Public verifier

Verify any Deliver Hub shipment.Independently.

Every lifecycle event — pickup, in-transit, out-for-delivery, delivered, RTO — is signed with an Ed25519 key owned by the actor that reported it, and hashed into a tamper-evident chain. No one can rewrite history after the fact — not Deliver Hub, not the courier, not the merchant.

Paste a shipment id to verify

You’ll be taken to the shipment’s signed event timeline.

No account required. The signed chain is public read-only.

What this proves

  • Every event is cryptographically signed

    Pickup, in-transit, out-for-delivery, delivered, RTO — each one carries an Ed25519 signature from the actor who reported it (platform, courier, or merchant).

  • Events are hash-linked

    Each event hashes its own payload together with the previous event’s hash. Inserting, re-ordering or deleting an event anywhere in the chain breaks every hash after it.

  • Public key fingerprints are published

    The verifier at /verify/<id> re-checks every signature against the actor’s published key. If a key rotates, the old fingerprint is still verifiable.

  • Anyone can verify, without an account

    The verify endpoint is public and read-only. Insurance adjusters, auditors, buyers and regulators get the same answer as a logged-in merchant.

Technical details

For engineers and auditors.

Expand
Signature scheme

Ed25519 (RFC 8032). Each actor — the platform, each courier integration, and any merchant that enrols a key — holds a private key; the corresponding public key is published and referenced by its SHA-256 fingerprint. Signatures are computed over the canonical JSON encoding of the event payload plus the previous event’s hash, so a signature only validates in its original position in the chain.

Hash chain

SHA-256. Event n’s hash is SHA256(payload_n ‖ hash_(n-1)). The genesis event uses a null previous-hash. Changing a single byte in any event invalidates its hash and every subsequent hash in the chain.

Storage

Events live in an append-only table. There is no in-place update path in application code; even a Deliver Hub operator with database access cannot amend an event without the hash check at /verify/<id> flagging the chain as broken.

Verification path

GET /api/public/verify/<shipmentId> returns the ordered event list plus per-event hashValid and signatureVerified flags. The response is deterministic — the same inputs always yield the same badge. Chains that include legacy webhook events (recorded before signing was available for a given courier) are reported as partially verified rather than broken.

Verification covers what was reported into the chain. It confirms that the recorded events were signed by the stated actors and have not been altered since; it does not independently witness the physical events themselves.