Verify a Receipt PUBLIC · NO LOGIN

Check a DSSE signature locally with a supplied public key, or explicitly request online runtime verification. Signature validity, signer identity, and chain integrity are separate checks.
A signature you can't check is just a claim.
Here you can check it yourself.

Offline verification runs ECDSA-P256 / SHA-256 over DSSE PAE in this browser. Paste the public key and expected key id obtained from a source you trust. The receipt and key stay in this browser during the offline check. A valid signature under a supplied key does not establish the signer's identity, authorization, or the truth of the payload.

This is the interactive product tool at a-11-oy.com. The separate public RECORD registry is a11oy.net. Offline chain verification is UNAVAILABLE here; the optional online check can inspect the runtime's in-memory Khipu ledger.

Math demo · τ = 0.80 POLICY · equal-weight n=4

G = exp(Σ log xᵢ / n). Admit iff G ≥ 0.80 ∧ min > 0. dang ≔ (AM ≥ τ) ∧ (GM < τ). hidden_weak is the dang demo. false_friend is not. liar is dang only at frontier-default 0.70.

vectoraxesGMAMminadmitdang

Maximum 256 KiB of UTF-8 input, 128 KiB decoded payload, and 16 signatures. Use a DSSE envelope directly; other receipt formats are not converted or guessed.

The optional digest must refer to the exact decoded DSSE payload bytes, not a receipt id, chain seal, or a reserialized inner object. Obtain the expected digest independently.

The math table and loaded axes are a local demonstration with τ = 0.80 policy. They do not authorize execution. The current runtime verifier reports signature, payload digest, and hash-chain checks; it does not validate the axes or a Λ claim. Λ remains Conjecture 1.

Online verification sends the envelope and/or receipt id to this product host. It does not send the supplied public key. It uses runtime and retained organization keys; a missing chain remains UNAVAILABLE after a runtime restart.

Result
—
Verification details and scope

    
How to read the honest labels

VERIFIED the check ran and passed.   MISMATCH the check ran and FAILED (bad signature, tampered payload, or broken chain).   UNSIGNED-LOCAL the envelope carries no signature — nothing to verify (never faked).   UNAVAILABLE evidence needed for this check is absent or the mechanism is unsupported here.

PARTIAL means at least one check passed while another remains unavailable. Offline results remain PARTIAL when signature and optional payload digest checks pass: trusted signer identity and parent-chain verification are not established.

Λ = Conjecture 1 (never a theorem). This verifier adds nothing to the locked-8 (749/14/163 @ kernel c7c0ba17). Trust ceiling is never 100%. The signature is checked against the supplied public key for offline checks; obtain trusted key provenance independently. Runtime receipt key metadata is available at /api/a11oy/v1/govern/verifying-key; compare its fingerprint with an independently authenticated source. Online POST verification tries this deployment's runtime key at /cosign.pub first, then retained keys. The signature check in the raw response names the verifying key using verified_by or verified_by_keyid. This deployment publishes /cosign.pub itself; it is not an independent trust anchor. Key rotation can require a different historically trusted key. In-memory Khipu chains reset on a Space restart, so a hash-chain check can honestly read UNAVAILABLE for an older receipt id.
🌐Spaces