attest

For a reader with no receipt yet

Start here

You bought a game, a film, an album or a book online. What you actually got is permission to use it, kept on the store's computers. If the store closes, or your account is shut, or a licensing deal expires, that permission can vanish — and with it the thing you paid for.

attest gives you one piece of that purchase to keep. When a store uses it, your download comes with a small extra file: a receipt, signed by the seller. "Signed" means the receipt carries a seal made with the seller's signing key. Anyone can detect a later change, and only someone holding that key can make a receipt pass the check — which is why a stolen or compromised signing key still matters. You don't have to understand how the seal works. You only have to keep the file.


What you can do with it


What it does not do

Never send *.private.attest to anyone.

That file is the proof the purchase belongs to you: anyone holding it can claim to be the buyer.

Because one private file covers your whole library, handing it over hands over proof for every purchase inside at once, not just the one you meant to show.

A real store or support agent will never need it — they can already see your order.

Keep it private, the way you would keep a paper receipt with your card number on it.

Your receipt will arrive as two files. If anyone needs to see what you bought, send them the other one — the one whose name ends in .attest but not in .private.attest. It shows the same purchases and gives no one a way to claim them.