Check it
yourself.
What the router has verified about a provider’s hardware attestation, what it has not, and a receipt checker that runs in your browser against the keys the router publishes. Anything unverified stays marked unverified.
What we saw
A plain-English reading of a receipt: output and usage, who could read the request, who saw your address, how it was paid, what was kept and what hardware answered. The router works it out from the signed receipt, and on ordinary chat paths it reads the prompt in memory to route it. The encrypted-chat path forwards ciphertext. Enter the id from the X-Receipt-Id header.
Verify a receipt
Paste a receipt from a response, or from GET /api/v1/receipts/<id>. It is checked in this browser against the keys the router publishes at /.well-known/anyroute-receipt-keys.json. A receipt with a v2 (COSE) encoding gets that checked too: signature, chain head and Merkle path. Nothing you paste is sent anywhere.
Verify a monthly statement
Paste or drop signed JSON. The browser checks the canonical JSON signature with the router’s published receipt keys and reconciles its amounts. The JSON stays on your device.
Check the provider itself
The record above is the router’s account. The SDKs go further before they send anything: they read the provider’s own /attest, check that the quote commits to its TLS key and digests, that its certificate name is derived from the quote, and refuse if any of it fails. They do not repeat Intel’s signature check on the quote; the router does that, and the SDK says so in its report.
import { AnyRoute } from "@anyroute/client";
const client = new AnyRoute({ baseUrl: "https://<router>", apiKey: process.env.ANYROUTE_API_KEY });
// Reads the router's record and the provider's own /attest, checks the quote binds its TLS key and digests,
// and throws AttestationRefused before anything is sent if a check fails.
const res = await client.chat.completions.create(
{ model: "<model>", messages: [{ role: "user", content: "Hello" }] },
{ attested: { providerId: "<provider id>", attestUrl: "https://<provider>/attest", expected: { modelDigest: "sha256:<digest you expect>" } } },
);
console.log(res.anyroute.receiptVerification.valid);
History and badge
The registry keeps every measurement the router verified for an attested provider, and every check it ran. Each entry has a badge any site can embed, which re-reads this record from the visitor’s browser and shows Attested only when the checks pass.
Proven hardware
The hardware check passed; this does not hide ordinary prompts from the router or prove answer quality.
Compare the provider id below with the receipt. Read the current quote checks and their gaps; a receipt records the check at the time of that call. Look up hardware evidence →
Encrypted end to end
The device-encryption path sends ciphertext through the router to the attested gateway; routing and billing details remain visible.
Use the device-encryption gateway setup. Check the receipt’s end_to_end_encrypted and e2ee fields; a model’s Encrypted chat capability alone does not show this path was used. Check the encrypted-chat setup →
Unlinkable route
Tor onion access and blind tokens separate your address and payment from the request; the router still reads ordinary prompts in memory.
Use Tor onion access and blind tokens. Check the receipt’s unlinkable lane and blind-payment fields. Timing and purchase size can still suggest links. Check the transport and payment requirements →
Standard provider
No hardware proof is established by this record; ordinary requests are readable by the router and provider.
Inspect the receipt and provider record below. A lane name, a private switch or an owner’s description cannot replace hardware evidence. Look up the provider record →
Stored answer
This answer came from the response cache; no provider ran for this call and the router read the request in memory.
Inspect the receipt’s mode and provider fields for cache. A stored answer does not prove that hardware ran for this call. Read the receipt record →
Signed receipt
A signature is recorded for this receipt; use the checker to verify it, its signing key and its limits.
Retrieve the receipt JSON and paste it into the browser checker below. A recorded signature or receipt id does not establish validity; check the key and anchoring limits too. Open the signature checker →
Track-record certificates
These are router-signed records of an agent’s history through AnyRoute, with a fresh pseudonym and a seven-day lifetime. They do not prove current hardware, answer quality or activity outside AnyRoute. Inspect the signed certificate JSON and expiry on the profile. The receipt checker below checks receipts, not track-record certificates.
Read the certificate format and limits →