.

The open-source family

Three licences. Reference libraries and the verifier are Apache-2.0; the conformance corpus mixes Apache-2.0 (harness) and CC0 (vectors); the spec itself is CC-BY-4.0. A signed, downloadable source distribution is being prepared and is not yet published.

Reference libraries

reference-rust

Reference Rust crate. JCS canonicalisation, ECDSA P-256 signing and verification, chain validation. Optional aws-lc-rs signing backend (not the FIPS build).

Rust 1.82+Apache-2.0FIPS feature

reference-typescript

Reference TypeScript package. Signatures via @noble/curves; two runtime dependencies.

Node 20+Browser ESMApache-2.0

Go and Python reference libraries are planned but not yet implemented.

Tooling

verifier-cli

Published binary cloak-receipt 0.1.0 for Linux x86_64 and Windows x86_64. Linux commands: verify, build, chain-verify, serve. No source tarball is published on this site.

Rust binaryApache-2.0
Specification & governance

conformance

The conformance test corpus: 248 known-good and 187 known-bad vectors, plus an Apache-2.0 harness that drives any reference library. Vectors themselves are CC0 to make embedding trivial.

Test corpusApache-2.0 harnessCC0 vectors

badges

The badge-claimants registry. Planned format: one YAML file per claimant with the producer's published JWKS URL and a signed sample receipt. Not published yet; the submission form drives the public listing on /implementations/.

YAML registryApache-2.0

spec

The normative specification source — Markdown plus the JSON Schema and the canonical test vectors referenced from the appendices. CC-BY-4.0 so anyone can quote, fork, or translate the spec without asking permission.

Markdown + JSON SchemaCC-BY-4.0

How releases will work

A signed, downloadable source distribution is being prepared. Each artefact is intended to ship a MANIFEST.sha256 with file-by-file fingerprints and a top-level signature over that manifest. No tarballs are published yet. Issues, patches, or questions go to open-source@cloakapi.io.