What is this file?

You bought something online, and your download included one or two extra files ending in .attest or .private.attest. This page explains what they are.

Each file is a small, signed receipt from the store you bought from. It's yours: proof that you paid for what's listed inside, signed by the seller so anyone can check it's genuine. Keep it the way you'd keep an important paper receipt — it doesn't live in any account, and nobody can take it away with a click.

You can check it yourself, without the store

You don't need to trust this page, or the store, or take anyone's word for it. Anyone can verify the receipt directly — including you, right now, in your browser, with the file never leaving your machine.

Verify a receipt →

Never send *.private.attest to anyone.

That file is the proof the purchase belongs to you: anyone holding it can claim to be the buyer.

Because one private file covers your whole library, handing it over hands over proof for every purchase inside at once, not just the one you meant to show.

A real store or support agent will never need it — they can already see your order.

Keep it private, the way you would keep a paper receipt with your card number on it.

To prove a single purchase, use attest disclose <receipt_id> instead: it shares that one receipt and nothing else.

What if the store is gone?

That's the whole point of this format: the receipt still works. It doesn't call home, it doesn't need the store's servers to be running, and it doesn't expire when a shop closes down. A verifier can check it entirely offline, months or years later, using nothing but the file itself and the seller's published signing key. If a store you bought from shuts down, your receipt still proves you bought what it lists — it isn't the thing itself, but it's the part of your purchase nobody can take away.