Skip to content

Verify / providers and receipts

Don't take our word.
Check it.

What the router has verified about a provider's hardware, what it has not, and a receipt checker that runs in this browser. Anything unverified stays labelled unverified.

What the receipt says

Preview · not live

A plain reading of one answer's receipt: which host could read the prompt, which lane it took, how it was paid, what was kept and what hardware answered. Enter the id from the X-Receipt-Id response header.

Check a receipt

Works now

Paste a receipt as JSON. The payload is put in canonical form (keys sorted, no spaces) and its Ed25519 signature is checked here, with your browser's own cryptography. Nothing you paste leaves this page. Router keys will be published at /.well-known/verifyroute-keys.json when receipts go live.

The sample is a demo key and a sample receipt: a real signature over made-up values.

Check against a key I trust instead

A provider's enclave can sign receipts with its own key, which the router's list will not contain. Paste that key here (64 hex characters, the one its attestation quote commits to) and it is used instead of the key inside the receipt.

Check the provider yourself

The router's record is one account. The planned client SDK goes further before it sends anything: it reads the provider's own /attest, confirms the quote commits to its TLS key and model digest, and refuses the call if any of that fails.

JavaScript · @verifyroute/client (planned)
import { VerifyRoute } from "@verifyroute/client";

const vr = new VerifyRoute({ baseUrl: "https://verifyroute.tech", apiKey: process.env.VERIFYROUTE_API_KEY });

// Reads the router's record and the provider's own /attest endpoint, checks
// that the quote binds its TLS key and model digest, and throws
// AttestationRefused before any prompt leaves your machine if a check fails.
const res = await vr.chat.completions.create(
  { model: "<model>", messages: [{ role: "user", content: "Hello" }] },
  { attested: { providerId: "<provider id>", expect: { modelDigest: "sha256:<digest>" } } },
);

console.log(res.verification.receipt.valid);
SDK documentation

History and badge

The registry will keep every measurement the router verified for an attested provider, and every check it ran. Each entry gets a badge any site can embed; it re-reads the record from the visitor's browser and shows Attested only when the checks pass.