Check a receipt or download.
Works offline as one HTML file. No installation needed.
Save the offline verifier ↓ About SPIRALMESH
What it cannot prove: who produced the receipt, whether the events happened, or whether history is complete. Those report UNKNOWN because these evidence classes (UNSIGNED_FIXTURE, UNSIGNED_LOCAL_MODEL) carry no signature and no authority. For local-model receipts, weight identity and network confinement also stay UNKNOWN — daemon metadata is not weight verification.
Your file stays here: verification runs in this browser. It does not upload the receipt or call a verification service.
Input
Check a download
Choose a file and paste the SHA-256 from the .sha256 published beside that download. This page uses the value you supply; it has no embedded catalog and does not fetch a checksum.
A match means these bytes match that fingerprint. It does not prove who made the file, whether it is current, that someone consented, or that its contents are true. A checksum from the same site is not independent proof of origin.
Your file stays here: reading and hashing happen in this browser, with no upload or network request. The whole file is read into memory; large files may exceed your browser's available memory. There is no artificial file-size cutoff.
File and expected checksum
No file selected.
Accepted: one 64-character hash, or hash filename (two spaces) / hash *filename. One final newline is allowed. A filename is informational: renamed files can still match. Text after the standard separator is read as the filename. Extra lines, control characters and text outside this format are rejected.
Checking a receipt and checking a download answer different questions. Memory exports need their matching local verifier; see the Memory Rights guide. Hashes are not encryption and do not prove that other copies were deleted.