Browser verifier · checks run in your browser

Verify a receipt.

Paste an OpenReceipt envelope. The verifier resolves the producer's JWKS, canonicalises the envelope (RFC 8785), and checks the ECDSA P-256 signature with WebCrypto. It checks the signature only: not that the receipt is recent, and not that it links to the receipts before and after it (linkage needs the neighbouring receipts, which this page never sees). No account. Besides the JWKS fetch, the page sends one anonymous count per verification to api.cloakapi.io (profile version, pass/fail, a short error class on failure and a fixed browser/public label — never the receipt, no cookies).

Input

paste base64 receipt or JSON envelope

Result

No receipt loaded. Paste an OpenReceipt envelope and press Verify receipt to see the per-check breakdown.

How verification works

The verifier accepts either the raw JSON envelope or the base64-encoded form returned in the X-CloakAPI-Receipt-v2 response header. It resolves the producer's JWKS (from {iss}/.well-known/openreceipt-pubkeys.jwks when iss is present, falling back to a published cache for the canonical CloakAPI gateway), requires the receipt's exact kid to select an EC P-256 key, canonicalises the envelope per RFC 8785 (JCS) for v2 receipts or treats the OpenReceipt v1 sidecar payload directly, and verifies the ECDSA P-256 / SHA-256 signature using crypto.subtle.verify. The legacy ES512 / SHA-512 wire profile (cloakapi-gateway-v1) was retired in iter-16 and is no longer supported.

JWKS key validity uses an explicit CLOCK_SKEW_SECONDS = 30: exp is expired when now >= exp + 30; nbf is rejected only when nbf > now + 30. When present, each value must be an integer-valued Unix-seconds number from 0 through 10000000000. Strings, fractions, null, booleans, arrays, objects, negative values, milliseconds, larger values, and an unavailable clock are rejected. A key with both fields absent remains acceptable while it stays in the issuer's JWKS; removing it retires it.

If verification fails, the result panel reports the exact failing step (JWKS fetch, kid lookup, signature length, or signature mismatch) so an auditor can reproduce the failure independently.