Paste a signed receipt. Get four answers, not one.
No account, no cookie, nothing installed. This checks whether the document is intact, whether the key that signed it belongs to a licence we issued, whether that licence was live at the moment the receipt says it was written, and whether the number inside can be recomputed by a stranger or only believed. Those are four separate questions and they get four separate answers — this page never merges them into a badge.
Your expectation is checked separately from what the receipt itself claims. It is never used as a stand-in: a receipt that names no licence stays unclaimed no matter what you type here.
Nothing in hand? “Load a real one” pastes a genuine ed25519-sealed ledger attestation from this repo. It is intact and it names no licence — so it comes back signed-but-unclaimed, which is the most common state a real receipt is in and the one worth understanding first. We do not ship a sample rigged to come back clean.
- That the agent behaved correctly, safely or usefully, or that the code is bug-free, or that the output is accurate. WHERE this landed is provable and re-runnable — WHETHER it's bug-free is UNDECIDABLE (Rice), we don't claim that.
- That a pass is an insurance certificate, a warranty, a coverage decision, or any statement about how trustworthy the deployer is. It is a statement about a document.
- That the buyer, and only the buyer, could have produced this. The authority can re-derive every licence key, so this is a custodial v1: identity proves the receipt is attributable to a licence this authority issued and has not altered; it does not prove the buyer, and only the buyer, produced it.
- That the receipt is fresh. A byte-identical copy of a genuine receipt passes every checkable claim, because it is a genuine receipt. This checks a document, not a session — uniqueness is your own ledger’s job.
- Your email, company or payment reference. The endpoint cannot return them and this page never asks for them.
Prefer to send nothing at all? Verify offline, in your own tab, nothing sent anywhere — /trust runs the signature check in-browser via Web Crypto. It cannot answer the entitlement question, because that one needs the licence tape.