Skip to content

kojibai/receiz_offline_verifier

Repository files navigation

Receiz Offline Verifier

Verify a file offline. Proof is in the file.

Current release: v113.0.0

What changed in v113.0.0

  • Current release/docs surfaces are aligned to v113.0.0.
  • Published the Production Global Reconciliation release at docs/releases/v113.0.0.md.
  • Published the release-scoped product truth, checklist, process, regression lessons, performance findings, invariant register, and commit-history boundary.
  • “Global” is explicitly scoped to acceptance by receiz.com/global/v1; it does not mean universal consensus.
  • Exact sealed artifact bytes and independently verified causal history remain above Connect tokens, private staging, rows, receipts, effects, outbox state, projections, and release records.
  • The SDK keeps plan, Identity Seal capability, neutral stage, commit, accepted-head resolution, attempt recovery, and effect status as distinct phases.
  • Returned artifacts are independently reverified before the SDK exposes runtime-custodied artifact truth.
  • MCP retains the frozen five v112 artifact tools and adds exactly four reconciliation tools.
  • Known artifact truth paints before remote construction or requests; remote work may append only verified additions.
  • The additive private migration is coordination-only and remains unapplied by this release commit.
  • Current coordinated identity aligns at 113.0.0 with registry digest 4c4aa85f9785d205dcf7e4e5109837a83f8c3bf8e166130ae7e87353f299c637 and effective Kai 13198000.
  • The v94.0.0 Official SDK And Durable Proof Operating Model release remains in force.
  • The v93.2.0 SDK Proof Developer Experience release remains in force.
  • The v93.1.0 Durable Proof Memory release remains in force.
  • The v93.0.0 Sports Proof Economy release remains in force.
  • The v89.0.0 foreground anchor publication, profile projection, Sports Vault sealed-manifest proof, wallet/runtime, lease/market, DB pressure, regression-lessons, and commit-history boundary remains in force.
  • The v87.0.0 offline proof baseline remains in force.
  • The v64.0.0 value-loop invariants remain in force.
  • Broader platform target environments require reconciliation, packed-package, release-freeze, governance, migration, publication, deployment, production, and attestation evidence named in docs/releases/v113.0.0-checklist.md.
  • Current shipped verifier, Sports card verifier, studio, and settlement entrypoints display v113.0.0.
  • Root package metadata resolves cleanly to 113.0.0.
  • The static service-worker surface carries runtime version 113.0.0.
  • Verifier semantics remain unchanged relative to v60.0.0.
  • Core verifier outcomes remain file-authoritative, deterministic, and fail-closed.

Live Conformance

Powered by Receiz Verification conformance badge Settlement conformance badge Identity conformance badge Issuance conformance badge Interoperability conformance badge World conformance badge

The repo-local conformance hub at docs/conformance/README.md tracks the latest vendored conformance snapshot in this repository. It includes live badge surfaces, current imported results, and suite-by-suite requirement coverage docs for the currently imported suites; the broader v113.0.0 release is documented in the release note and can be vendored here on the next snapshot refresh.

Release train highlights (v14 -> v98.0)

  • v14.0.0: UI release marker advanced to v14.0.0; app entrypoint rename started (receiz-offline-verifier.html -> offline-verifier.html).
  • v15.0.0 / v15.5.0: runtime/doc route references aligned to /offline-verifier.html; release markers advanced.
  • v16.0.0: wording shifted from "original/sealed artifact" language to consistent "file/sealed file" language.
  • v17.0.0: anchor derivation + cross-check hardening shipped.
  • v18.0.0: Signature v3 offline verification + key pinning model shipped.
  • v19.0.0: Signature v3 key policy shifted to pulse-based lifecycle enforcement.
  • v20.0.0: added footer download action for the offline verifier page.
  • v21.0.0: strict verification gating requires signature, anchor context, and real g16: Groth16 proof artifacts.
  • v22.0.0: release marker and docs alignment with no policy/runtime behavior change.
  • v23.0.0: Signature v4 trust-chain verification and trusted-signature policy expansion (signatureV3 or signatureV4).
  • v24.0.0: trusted-signature gating narrowed to signatureV4 and v4 root-key pin set expanded.
  • v26.0.0: release-marker/docs alignment only; verification semantics unchanged from v24.
  • v27.0.0: release-marker/docs alignment only; verification semantics unchanged from v26.
  • v28.0.0: release-marker/docs alignment only; verification semantics unchanged from v27.
  • v29.0.0: release-marker/docs alignment only; verification semantics unchanged from v28.
  • v30.0.0: release/docs alignment plus public standards, governance, and release-note expansion; verifier semantics unchanged from v29.
  • v40.0.0: release/docs alignment for the broader operational trust-platform release, including offline proof, wallet/settlement, public artifact delivery, admin/business rails, and world-runtime framing.
  • v45.0.0: release/docs alignment for the production Public Twin and World consolidation release, including photoreal live stages, owned-runtime rendering, deterministic trail bundles, and hardened calendar/booking flows.
  • v46.0.0: release/docs alignment for the locked-surface product-truth release, including richer original/document viewing, a stronger verified-original player, authority-aware Public Twin photoreal behavior, and explicit release-freeze framing.
  • v47.0.0: release/docs alignment for the governed trust-surface release, including first-class original/document delivery, stronger verified-player continuity and sharing, stricter storage/media freshness, more authority-aware Public Twin/world behavior, and explicit version-truth governance.
  • v47.0.1: release/docs alignment for the profile stability patch; verifier semantics remain unchanged from v47.0.0.
  • v47.2.0: release/docs alignment for the Business custom-domain root-routing and DNS setup-surface patch; verifier semantics remain unchanged from v47.0.0.
  • v47.3.0: release/docs alignment for the custom-domain continuity and sign-in experience release, including auth-bridge continuity on verified business domains, email-first fallback in likely embedded browsers, and trusted-host first-paint hero media behavior; verifier semantics remain unchanged from v47.0.0.
  • v47.4.0: release/docs alignment for the native business-entitlement and embedded-surface continuity release, including Business-preserving session surfaces, Receiz calendar scheduling continuity, and Receiz-hosted embedded Stripe checkout; verifier semantics remain unchanged from v47.0.0.
  • v47.5.0: release/docs alignment for the world revenue-operations release, including explicit revenue skills, multi-channel outbound opportunity lanes, owner-side playbooks, proof-first kits, action-card embeds, booking confirmation packs, and call closeout rails; verifier semantics remain unchanged from v47.0.0.
  • v47.6.0: release/docs alignment for the world command-center and contacts-operations release, including the atlas-first /world shell, concierge twin-run tracking, a standalone /contacts CRM surface, safer outreach persistence rules, and Stripe-backed checkout completion truth; verifier semantics remain unchanged from v47.0.0.
  • v47.7.0: release/docs alignment for the durable contacts production release, including migration-backed contact persistence, historical relationship backfill, live person timelines, portable import/export, and locked release-governance surfaces; verifier semantics remain unchanged from v47.0.0.
  • v47.8.0: release/docs alignment for the contacts continuity hardening release, including guest-contact materialization, public-twin and calendar continuity, mobile identity visibility, and guest-thread follow-up continuity; verifier semantics remain unchanged from v47.0.0.
  • v48.0.0: release/docs alignment for the operator-surface release, including the operator-first contacts shell, durable linked_user_id merge upgrades, and a cleaner authoritative mobile world atlas; verifier semantics remain unchanged from v47.0.0.
  • v50.0.0: release/docs alignment for the world revenue operating system release, including durable contacts CRM, live world command surfaces, concierge-run lead sourcing, campaign persistence, scheduled autopilot, provider telemetry, truthful rail readiness, reply handling, and revenue attribution; verifier semantics remain unchanged from v47.0.0.
  • v51.0.0: release/docs alignment for the product-ladder and operator-truth release, including public plan renaming to Authorship / Business / Automation, Free-to-Enterprise ordering, consistent entitlement copy, and carried-forward Contacts/world truth hardening; verifier semantics remain unchanged from v50.0.0.
  • v52.0.0: release/docs alignment for the governed market release, including deterministic quote execution, replayable quote evidence, partial share-certificate custody, first-class market conformance, and lighter premium market runtime behavior; verifier semantics remain unchanged from v51.0.0.
  • v52.5.0: release/docs alignment for the market hardening release, including deterministic quote math, persisted quote evidence, bounded spread/pressure behavior, partial share-certificate custody, first-class market conformance, lighter premium runtime, contextual market media, inline launch, and official market share surfaces; verifier semantics remain unchanged from v52.0.0.
  • v53.0.0: release/docs alignment for the public market product-system release, including public market data routes, persisted conformance history, stricter prediction resolution, touch-safe market/player flows, stronger proof metadata, proper passkey account attachment, first-class Enterprise handling, simpler public entry surfaces, and Ed25519 release attestation; verifier semantics remain unchanged from v52.0.0.
  • v54.0.0: release/docs alignment for the broader operating-system release, including the expanded public product map, the dedicated Business surface, the admin command deck, Stripe-to-ledger wallet transparency, shared session bootstrap, deterministic market-preview pricing, twin continuity across profile/artifact/player handoffs, and deterministic Kai sigil rendering; verifier semantics remain unchanged from v53.0.0.
  • v55.0.0: release/docs alignment for the guided owner-setup release, including sticky /profile activation, sealed profile media, explicit world-avatar freshness, shared stable-route market/player continuity, and canonical performance route grouping; verifier semantics remain unchanged from v54.0.0.
  • v55.1.0: release/docs alignment for the continuity-and-execution release, including reusable profile truth, deterministic route handoff, passkey-first buy continuation, exact-USD non-entitled settlement, position-aware sell presentation, and tighter live-player continuity; verifier semantics remain unchanged from v55.0.0.
  • v56.0.0: release/docs alignment for the canonical continuity release cut, including lockstep version surfaces, guarded logged-in world hydration, entitlement-aware concierge polling, and fresh-account analytics schema-drift hardening; verifier semantics remain unchanged from v55.1.0.
  • v57.0.0: release/docs alignment for the route-coherence, certificate-custody, and market-conformance release, including canonical managed-owner routing, world/market fast-entry truth reuse, certificate-native custody/history, and coherent market balances and inventory across certificate and profile-visibility mutations; verifier semantics remain unchanged from v56.0.0.
  • v58.0.0: release/docs alignment for the authoritative-market and release-surface coherence cut, including authoritative signed-in market first paint, shared wallet/chart-buy live hydration, lean deterministic market transport, live tracked-position semantics, and unified release-surface version truth; verifier semantics remain unchanged from v57.0.0.
  • v60.0.0: release/docs alignment for the major stable recap cut across v50.0.0 through v60.0.0, including live proof and twin at the front door, stronger canonical original upload/download recovery, explicit profile-ready twin portrait publishing, tighter compact-device wallet and certificate framing, and unified v60.0.0 release truth; verifier semantics remain unchanged from v58.0.0.
  • v60.1.0: release/docs alignment for the continuity-and-market-proof cut on top of v60.0.0, including holder-aware public market witness truth, compact market-desk polish, twin shell continuity without late visible promotion, lighter public-profile route assembly, and deterministic market sigil hydration; verifier semantics remain unchanged from v60.0.0.
  • v61.0.0: release/docs alignment for the governed historical-continuity and runtime-discipline cut on top of v60.0.0, including the governed pre-v4 historical cohort, deterministic market exits, stricter settled-shell runtime boundaries, published operating standards, and unified v61.0.0 release truth; verifier semantics remain unchanged from v60.0.0.
  • v64.0.0: release/docs alignment for the complete value-loop cut, including Settlement as proof-native liquid value, funded Reserve as the external-conversion lane, Reserve-only notes and wire transfer, Reserve-first sends and buys, funded/unfunded market sale splits, buyer-funded certificates, and canonical value-loop invariants; verifier semantics remain unchanged from v60.0.0.
  • v66.0.0: release/docs alignment for the local proof continuity cut, including local identity roots, verified-register-backed proof authority, deterministic state preservation, append-only history, compact local memory, sync as propagation, explicit verified-snapshot persistence, and local twin register projection; verifier semantics remain unchanged from v60.0.0.
  • v70.0.0: release/docs alignment for the public alpha cut, including one-click Receiz ID entry, canonical /<username> profile truth, complete Settlement/Reserve value-loop causality, local-first/server-always recovery, route-preserving stale-runtime recovery, live twin identity locking, proof-sealed world trail bundles, and the v70.0.0 invariant register; verifier semantics remain unchanged from v60.0.0.
  • v72.0.0: release/docs archive for the stable continuity cut, including actor-scoped route warmth clearing on account switch and compact mobile Live Twin face-lock overlay fit; verifier semantics remain unchanged from v60.0.0.
  • v73.0.0: release/docs alignment for the ownership, vault, and continuity cut, including business account ownership, receipt provenance, vault portability, account brain proof detail, Offline Verifier authority navigation, and bounded world twin fit contracts; verifier semantics remain unchanged from v60.0.0.
  • v74.0.0: release/docs alignment for the Receiz Key, identity artwork, and profile media cut, including sovereign Receiz Key restore, deterministic profile identity artwork, PBI-signed identity artifacts, stable profile creation truth, long-form originals, attached-link preservation, video derivatives, sold-position continuity, and portable profile state import; verifier semantics remain unchanged from v60.0.0.
  • v75.0.0: release/docs alignment for the local proof, backup sign-in, market continuity, and Explore cut, including local-first Receiz ID proof, durable account bindings, Identity Record / Seal / Receiz Key restore parity, old-browser backup sign-in, restored-account route authority, profile identity downloads, Plans / Upgrade parity, market snapshot continuity, stable market navigation, and Explore mobile packaging; verifier semantics remain unchanged from v60.0.0.
  • v76.0.0: release/docs alignment for the World Agent revenue loop, Public Proof registry, Market Twin mandate safety, wallet settlement correctness, and expanded public/developer status inventory; verifier semantics remain unchanged from v60.0.0.
  • v77.0.0: release/docs alignment for Signal Circuit, verified Signal Cards, Signal Vault and packs, Signal Pack Foundry, public conformance assurance, Creator OS, creator wallet metering, managed launch, Vault sealed downloads, old-Safari Signature V4 document sealing, runtime recovery, market quote batching, and wallet/profile continuity; verifier semantics remain unchanged from v60.0.0.
  • v78.0.0: release/docs alignment for Signal Card World ownership, synced Vault discovery, sealed Vault Card export, explicit mobile/PWA download intent, transfer packages, Signal Arena, auction wallet holds, public Signal Circuit and Exchange routes, conformance source repair, dashboard first paint, service-worker/PWA continuity, value-loop copy, and release-worker coherence; verifier semantics remain unchanged from v60.0.0.
  • v80.0.0: release/docs alignment for the major stable release, including verified-truth-first identity, canonical profile truth, wallet/market funded causality, World revenue loops, Public Proof registry behavior, Creator OS production, Signal Cards as owned Receiz assets, Vault export portability, public conformance/status visibility, and runtime/PWA continuity; verifier semantics remain unchanged from v60.0.0.
  • v81.0.0: release/docs alignment for the Signal Circuit Provenance Release, including Signal Card DNA, rewarded-card payment before reveal, wallet/calendar card activity, transfer deduplication, all-card history, explicit discovery memory, mobile/PWA chrome stability, and card proof/art polish; verifier semantics remain unchanged from v60.0.0.
  • v82.0.0: release/docs alignment for the Sports Arena World-Class Gameplay Release, including live MLB Sports Arena, owned Sports cards, pack issuance, auditable rarity odds, Pick 5, daily tournaments, live scoring, card careers, Sports market depth, trading, conformance, scale hardening, and PWA first-paint stability; verifier semantics remain unchanged from v60.0.0.
  • v83.0.0: release/docs alignment for the Stable Live Proof Release, including deterministic Sports first paint, scoped score and lock truth, stable card reveal/issuance continuity, live-player sharing recovery, fast Explore and Market surfaces, centralized interoperability policy, OTC proof objects, and release conformance hardening; verifier semantics remain unchanged from v60.0.0.
  • v84.0.0: release/docs alignment for the Proof-Native Artifact System Stable Release, including direct primitive naming, stronger/weaker truth hierarchy, forbidden downgrade boundaries, deterministic first-paint protection, service-worker version truth, and release law coherence; verifier semantics remain unchanged from v60.0.0.
  • v85.0.0: release/docs alignment for the Official Proof-Native Sports, Market, Passport, and Speed Release, including Signal Card provenance, Sports as a live proof economy, Main Event as a settlement primitive, deterministic Market/wallet ownership and settlement projection, Series Passport proof-object gating, referral-backed public sharing, truthful speed invariants, and coherent release/service-worker identity; verifier semantics remain unchanged from v60.0.0.
  • v86.0.0: release/docs alignment for the Official Locked Proof-Native Baseline, including the v80-to-v86 proof arc, Profile-visible proof objects in Market, deterministic Market and Explore first paint, signed-in ownership-history preservation, Sports all-source-date live hydration, payment-confirmed Main Event entry, single-card QR proof routes, World/public twin continuity, and coherent release/service-worker identity; verifier semantics remain unchanged from v60.0.0.
  • v87.0.0: release/docs alignment for Offline Proof Links, QR Proof Transport, And Post-v86 Public Proof Lock, including compact offline proof-bearing /v links, /v Signature V4 proof-bundle classification as Proof, coordinate-only historical fallback boundaries, Sports single-card QR/value proof surfaces, World Estate, Market/Profile first-paint hardening, and RLS/security cleanup; verifier semantics remain unchanged from v60.0.0.
  • v88.0.0: release/docs alignment for Live Sports Truth, Runtime Coherence, Public Live Cockpit, And Post-v87 Regression Lock, including Sports selected-game field truth, /baseball direct entry, locked entries, per-player scores, finalized reward recovery, Public Live Cockpit, runtime/session coherence, notification/chat delivery, Supabase timeout hardening, and required regression lessons; verifier semantics remain unchanged from v60.0.0.
  • v89.0.0: release/docs alignment for Foreground Anchor Publication, Profile Global Sync, Sports Vault Public Proof, Wallet Runtime, And Post-v88 Regression Lock, including /api/receiz/anchor outbox exclusion, profile showcase/global/public market/route snapshot projection, Sports Vault sealed-manifest public proof publishing, Sports FIFA/UFC/fight additions, wallet/runtime continuity, lease/market ownership surfaces, DB pressure repairs, required regression lessons, and commit-history boundary; verifier semantics remain unchanged from v60.0.0.
  • v90.0.0: release/docs alignment for the Official Stable Proof-Native Artifact System Release, including the full v80-to-current proof-native arc, Sports Vault owner-row projection, Sports card ownership transfer, Sports event proof value, Sports conformance, live value/market depth, competition rooms, public metadata projection, regression lessons, and commit-history boundary; verifier semantics remain unchanged from v60.0.0.
  • v91.0.0: release/docs alignment for the Deterministic Sports Scale And Proof-Native Game Release, including deterministic value chart math, full LiveChart primitive preservation, Pack Derby reward-game challenge settlement, post-deadline receipt rejection, sport-specific Sports entry finalization, FIFA closeout composition, settlement conformance, and the scale reasoning law; verifier semantics remain unchanged from v60.0.0.
  • v92.0.0: release/docs alignment for the Receiz Logic Release, including the repo-local reasoning kernel, public proof/profile first paint, vault ownership projection, value/event proof stacking, Pitch Command proof, Pack Derby proof gameplay, append source-date truth, source-age countdown truth, and local artifact save; verifier semantics remain unchanged from v60.0.0.
  • v92.1.0: release/docs alignment for the Sports Proof Telemetry Release, including Play Command 3D play proof, exact Pitch Command event binding, event proof video and milestone projection, foreground Sports Arena appends, Pack Derby opening stability, rarity/value/rookie truth, pitch day-proof archives, and Sports DB hot-path hardening; verifier semantics remain unchanged from v60.0.0.
  • v93.0.0: release/docs alignment for the Sports Proof Economy Release, including Sports Economy as a live public proof surface, bounded proof-read projection, Sports score ledger projection, deterministic card value basis, causal card lineage, visible-card append memory, physical activation proof/settlement routing, command-grade Play/Pitch surfaces, Pack Derby proof-game continuity, and explicit performance/invariant locks; verifier semantics remain unchanged from v60.0.0.
  • v93.1.0: release/docs alignment for the Durable Proof Memory Release, including first admission then append forever, Calendar/Account shared event proof projection, Account brain activity proof nodes, wallet Kai-ledger heads, bounded Sports addition discovery, SDK convenience boundary, and no-downgrade Sports proof fixtures; verifier semantics remain unchanged from v60.0.0.
  • v93.2.0: release/docs alignment for the SDK Proof Developer Experience Release, including runtime schema exports, deterministic proof object projections, Sports card proof object projections, append-only SDK proof memory, verify/project/admit/persist/append docs, and SDK convenience beneath proof authority; verifier semantics remain unchanged from v60.0.0.
  • v94.0.0: release/docs alignment for the Official SDK And Durable Proof Operating Model Release, including the official @receiz/sdk launch, known-verified-truth-first rendering, verified additions after known heads, Kai coordinate preservation, bounded projection mechanics, and SDK convenience beneath proof authority; verifier semantics remain unchanged from v60.0.0.
  • v95.0.0: release/docs alignment for the Official Public Table Release, including complete proof objects carrying Kai/Klok state, Kai Klok as proof object state machine, kaiPulseEternal / kai_upulse as pulse unit, SDK canonical proof bundle parity, and no optional-Kai doctrine for complete proof objects; verifier semantics remain unchanged from v60.0.0.
  • v96.0.0: release/docs alignment for the SDK A+ Release Evidence Lock, including the receiz CLI, local fixture conformance with zero network/DB authority, proof payload inspection, local-first proof memory starter generation, passive SDK observations, copy-paste integration docs, and release-blocking SDK package evidence; verifier semantics remain unchanged from v60.0.0.
  • v96.1.0: release/docs alignment for the Twin And World SDK Release Lock, including World public SDK clients, delegated Twin clients, Connect Twin scopes, OpenAPI/status catalog visibility, Twin/World integration docs, identity conformance visibility, and app/SDK version identity lock; verifier semantics remain unchanged from v60.0.0.
  • v97.0.0: release/docs alignment for the Public App-State Projection Rail And SDK Ecosystem Release, including delegated public app-state publishing, URL/host/domain/creator/namespace/id reads, URL-normalized app-state projections, SDK app-state helpers, OIDC consent repair, public proof projection correctness, admin performance measurement cleanup, and app/SDK release identity lock; verifier semantics remain unchanged from v60.0.0.
  • v97.2.0: release/docs alignment for the Enterprise App Runtime SDK Release, including customer sessions, customer portals, merchant onboarding, expanded commerce primitives, media, events, jobs, RBAC, audit, risk, compliance, portability, search, notifications, release pinning, React subpath helpers, idempotent writes, and offline proof queues beneath proof authority; verifier semantics remain unchanged from v60.0.0.
  • v97.5.0: release/docs alignment for the Public App-State, Enterprise SDK, and MCP Agent Rail Release, including public-store projections, typed SDK app rails, @receiz/mcp-server, delegated agent tokens, MCP resource templates, npm .bin startup repair, and developer MCP surfaces beneath proof authority; verifier semantics remain unchanged from v60.0.0.
  • v97.6.0: release/docs alignment for the Signed Merchant Public-Store, Live Proof Graph, MCP, SDK, and Service Worker Law Release, including Identity Seal / Receiz Key public-store publishing, proof graph inspection, SDK/MCP authority-boundary guidance, service-worker release continuity, and Sports saved-card base issue copy; verifier semantics remain unchanged from v60.0.0.
  • v105.0.0: Browser-safe SDK architecture separates runtime/React/testing graphs from the Node-only compiler, adds stable redacted errors, capabilities, protected generation, emulator conformance, semantic MCP operations, and exact externally installable coordinated packages.
  • v106.0.0: Registry-bound constitutional enforcement coordinates SDK command admission, MCP context, AI-skill contracts, forward-only migration, and independent replay while restoring owner-local PBI and Live Player append continuity.
  • v107.0.0: Unified developer operations expose identity, profile, media, portable continuity, generic bearer ownership, receipts, proof heads, and signed offline proposals across coordinated packages and runtime surfaces.
  • v108.0.0: Proof-object-first authority restoration returns first-party profile saves to the admitted same-account operation and makes SDK, MCP, and AI adapters explicitly subordinate to Receiz.com reference behavior and stronger sealed proof.
  • v109.0.0: Coordinated local-offline developer verification packages Signature V4 and Groth16 dependencies, verifies complete artifact bytes with zero network calls, keeps artifact custody separate from payload extraction, and seals ARTIFACT-011 beneath proof-object authority.
  • v110.0.0: Unified artifact admission and recovery composes exact-byte verification into typed verdicts/actions, deterministic read-only recovery planning, and explicit capability-bound atomic commit under ARTIFACT-012 through ARTIFACT-015.
  • v111.0.0: Artifact-derived authority hardening requires canonical exact-byte reverification, independently rooted single-head history, proven private-key control, complete plan/capability bases, immutable failures, and fresh MCP attempt identity.

Supported artifact inputs (v60)

  1. PNG artifact containing exactly one receiz.proof_bundle text chunk.
  2. PDF artifact containing exactly one embedded Receiz proof object (/Type /ReceizProof + /ProofBundle).
  3. SVG artifact with exactly one embedded Receiz proof metadata attribute (with trailer-proof fallback).
  4. JSON artifact with exactly one embedded Receiz JSON whitespace proof channel (with trailer-proof fallback).
  5. Trailer-sealed artifact ending with one Receiz trailer payload.
  6. .receizbundle container (kind: receiz.bundle.v1).
  7. Sealed package payloads provided as ZIP or multi-file folder-style selections (manifest-driven verification path).

Primitive contract (what "Verified" means)

A file is verified only if the verifier can prove integrity from bytes (plus optional integration-supplied path input):

  • proof bundle payload is found exactly once for the selected format
  • proof bundle decoding succeeds
  • canonical field invariants pass
  • artifact binding hash matches normalized basis bytes
  • trusted signature checks pass (signatureV4 must verify)
  • anchor context is present (explicit or derived) and matches bundle code/pulse
  • real g16: Groth16 proof artifacts are present and verify against digest/public-signal constraints
  • if an optional path is supplied, it matches an accepted embedded canonical path

Runtime notes

  • The verifier is a static HTML app.
  • Verification logic runs client-side in browser JavaScript.
  • Signature v4 verification uses WebCrypto Ed25519 verification.
  • Trusted-signature outcomes are fail-closed:
    • any present invalid signatureV4 payload fails verification
    • unavailable present signatureV4 fails verification
    • missing signatureV4 fails verification
  • Signature policy validates bundle kaiPulseEternal against pinned Signature v4 root-key lifecycle windows (activeFromPulse / retiredAtPulse).
  • Signature v4 validates a device certificate chain rooted in pinned v4 root keys.
  • signedAtMs remains required in signature payload shape and v4 enforces certificate issuance/expiry bounds against signedAtMs.
  • Groth16 checks require zkPoseidonHash, groth16Proof, and groth16ProofDigest.
  • Only real g16: Groth16 payloads are accepted.
  • The default v60 UI does not prompt for manual /v/... path input; integrations can still supply it.

Quick start (local)

Option A: Open directly

Open site/index.html.

Option B: Serve locally (recommended)

cd site
python3 -m http.server 8080
# then open http://localhost:8080

Deploy

Deploy the site/ directory to any static host.

Required runtime assets for v60:

  • index.html
  • offline-verifier.html (if served as an alternate entry path)
  • sw.js (optional, for service worker warm behavior)

Note: Signature/Groth16 verification runtime and pinned key material are embedded in the shipped HTML entrypoints.

Schemas

Machine-readable schemas are provided in docs/schemas:

Repository layout

Security

If you discover a vulnerability (including false-positive verification), do not open a public issue. Use SECURITY.md.

License

MIT for repository contents. See LICENSE for scope notes covering live receiz.com assets and Receiz branding references.

About

Receiz Offline Verifier — Verify originals anywhere. Drop in a Receiz file to confirm it’s unchanged (original) or detect any change (copy). No account. No network. Just pass/fail truth.

Topics

Resources

License

Code of conduct

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Packages

 
 
 

Contributors

Languages