Free · MIT licence · works offline
Verify a GAIP receipt yourself
Every GAIP receipt is signed with an Ed25519 key GAIP publishes. You do not have to trust GAIP's website to check one: save the receipt and the key set, and run a verifier on your own machine.
- Save the receipt:
/v1/free/receipts/<code>(the JSON link on any receipt page). - Save the key set once: /.well-known/gaip-receipt-keys.json. Retired keys stay listed so older receipts still verify; a key marked COMPROMISED is refused.
- Run
python3 gaip_receipt_verify.py receipt.json gaip-receipt-keys.json, or import the JavaScript module and callawait verify(receipt, keys).
Python
One file, standard library only (Python 3.8+), including its own Ed25519 check. gaip_receipt_verify.py
JavaScript
One ES module, no packages: Web Crypto Ed25519 in current browsers, Node 20+, Deno and Bun. gaip-receipt-verify.mjs
Spec and test vectors
Fields, canonical form, the signed message, key discovery and what a receipt does not claim. gaip-receipt-v1 · test vectors
A valid signature shows that GAIP's published key signed that digest, and records what GAIP observed at the stated time. It does not prove that the recorded event is true or complete, anyone's identity, ownership, value or outcome, or that a purchase was made. It is not a certification or advice, and not a qualified electronic signature, seal or timestamp. Something wrong in a receipt? Corrections.