bucker
Published by Bucker. Every number here is computed from the same records the product runs on.bucker.io

Verify a Proof Ledger certificate

Paste a Proof Ledger bundle, a DSSE envelope or a provenance certificate, or open a share link. The claims are re-derived in this browser tab — your certificate is not sent to us — and the Ed25519 signature is checked here too, against the issuer’s published key.

What this page checks, and what it does not

CHECKED HERE: that every claim in the document is supported by the evidence the document itself carries, and that the tier it asserts is one that evidence earns. This is the same rule set as the offline command-line tool, and a conformance test pins the two together. Nothing you paste leaves this tab.

ALSO CHECKED HERE: the Ed25519 signature, using WebCrypto in your own browser. The two answers are kept apart and reported in separate panels, because a self-consistent forgery and a signed document are different things and one green tick cannot mean both. A bare proof bundle carries no signature — it is the payload of an envelope — so paste the DSSE envelope or the whole share response to have authorship checked as well.The public key is fetched from /.well-known/proof-ledger-keys and never read out of the document you pasted, so the verdict says the document was signed by whoever controls that endpoint. To authenticate the issuer to YOU, compare the key id shown against a key you obtained independently, or verify offline with the command-line tool below, which takes the key as an argument. Provenance certificates signed before the Ed25519 change used a shared secret and are refused rather than checked: anyone able to verify one of those could forge it.

Off by default: a certificate is issued at verification time, before anyone has approved anything. A merge gate turns this on.

Or check it without a browser at all

This page is a convenience. The independent verifier is a command-line tool with no account, no network and no runtime dependencies — a different implementation of the same published specification, and the one that also checks the Ed25519 signature.

npx bucker-verify bundle.json --keys proof-ledger-keys.json