badges
v1.0.0The badge-claimants registry. One YAML per claimant with the producer's published JWKS URL, conformance run digest, and a signed sample receipt. Pull requests drive the public listing.
About this artefact
The badges artefact is the public registry of every implementation that has self-attested compatibility. Each claimant submits one YAML file under claimants/<slug>.yaml containing the implementation's name, vendor, source URL, the producer's published JWKS URL, the conformance run digest from conformance, and a base64-encoded sample receipt.
CloakAPI reviews each submission manually — checking JWKS reachability, replaying the conformance digest, and validating the sample receipt against the claimed JWKS. There is no automated validation and no fixed review cadence. Accepted entries appear on the public /implementations/ table. Submissions go via signed email patches to open-source@cloakapi.io.
Manifest
| Path | Size | SHA-256 |
|---|---|---|
README.md | 1.8 KB | b52b737c1527afc46ff1180a9a2d97144945faad7cd721a9651c0ab268d23542 |
schema/claimant.schema.json | 3.4 KB | f3df5b45519996efec76e9773d1d8cc2cd4ce108d6822199df082d2a52a31793 |
claimants/cloakapi-gateway.yaml | 0.9 KB | aa2d001ac12346728ffad8be1db5a635703878acdecdbf6afc3bc56422681761 |
claimants/cloakapi-desktop.yaml | 0.9 KB | 817f6d0a1148f994d2e94f9ec984bb7d1078b6a74149032b0e6d2eff8c6cccf7 |
claimants/cloakapi-extension.yaml | 0.8 KB | e4cc57a0e4862f28fb61cd1870face9e77b566994af05c7914a0fa8f0b0b90fa |
8af4c92dQuick start
name: ExampleGW vendor: Example, Inc source: https://example.com/signedreceipts jwks_url: https://api.example.com/.well-known/jwks.json conformance_digest: sha256:8af4c92d... sample_receipt: base64:eyJ2IjoiMS4w... contact: security@example.com
# Validate your YAML before submitting signedreceipt jwks fetch https://api.example.com/.well-known/jwks.json signedreceipt verify --jwks ./jwks.json sample-receipt.json # Mail the patch to CloakAPI git format-patch -1 --stdout | mail -s '[badge] ExampleGW' open-source@cloakapi.io
Issues / questions
Bug reports, patches, and security advisories all go to the CloakAPI open-source inbox.
Back to /source/ · related: spec · conformance · implementations