Verify receipt
curl --request POST \
--url https://api.truthlocks.com/v1/receipts/verify \
--header 'Content-Type: application/json' \
--header 'X-API-Key: <api-key>' \
--data '
{
"receipt_id": "<string>"
}
'import requests
url = "https://api.truthlocks.com/v1/receipts/verify"
payload = { "receipt_id": "<string>" }
headers = {
"X-API-Key": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'X-API-Key': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({receipt_id: '<string>'})
};
fetch('https://api.truthlocks.com/v1/receipts/verify', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.truthlocks.com/v1/receipts/verify",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'receipt_id' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"X-API-Key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.truthlocks.com/v1/receipts/verify"
payload := strings.NewReader("{\n \"receipt_id\": \"<string>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("X-API-Key", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.truthlocks.com/v1/receipts/verify")
.header("X-API-Key", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"receipt_id\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.truthlocks.com/v1/receipts/verify")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["X-API-Key"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"receipt_id\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"valid": true,
"receipt_id": "<string>",
"checks": {}
}{
"code": "AUTH_REQUIRED",
"message": "Authentication required",
"http_status": 401
}Receipts
Verify Receipt
Verify a receipt’s cryptographic signature and current status.
POST
/
v1
/
receipts
/
verify
Verify receipt
curl --request POST \
--url https://api.truthlocks.com/v1/receipts/verify \
--header 'Content-Type: application/json' \
--header 'X-API-Key: <api-key>' \
--data '
{
"receipt_id": "<string>"
}
'import requests
url = "https://api.truthlocks.com/v1/receipts/verify"
payload = { "receipt_id": "<string>" }
headers = {
"X-API-Key": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'X-API-Key': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({receipt_id: '<string>'})
};
fetch('https://api.truthlocks.com/v1/receipts/verify', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.truthlocks.com/v1/receipts/verify",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'receipt_id' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"X-API-Key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.truthlocks.com/v1/receipts/verify"
payload := strings.NewReader("{\n \"receipt_id\": \"<string>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("X-API-Key", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.truthlocks.com/v1/receipts/verify")
.header("X-API-Key", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"receipt_id\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.truthlocks.com/v1/receipts/verify")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["X-API-Key"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"receipt_id\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"valid": true,
"receipt_id": "<string>",
"checks": {}
}{
"code": "AUTH_REQUIRED",
"message": "Authentication required",
"http_status": 401
}Verifies a receipt by ID. Returns a verdict indicating the cryptographic validity and current status of the receipt.
Verdicts
| Verdict | Meaning |
|---|---|
VALID | Signature is valid, key was not compromised, receipt is active |
REVOKED | Receipt has been explicitly revoked |
INVALID_SIGNATURE | Cryptographic signature verification failed |
KEY_COMPROMISED | Signing key was marked compromised at or before issuance |
KEY_INACTIVE | Signing key is no longer active |
NOT_FOUND | Receipt not found for this tenant |
Request
string
required
UUID of the receipt to verify.
Response
string
UUID of the verified receipt.
string
VALID, REVOKED, INVALID_SIGNATURE, KEY_COMPROMISED, KEY_INACTIVE, or NOT_FOUND.string
The receipt type name.
string
UUID of the issuer that signed the receipt.
string
ISO 8601 timestamp of when the receipt was minted.
string
ISO 8601 timestamp of this verification check.
⌘I

