You bought something online, and your download included one or two extra
files ending in .attest or .private.attest. This page
explains what they are.
Each file is a small, signed receipt from the store you bought from. It's yours: proof that you paid for what's listed inside, signed by the seller so anyone can check it's genuine. Keep it the way you'd keep an important paper receipt — it doesn't live in any account, and nobody can take it away with a click.
You don't need to trust this page, or the store, or take anyone's word for it. Anyone can verify the receipt directly — including you, right now, in your browser, with the file never leaving your machine.
That file is the proof the purchase belongs to you: anyone holding it can claim to be the buyer. And because one private file covers your whole library, handing it over hands over proof for every purchase inside at once, not just the one you meant to show. A real store or support agent will never need it — they can already see your order. Keep it private, the way you would keep a paper receipt with your card number on it.
To prove a single purchase, use
attest disclose <receipt_id> instead: it shares that one
receipt and nothing else.
That's the whole point of this format: the receipt still works. It doesn't call home, it doesn't need the store's servers to be running, and it doesn't expire when a shop closes down. A verifier can check it entirely offline, months or years later, using nothing but the file itself and the seller's published signing key. If a store you bought from shuts down, your receipt still proves you bought what it lists — it isn't the thing itself, but it's the part of your purchase nobody can take away.