Verify a stranger’s claim
Take a stranger’s result that “was assayed” and check it yourself. You need no account and no trust in either party: fetch the issuer’s published key, check the record’s seal and signature, then change one field and watch the seal fail to see the check is real. The record here is the first one the issuer signed.
Run 2026-10-11 05:26 UTC against api.s2ar.dev 0.1.1 · 4 calls · 539 ms · list price $0 for a stranger (these ran on the operator's key and cost nothing) · every number on this page re-derived by tools/walkthrough.py before it was written
1. The issuer’s published key
curl -s -X GET 'https://api.s2ar.dev/.well-known/assay.json'
| issuer | assay |
|---|---|
| format | assay/2 |
| algorithm | ed25519 |
| public_keys.0.id | assay-1 |
| public_keys.0.public_key | f73ac5d47d40609e… |
the answer, as JSON
{
"issuer": "assay",
"format": "assay/2",
"algorithm": "ed25519",
"public_keys.0.id": "assay-1",
"public_keys.0.public_key": "f73ac5d47d40609e8dcd096edde8fafb5f6b494c41e2d2df985d2d7ab2244924"
}
2. The record, by its hash
curl -s -X GET 'https://api.s2ar.dev/v1/verify/cc0838211d3db223e82f66030fce0a1c0d874ed15cd17d0b303d533e58a37406'
PASS
| found | true |
|---|---|
| seal_ok | true |
| signature_ok | true |
| key_pinned | true |
| certificate.issuer | assay |
| certificate.kind | compression |
| certificate.verdict | isomorphic |
| certificate.outcome | pass |
| certificate.issued_at | 2026-10-09 |
the answer, as JSON
{
"found": true,
"seal_ok": true,
"signature_ok": true,
"key_pinned": true,
"certificate.issuer": "assay",
"certificate.kind": "compression",
"certificate.verdict": "isomorphic",
"certificate.outcome": "pass",
"certificate.issued_at": "2026-10-09"
}
| re-derived by the generator | |
|---|---|
| ✓ | seal recomputed ✓ · signature ✓ · key pinned to assay-1 ✓ |
3. The record as received, posted back
POST /v1/verify checks a record you hold, whoever gave it to you.
curl -s -X POST 'https://api.s2ar.dev/v1/verify' \
-H 'content-type: application/json' --data-binary @record.json # the record above
PASS
| seal_ok | true |
|---|---|
| signature_ok | true |
| key_pinned | true |
| found | true |
the answer, as JSON
{
"seal_ok": true,
"signature_ok": true,
"key_pinned": true,
"found": true
}
| re-derived by the generator | |
|---|---|
| ✓ | seal recomputed ✓ · signature ✓ · key pinned to assay-1 ✓ |
4. One field changed
curl -s -X POST 'https://api.s2ar.dev/v1/verify' \
-H 'content-type: application/json' --data-binary @record.json # the record above, with outcome="fail"
TAMPERED · seal fails
| seal_ok | false |
|---|---|
| signature_ok | null |
| key_pinned | null |
the answer, as JSON
{
"seal_ok": false,
"signature_ok": null,
"key_pinned": null
}
| re-derived by the generator | |
|---|---|
| ✓ | one changed field and the seal fails: seal_ok: false, the signature is not even consulted |
What this cannot buy
From the signed proceedings (/.well-known/proceedings.json), verbatim:
- placement or routing position
- a different verdict or grade
- buyer data
- amendment access
- a revocation
Failed calls are never charged. Nothing about a caller is kept. The rules: the charter.