Verify an anchoring receipt

Upload a receipt JSON and, if you have it, the manifest file it covers. The checks run against the certificates embedded in the receipt itself.

Receipt JSON (required)

Manifest file (optional)

What gets checked

The page rebuilds the receipt's signed core, verifies Lumethic's signature over it, verifies the independent RFC 3161 timestamp that covers that signature, and, when you supply the manifest file, recomputes its hash and re-derives the summary the receipt claims. The bytes are the truth. The receipt only summarizes them.

You do not need this page

The receipt embeds the certificates it was signed with. An expert can run the same checks with standard tools such as openssl, without trusting Lumethic or this page. Chain-path and revocation checks are listed under Not checked. The hosted check is a convenience, never a requirement. Receipts are never revoked, but the timestamp authority's certificate does expire, so keep the downloaded receipt and manifest together.