Look twice.Find the gem.

AI agents and MCP servers, each published with its source and what the checks found.

Marketplace

  • Everything
  • AI agents
  • Apps
  • MCP servers
  • Templates
  • What people want
  • What changed this week
  • The verification standard
  • The ooruby Index
  • Servers that publish no source
  • Reliability guides
  • What the catalogue holds
  • Sell here

Our library

  • Everything, in one place
  • Guides
  • Glossary
  • Calculators
  • Checklists and cheat sheets
  • Community

ooruby

  • Home
  • For teams
  • Site status
  • Company projects
  • RSS feed

Verification records what our published tests found on a specific version at a specific date. It is not a warranty, and it does not certify that software is free of defects.

Rubricv1.0
AI agentsAppsMCP serversTemplatesWantedCommunityOur library
Sign inSell

Receipt laboratory

Trust the signed bytes. Then check what changed.

A signature proves authenticity, not present-tense approval. This inspector verifies both layers: the portable Ed25519 receipt and the live registry state that can expire, supersede or revoke it.

Read the rubricPublic JWKSSigned status list

Portable evidence inspector

Paste the compact JWS

We verify the exact signed bytes, resolve the signing key, then check the immutable registry for current lifecycle state.

Receipts are designed to be public. This tool sends the JWS to this site for verification; never paste tokens, private keys or scanner reports.

1 · Signature

Require EdDSA, the exact receipt media type and a registered key id.

2 · Schema

Reject unknown fields, non-canonical JSON and inconsistent result or timestamp claims.

3 · Lifecycle

Resolve the exact registry record so expiry, revocation and supersession travel with it.

What a pass means

Narrow, dated and reproducible.

The receipt binds one listing version to one artifact SHA-256, one capability-manifest SHA-256, one rubric digest and one scan time. A later release does not inherit it.

“Signature authentic” means the protected EdDSA signature validates against a key in the public registry. “Current evidence” additionally requires the exact immutable receipt record to remain active and unrevoked.

The public status list is independently signed for automation and offline transfer. It is present-tense evidence only until its signed next_update; refresh it at that boundary.

Private scanner logs and reproduction steps are deliberately excluded. The portable receipt contains only the public result needed to verify the claim without leaking exploit material.

CI and procurement API

Fail a gate when trust is not current.

The credential-free endpoint supports CORS and returns signature validity separately from registry reliance. Treat only reliance: current as present-tense marketplace evidence.

curl -X POST https://ooruby.com/api/receipts/inspect \
  -H "content-type: application/json" \
  --data '{"jws":"<compact-jws>"}'