Require EdDSA, the exact receipt media type and a registered key id.
Receipt laboratory
Trust the signed bytes. Then check what changed.
A signature proves authenticity, not present-tense approval. This inspector verifies both layers: the portable Ed25519 receipt and the live registry state that can expire, supersede or revoke it.
Portable evidence inspector
Paste the compact JWS
We verify the exact signed bytes, resolve the signing key, then check the immutable registry for current lifecycle state.
Receipts are designed to be public. This tool sends the JWS to this site for verification; never paste tokens, private keys or scanner reports.
Reject unknown fields, non-canonical JSON and inconsistent result or timestamp claims.
Resolve the exact registry record so expiry, revocation and supersession travel with it.
What a pass means
Narrow, dated and reproducible.
The receipt binds one listing version to one artifact SHA-256, one capability-manifest SHA-256, one rubric digest and one scan time. A later release does not inherit it.
“Signature authentic” means the protected EdDSA signature validates against a key in the public registry. “Current evidence” additionally requires the exact immutable receipt record to remain active and unrevoked.
The public status list is independently signed for automation and offline transfer. It is present-tense evidence only until its signed next_update; refresh it at that boundary.
Private scanner logs and reproduction steps are deliberately excluded. The portable receipt contains only the public result needed to verify the claim without leaking exploit material.
CI and procurement API
Fail a gate when trust is not current.
The credential-free endpoint supports CORS and returns signature validity separately from registry reliance. Treat only reliance: current as present-tense marketplace evidence.
curl -X POST https://ooruby.com/api/receipts/inspect \
-H "content-type: application/json" \
--data '{"jws":"<compact-jws>"}'