Skip to content
Documentation menu

Provenance & receipts

Verifying one yourself

Verification is free, forever — and the reason is not generosity.

Status — in design. Nothing is shipped, nothing is sold, and there is no customer. The spec and the verifier will be published when they exist, and this page will link them when they do.

Verification is free, forever. Anyone can check a receipt without an account, a licence, or a payment.

Why that is a structural decision, not a courtesy

A receipt only its issuer can check is worth nothing in a dispute. If the party being challenged is also the only party who can confirm the evidence, there is no evidence — there is a claim with extra steps.

So the receipt format and the verifier are open. If we vanished tomorrow, receipts already issued would remain checkable by anyone who has them.

Open core, and where the line falls

Open: the receipt specification, and the verifier. These are the things that must be trusted, and a thing that must be trusted cannot be a black box.

Closed: the server, the signing infrastructure, and the evidence packaging. These are the things that must be operated — run reliably, kept secure, held to an availability commitment.

Open the things that must be trusted; sell the things that must be operated.

What verification tells you

That the receipt is well-formed, that its signature is genuine, and that the span it names matches the document it names under the root it names.

It does not tell you the corpus was the right corpus, or that the document was true. Those are judgements a person makes. A receipt narrows the argument to the things worth arguing about.

navigate openesc close