/source/ · Node 20+ · Browser ESM · Apache-2.0

reference-typescript

v1.0.0

Node 20+ and browser ESM build of the SignedReceipts producer and verifier. Signatures via @noble/curves; two runtime dependencies.

published March 2026

About this artefact

@cloakapi/open-receipt is the reference TypeScript package. It exposes a receipt builder, signing, and a verifier that share one canonicalisation pipeline. Signatures use @noble/curves and hashing uses @noble/hashes (its two runtime dependencies). It is not yet published to npm.

A separate @signedreceipts/cli wrapper exposes the same verifier through a small command-line shim, but the canonical CLI is the Rust binary in verifier-cli — the TS shim exists to make local development inside JavaScript projects friction-free. No tarball or npm release is published yet; the source distribution is being prepared.

Manifest

No tarball or file manifest is published yet. When a release is published, its file list and SHA-256 fingerprints will be computed from the published files and listed here.

Quick start

shell
# No published npm package yet — build from the TypeScript source in this repository.
verify.ts
import { verify } from "@cloakapi/open-receipt";

// pubKeyHex: the producer's P-256 public key, hex-encoded
const result = verify(signedReceipt, pubKeyHex);

Issues / questions

Bug reports, patches, and security advisories all go to the CloakAPI open-source inbox.

open-source@cloakapi.io

Back to /source/ · related: spec · conformance · implementations