Ed25519 receipts you can check in the browser

A walk through what a provenance receipt contains, how the signature works, and how to verify one yourself without calling anyone's server.
Robert ChristianSeptember 22, 20264 min read

A provenance receipt is a small, plain object, and that is the point. It is plain enough to verify in a few lines of code, in a browser, without calling the server that issued it. Here is what is inside and how the check runs.

A receipt carries an id, the action it records, the time, a hash of the inputs, a hash of the outputs, some metadata, a signature, and the public key that signed it. It can also link to a parent receipt, which is how receipts chain.

The signature is Ed25519, a public-key scheme. The issuer holds a private key and signs a canonical serialization of the receipt's fields. Anyone with the matching public key can confirm the signature came from that key and that the signed bytes are unchanged. No shared secret, no server round trip.

The DRM3 verify page.
Check any receipt yourself, in the browser, against the published keys.

Three steps to verify one

Serialize the receipt's fields the same canonical way the signer did. Fetch the public key from the issuer's published key list. Run the Ed25519 verify over the bytes and the signature. A pass means two things are now certain: this key signed this, and the bytes have not changed since.

Two details decide whether the check is meaningful. Canonicalization has to match exactly, or the hashes differ and a valid receipt reads as invalid; a published provenance format pins the serialization so independent verifiers agree. And the public key has to come from a source you trust to represent the issuer, usually a key list the issuer publishes and, better, anchors somewhere public so it cannot be swapped quietly.

What the check does not tell you is whether the claim is true. It tells you who stands behind it and that it has not been altered. That is the limit of a signature, and it is enough to build accountability on.

DRM3 publishes its signing keys and ships the verification so you can run it yourself: verify the receipts against the public keys, in your browser.

Published by

Robert Christian

Founder and CEO, DRM3 Labs Corp.

2026 DRM3 Labs Corp. All rights reserved. DRM3 Labs builds infrastructure for open protocols.