Verify a stranger’s claim

Take a stranger’s result that “was assayed” and check it yourself. You need no account and no trust in either party: fetch the issuer’s published key, check the record’s seal and signature, then change one field and watch the seal fail to see the check is real. The record here is the first one the issuer signed.

4calls answered
0receipts re-hashed
2records verified
$0list price for a stranger
539ms end to end
pass · a tampered copy fails · 2 records verified

Run 2026-10-11 05:26 UTC against api.s2ar.dev 0.1.1 · 4 calls · 539 ms · list price $0 for a stranger (these ran on the operator's key and cost nothing) · every number on this page re-derived by tools/walkthrough.py before it was written

1. The issuer’s published key

curl -s -X GET 'https://api.s2ar.dev/.well-known/assay.json'

→ HTTP 200 · 92 ms

issuerassay
formatassay/2
algorithmed25519
public_keys.0.idassay-1
public_keys.0.public_keyf73ac5d47d40609e…
the answer, as JSON
{
  "issuer": "assay",
  "format": "assay/2",
  "algorithm": "ed25519",
  "public_keys.0.id": "assay-1",
  "public_keys.0.public_key": "f73ac5d47d40609e8dcd096edde8fafb5f6b494c41e2d2df985d2d7ab2244924"
}

2. The record, by its hash

curl -s -X GET 'https://api.s2ar.dev/v1/verify/cc0838211d3db223e82f66030fce0a1c0d874ed15cd17d0b303d533e58a37406'

PASS → HTTP 200 · 185 ms

foundtrue
seal_oktrue
signature_oktrue
key_pinnedtrue
certificate.issuerassay
certificate.kindcompression
certificate.verdictisomorphic
certificate.outcomepass
certificate.issued_at2026-10-09
the answer, as JSON
{
  "found": true,
  "seal_ok": true,
  "signature_ok": true,
  "key_pinned": true,
  "certificate.issuer": "assay",
  "certificate.kind": "compression",
  "certificate.verdict": "isomorphic",
  "certificate.outcome": "pass",
  "certificate.issued_at": "2026-10-09"
}
re-derived by the generator
✓seal recomputed ✓ · signature ✓ · key pinned to assay-1 ✓

3. The record as received, posted back

POST /v1/verify checks a record you hold, whoever gave it to you.

curl -s -X POST 'https://api.s2ar.dev/v1/verify' \
  -H 'content-type: application/json' --data-binary @record.json   # the record above

PASS → HTTP 200 · 102 ms

seal_oktrue
signature_oktrue
key_pinnedtrue
foundtrue
the answer, as JSON
{
  "seal_ok": true,
  "signature_ok": true,
  "key_pinned": true,
  "found": true
}
re-derived by the generator
✓seal recomputed ✓ · signature ✓ · key pinned to assay-1 ✓

4. One field changed

curl -s -X POST 'https://api.s2ar.dev/v1/verify' \
  -H 'content-type: application/json' --data-binary @record.json   # the record above, with outcome="fail"

TAMPERED · seal fails → HTTP 200 · 160 ms

seal_okfalse
signature_oknull
key_pinnednull
the answer, as JSON
{
  "seal_ok": false,
  "signature_ok": null,
  "key_pinned": null
}
re-derived by the generator
✓one changed field and the seal fails: seal_ok: false, the signature is not even consulted

What this cannot buy

From the signed proceedings (/.well-known/proceedings.json), verbatim:

Failed calls are never charged. Nothing about a caller is kept. The rules: the charter.