/source/ · YAML registry · Apache-2.0

badges

v1.0.0

The badge-claimants registry. Planned format: one YAML per claimant with the producer's published JWKS URL and a signed sample receipt. Not published yet; listings come from the submission form.

published March 2026

About this artefact

The badges artefact will be the public registry of implementations that self-attest compatibility. It is not published yet; today, accepted listings appear on the /implementations/ table.

CloakAPI reviews each submission manually — checking that the JWKS URL is reachable and that the sample receipt verifies against it. There is no automated validation and no fixed review cadence. Submissions go through the submission form.

Manifest

No tarball or file manifest is published yet. When a release is published, its file list and SHA-256 fingerprints will be computed from the published files and listed here.

Quick start

claimants/your-impl.yaml
name: ExampleGW
vendor: Example, Inc
source: https://example.com/signedreceipts
jwks_url: https://api.example.com/.well-known/jwks.json
conformance_digest: sha256:8af4c92d...
sample_receipt: base64:eyJ2IjoiMS4w...
contact: security@example.com
shell
# Validate your YAML before submitting
signedreceipt jwks fetch https://api.example.com/.well-known/jwks.json
signedreceipt verify --jwks ./jwks.json sample-receipt.json

# Mail the patch to CloakAPI
git format-patch -1 --stdout | mail -s '[badge] ExampleGW' open-source@cloakapi.io

Issues / questions

Bug reports, patches, and security advisories all go to the CloakAPI open-source inbox.

open-source@cloakapi.io

Back to /source/ · related: spec · conformance · implementations