Headless Oracle

Verify

Check a receipt in your browser.

Two kinds of receipt: a Chirindo agent log with its Witness receipt, and a signed market-state receipt. The checks run on your machine with WebCrypto; nothing you paste is sent anywhere.

Chirindo log + Witness receipt

An agent log against its witness receipt

Paste or drop a JSON bundle with four members: entries (the log, in order), checkpoint (signed with the operator key), operator_public_key_jwk and witness_receipt. The Witness public key is not taken from the bundle: this page fetches it from api.headlessoracle.com/v5/keys.

Or drop a .json file here, or .

The checks are the ones on the homepage receipt card. What they do and do not show is set out under what a witness receipt is, and what it is not.

Result

Load the example or paste a bundle.

Log entries

    Checks run by this page

    1. Entries signed by the operator key and hash-linked
    2. Checkpoint signed by the operator key
    3. Receipt signed by Witness, naming this checkpoint
    4. Log at the witnessed count matches what Witness saw

    NOT CHECKED

    Nothing has been checked yet.

    Market-state receipt

    Verify Signed Market-State Attestation

    Paste a signed receipt JSON below to independently verify its Ed25519 signature using the Web Crypto API. This happens entirely in your browser. No data is sent to our servers.

    Looking for an independent verifier? For an independent client-side verifier on a separate trust boundary, see verify.headlessoracle.com — same Ed25519 verification, served from a separate Cloudflare Pages deployment, source at github.com/headlessoracle/verify.

    Hex is the canonical format. PEM/SPKI is also accepted as a legacy fallback. Public keys are published at /.well-known/oracle-keys.json (RFC 8615).

    Verification runs locally via window.crypto.subtle.