/source/ · Rust 1.75+ · Apache-2.0 · FIPS feature

reference-rust

v1.0.0

The canonical Rust crate for producing and verifying SignedReceipts envelopes. JCS canonicalisation, ECDSA P-256, chain validation, and an optional aws-lc-rs signing backend (not the FIPS build).

published March 2026

About this artefact

cloakapi-open-receipt is the reference Rust crate for the OpenReceipt envelope format. It has a receipt builder, JCS canonicalisation per RFC 8785, ECDSA P-256 signing and verification (RustCrypto p256), and chain verification. Its declared minimum Rust version is 1.82. It is not yet released on crates.io.

An optional fips feature signs with aws-lc-rs instead of p256. It does not enable the FIPS build of AWS-LC, so it does not by itself give you a FIPS 140-validated module. No tarball or crates.io release is published yet.

Manifest

No tarball or file manifest is published yet. When a release is published, its file list and SHA-256 fingerprints will be computed from the published files and listed here.

Quick start

Cargo.toml
# Not on crates.io yet — depend on the source by path:
[dependencies]
cloakapi-open-receipt = { path = "../open-receipt-rs" }
src/main.rs
use cloakapi_open_receipt::{discovery::verifying_key_from_pem, verify, SignedReceipt};

let signed: SignedReceipt = serde_json::from_slice(bytes)?;
let key = verifying_key_from_pem(PUBLIC_KEY_PEM)?;
let result = verify(&signed, &key);

Issues / questions

Bug reports, patches, and security advisories all go to the CloakAPI open-source inbox.

open-source@cloakapi.io

Back to /source/ · related: spec · conformance · implementations