Free, offline, no account

Verify a Phantom Receipt

Paste or drop a receipt and the public key you pinned for its signer. The check runs in this page with your browser's built-in cryptography. Nothing is uploaded, there is no ledger lookup, and the page makes no network requests (its content policy forbids them). Save the page and it works offline.

Signer identity is NOT bound unless you pinned the expected key. No pinned key entered. Signer identity is NOT bound: anyone can produce a receipt that verifies under a key they embedded themselves.

Paste, drop a .receipt file here, or choose a file.

ECDSA P-256 keys only. Leave empty to check the receipt against the key inside it (signer not bound).

No token loaded. Without one, only the receipt itself is checked.

A timestamp token is a small file from an outside timestamp service. It lets you check that this exact receipt existed by a certain time. Drop it here or choose it. It is checked in this page and nothing is uploaded.

Or paste the token as text (base64 or PEM)
Trusted timestamp authority

By default this page trusts the FreeTSA root certificate that is built into it.

If you add a certificate here, only that certificate is trusted. The built-in one is not used then. Get it from the authority's own website.

Sample receipts

Made with the Phantom Receipt tool and a throwaway test key (not hardware-held). Loading one fills both boxes, using the throwaway key as the pin. The tampered ones have one field altered after signing. The one signed by a different key is valid under the other party's key but not under the pinned one. Then press Verify receipt.

Samples with an independent timestamp

The first one loads a receipt plus a real token from the public FreeTSA service (it signed the receipt's hash on 2 October 2026). The second one changes one field of the receipt and keeps the same token. The timestamp check must then say INVALID, because the bytes are no longer the ones that were stamped.

What a VALID result means: the record is unaltered since it was sealed, it is covered by the signed chain tip or Merkle root, and the signature verifies under the key shown. What it does not mean: it does not identify the signer unless you pinned the right key, it does not show the recorded decision was correct, and it does not decide whether a court will accept it. That is for the court and your lawyer. Differences from the C++ verifier: pins are compared as decoded key bytes rather than PEM text, and only ECDSA P-256 keys are accepted.

About the timestamp check: a VALID timestamp means this exact receipt existed no later than the time the outside authority signed. It does not mean the contents are true. This page does not check whether the authority's certificate was later revoked. A free service such as FreeTSA has no uptime or accuracy promise. The check uses the certificate dates at the stamped time, not today's date. If you paste the receipt as text, line endings or a trailing newline can differ from the original file; load the original file when you can.