Skip to content
Menu

Verify a certificate

Paste the link or the identifier printed on the certificate, or scan its code. This page fetches the signed token and the published key set and verifies the signature in your browser — it does not ask us whether the certificate is good.

Sample data

No production certificate has been issued, and the production signing key signed nothing on this page. The certificates below were signed by this preview's committed fixture keys (psn-dev-2026-2) — public keys by construction, so nothing they sign is a credential. They exist so every verdict this page can reach is reachable, and a production build refuses them outright.

Scan a certificate

The camera picture stays on your device. Nothing is uploaded.

Offline mode — paste a token

Verify a certificate token against the published key set without looking anything up. Useful when you have the artifact but not the identifier, and for checking that a certificate you were sent matches one you already trust.

Offline mode checks the signature, and that the signing key's published validity window covers the time the token says it was signed. It cannot check transparency-log inclusion or revocation, so a token that passes here still needs a lookup by identifier to be trusted.

verify only at purposesource.org/verify

Try a sample certificate

One row per certificate this build published. Each link opens this page with the identifier filled in, and the verdict is then computed in your browser from the signature and the transparency log — not read off this table.

Sample certificates published by this preview. Every one is labelled sample; none is a credential.

Certificate
cert_01m395rstn8dbck57dywp1p907
license-status / waiver · SAMPLE — Jordon and Jordon sample

What the verdicts mean

Every outcome this page can reach, and what each one asserts

Verdict What it means
Genuine certificate Signature verified here, hash present in the transparency log, status current.
VERIFIED — attests participation in {year} A participation certificate past its period. It attests participation in that period, and that does not lapse: the published record says expired because the period is over, and expiry is not revocation.
WAS VALID for the period shown A company certificate past its period. It attests what it attested then — expiry is not revocation and is not a defect.
Revoked on {date} ({class}) Withdrawn, with a date and a reason class. Revocation is prospective: the historical window shown stood while it stood.
Superseded — a newer certificate replaces this one Replaced by a later certificate, linked from the verdict.
Not verified — do not rely on it The signature does not verify — altered, or never issued — or it verifies but the hash is absent from the transparency log, which is what the log is for; or the token could not have been signed by the key it names: it names no key, or one the key set does not carry; it is not ES256; it does not say when it was signed; or it dates itself outside that key's published validity window.
… — its signing key was later compromised The verdict before the dash stands, and the key that signed is now published as compromised; the token dates itself before that key's validity window ends. That date is the signer's own statement: the transparency log, and any incident notice for the key, show whether it was issued then.
Could not check — the key set does not settle the signing key The published key set does not state the signing key's status or validity window in a form this page can apply. The signature is not accepted, and nothing is asserted in either direction.
Could not check right now · Could not check the public log Something could not be fetched: the record, the published keys or the log. Nothing is asserted in either direction — this is deliberately not the same answer as "Not verified".
Could not check — you seem to be offline No network answered at all. Nothing is asserted; connect and reload the page.
Status record only — this page cannot confirm whose certificate this is The published record carries the certificate's status and its token's hash, and no name and no token, so a name printed on a copy is not checked here. Nothing is asserted about whose certificate it is until the holder shows the signed file — paste its token into the holder's box that appears with the record, and the page checks it against the hash, then verifies it.
Test certificate — not a real certificate Signed with a sandbox key. Never a production credential, whatever it looks like.
No certificate with this ID No record is published under the identifier. Ids are long and case-sensitive.

Offline mode — paste a token answers in the verdict matrix's own words (for example INVALID — signature does not verify, TRANSPARENCY-LOG INCLUSION UNKNOWN or CANNOT VALIDATE — not a token type this page can date): it checks the signature and its key's window, and never the log or the status.

Verifying by hand

Nothing here depends on our code. The steps this page performs are the steps you can perform with a shell and any standard token library. Every document is published twice — as a same-origin static copy on this host, and on the edge API once it is live — and the two are byte-identical by construction:

  1. Fetch the status record from /artifacts/certs/{certId}.json (or /v1/verify/{certId} on the API host).
  2. Fetch the key set from /artifacts/jwks.json (or /jwks.json) and select the key by its kid. Then check that the key could sign it: the token's iat must fall inside the key's psn:validityWindow (notBefore included, notAfter excluded), whatever its psn:status. A retired key still verifies what it signed inside its window; a compromised key's window ends where acceptance ends, never after the compromise, and what it signed before then is shown with a warning.
  3. Verify the ES256 signature over the token's header.payload bytes.
  4. Take the SHA-256 of the compact token and look for it in the transparency log segment the record names, at /artifacts/ct/{n}.json (or /ct/{n}.json).

Key rotation history and the log's append-only guarantee are documented on keys and the transparency log. What each class of certificate attests, and the exact wording its holder may publish about it, is the certificate policy.

verify only at purposesource.org/verify — any other address offering to verify our certificates is not ours.