← Back to Home

Check it yourself

Don't trust us. Check it yourself.

You don't need a SatGate account to check a signed receipt (Evidence Pack). Download the pack and SatGate's published public keys, then run the open-source verifier. It confirms SatGate signed the receipt and that nothing in it was changed afterward.

This is the signed refusal from the demo video on the home page: an MCP tool call refused with budget_exhausted after a 3¢ budget ran out. It's signed with the hosted MCP service's key. The live copy stays up until the plan's retention period ends; the downloaded file verifies the same way.

What the result means.

valid=true

Checked with the key stored inside the pack, this only shows the pack is consistent with itself. It doesn't show who signed it.

trusted_issuer_valid=true

This is the one that matters: the signature checks out against SatGate's public keys, downloaded separately from the pack.

Run the verifier

python3 -m venv .venv-verify
. .venv-verify/bin/activate
pip install cryptography rfc8785
curl -fsS https://satgate.io/evidence/sample-mcp-budget-refusal-20260928.json -o pack.json
curl -fsS https://satgate-mcp-saas.fly.dev/.well-known/jwks.json -o jwks.json
python tools/verify_evidence_pack.py pack.json   --jwks-file jwks.json   --require-trusted-issuer

What the verifier checks

  • • The receipt format version, and whether it's marked as real or a test.
  • • It rebuilds the signed content in a standard form (RFC 8785), leaving out receipt_hash and signature.
  • • The SHA-256 receipt_hash and the Ed25519 signature.
  • • The signature against SatGate's public keys at /.well-known/jwks.json. A key stored in the pack is only a fallback and doesn't prove who signed.
  • • The copies of the result and budget at the top of the pack match the signed receipt.
  • • The optional evidence_pack_hash, and that tokens and secrets are blanked out.

Current limits

  • • Signing keys are stored as platform secrets. We don't claim they sit in a hardware security module, and no outside firm has audited them.
  • • Receipts are kept in durable storage. They aren't anchored anywhere outside SatGate, and the storage isn't write-once.
  • • Anyone with a receipt link can open it, until the retention period ends or the pack is deleted. Share links with care.
  • • A pass means the receipt is intact and SatGate signed it. It says nothing about what your API did next, whether a payment settled, or regulatory compliance.

What a pass proves, and what it doesn't.

Proves

The key named in issuer_kid signed the receipt. Any change to a signed field makes the check fail. The rest of the pack agrees with the signed receipt, and tokens and secrets are blanked out.

Does not prove by itself

That a payment settled, that your API's own logs agree, that a revoke took effect everywhere instantly, or anything else beyond this one receipt.