Receipt evidence

Check what a line's receipts show.

A Qlaas DMI line signs a receipt for every decision and chains each to the one before. Drop an export and the line's public key here to verify them, and get a report you can print or keep.

Verify an export

Verified in this browser. Nothing is uploaded.

The files you choose are read by this page and checked with your browser’s own cryptography. They are not sent to qlaas or anyone else. The same checks run offline with the qlaas-evidence command.

  • 01Every receipt's Ed25519 signature, over its JCS canonical payload, under the line's public key
  • 02Every hash link: each receipt names the SHA-256 of the one before it
  • 03Order, gaps and duplicates, and the hash the export recorded for each receipt
  • 04What the verified receipts record: decisions, who decided, who was on the other end

Drag a .jsonl, .csv or .json export here, or choose it.

receipt-key.json, the line's dmi.json, or a JWK.

Read and verified in this browser. Nothing is uploaded. The report describes what the receipts record; it is not legal advice.

Method and limits

What a verified chain does and does not show.

A valid chain shows that the holder of the line’s receipt key signed each receipt, and that none was altered, removed or reordered between the first and the last one shown. To show nothing was withheld from the end, compare the head hash with the one the line reports.

Get the key from the line itself: /.well-known/qlaas/receipt-key.json, or evidence.receipts.key in its signed /.well-known/dmi.json. Exports come from the owner’s app as JSONL or CSV. The method follows section 7 of the draft DMI profile.

The report describes what the receipts record. It is not legal advice and does not say whether any obligation, such as AI transparency or call consent, is met. Where receipts do not record something, the report says so and lists the fields a line would need.