Signed Action Receipts

New Action Receipts are signed with Ed25519 over a canonical JSON of structural fields. Anyone can check a signature offline with the public key and the standalone script in the public anchors repository. Checking does not require a call to the Proofroom API.

A signature proves this receipt was issued by Proofroom and has not been altered since. It does not evidence that the underlying action occurred.

Public key

  • Product: /.well-known/proofroom-signing-key.json
  • Anchors repository: keys/proofroom-signing-key.json

Each key has a kid, validity window, and Ed25519 JWK x so keys can rotate.

Signed fields

Canonical JSON (keys sorted, no whitespace):

  • receipt_id (the public PRF code)
  • use_case_public_id (room slug)
  • event_type
  • authority_status
  • evidence_level
  • approval_status
  • timestamp
  • event_hash
  • config_fingerprint (string or null)

Offline verification

node scripts/verify-receipt.mjs receipt.json key.json

The script lives in the public proofroom-anchors repository. It performs no network call. A worked walkthrough is on /verify.

Related