Verify / providers and receipts
Don't take our word.
Check it.
What the receipt says
Preview · not liveA plain reading of one answer's receipt: which host could read the prompt, which lane it took, how it was paid, what was kept and what hardware answered. Enter the id from the X-Receipt-Id response header.
Check a receipt
Works nowPaste a receipt as JSON. The payload is put in canonical form (keys sorted, no spaces) and its Ed25519 signature is checked here, with your browser's own cryptography. Nothing you paste leaves this page. Router keys will be published at /.well-known/verifyroute-keys.json when receipts go live.
The sample is a demo key and a sample receipt: a real signature over made-up values.
Check against a key I trust instead
A provider's enclave can sign receipts with its own key, which the router's list will not contain. Paste that key here (64 hex characters, the one its attestation quote commits to) and it is used instead of the key inside the receipt.
Check the provider yourself
The router's record is one account. The planned client SDK goes further before it sends anything: it reads the provider's own /attest, confirms the quote commits to its TLS key and model digest, and refuses the call if any of that fails.
import { VerifyRoute } from "@verifyroute/client";
const vr = new VerifyRoute({ baseUrl: "https://verifyroute.tech", apiKey: process.env.VERIFYROUTE_API_KEY });
// Reads the router's record and the provider's own /attest endpoint, checks
// that the quote binds its TLS key and model digest, and throws
// AttestationRefused before any prompt leaves your machine if a check fails.
const res = await vr.chat.completions.create(
{ model: "<model>", messages: [{ role: "user", content: "Hello" }] },
{ attested: { providerId: "<provider id>", expect: { modelDigest: "sha256:<digest>" } } },
);
console.log(res.verification.receipt.valid);History and badge
The registry will keep every measurement the router verified for an attested provider, and every check it ran. Each entry gets a badge any site can embed; it re-reads the record from the visitor's browser and shows Attested only when the checks pass.