Verification Service
LIVEVerify the delivery status, routing path, and integrity of any envelope using its hash. Zero content exposure — only metadata and integrity flags are returned. Available as a single-hash lookup or batch verification for compliance audits.
Single Verification
cURL
curl -X POST https://arcform-api.com/v1/verify \
-H "Content-Type: application/json" \
-d '{"envelope_hash": "aa4a2d3dadd8ba65"}'bashJavaScript SDK
const proof = await client.verify("aa4a2d3dadd8ba65");
console.log(proof.status); // "verified"
console.log(proof.integrity.delivery_confirmed); // true
console.log(proof.bubble_state.content_stripped); // truejavascriptPython SDK
proof = client.verify("aa4a2d3dadd8ba65")
print(proof["status"]) # "verified"
print(proof["integrity"]["delivery_confirmed"]) # True
print(proof["bubble_state"]["content_stripped"]) # TruepythonBatch Verification
Pass an array of envelope hashes to verify multiple deliveries in a single request. Ideal for compliance audits and automated pipeline checks. Maximum 50 hashes per batch.
curl -X POST https://arcform-api.com/v1/verify \
-H "Content-Type: application/json" \
-d '{
"envelope_hashes": [
"aa4a2d3dadd8ba65",
"b48f21c316cb75f6",
"c93e4a7f28d1e092"
]
}'bashconst results = await client.verifyBatch([
"aa4a2d3dadd8ba65",
"b48f21c316cb75f6",
"c93e4a7f28d1e092"
]);
results.results.forEach(proof => {
console.log(proof.envelope_hash, proof.status);
});
console.log(results.summary);
// { total: 3, verified: 2, partial: 1, orphaned: 0, unverified: 0 }javascriptProof-of-Transit Response
{
"status": "verified",
"envelope_hash": "aa4a2d3dadd8ba65",
"verified_at": "2026-07-01T12:00:00.000Z",
"proof_checksum": "5f4dcd70a812503ad3aec82eb1110fdf...",
"audit_spine": {
"api_key_id": "ak_7f3a9b2c...",
"sender_key_id": "ak_7f3a9b2c...",
"sender_did": "did:comms:7d0a720e...",
"recipient_did": "did:comms:9e1b830f...",
"delivery_status": "delivered",
"anchor_status": "anchored",
"mediator_hops": 1,
"payload_size_bytes": 51,
"latency_ms": 12,
"anchored_at": "2026-07-01T11:59:58.000Z"
},
"identity": {
"identity_verdict": "ok",
"key_status_at_send": "active",
"key_current_status": "active",
"sender_key_id": "ak_7f3a9b2c...",
"sender_fingerprint": "A1B2:C3D4:E5F6:7890",
"signer_set_id": null,
"signer_set": null,
"lineage_events": []
},
"bubble_state": {
"current_status": "fetched",
"signal_type": "message",
"content_stripped": false,
"fetched_at": "2026-07-01T12:00:05.000Z",
"expires_at": "2026-07-02T12:00:00.000Z",
"created_at": "2026-07-01T11:59:59.000Z"
},
"integrity": {
"audit_record_exists": true,
"proof_checksum_valid": true,
"delivery_confirmed": true,
"routing_recorded": true
}
}jsonVerification Verdicts
verifiedIntegrity valid + identity ok at send-time (key active or historically active). Full trust.partialIntegrity valid but identity ambiguous or missing. Audit spine intact, sender trust indeterminate.degradedIntegrity valid but key was revoked/rotated before send-time, or sender was not in the authorised signer set. Content intact, sender compromised.orphanedBubble record exists without a matching audit spine entry — data integrity inconsistency.unverifiedNo records found for the given envelope hash.Integrity Flags
audit_record_exists— EnvelopeLog contains a record for this hashproof_checksum_valid— Recomputed proof checksum matches the stored valuedelivery_confirmed— EnvelopeLog status is 'delivered'routing_recorded— Envelope was routed through at least one mediator hopUse Cases
Regulatory Compliance
Prove PII was delivered and consumed without storing the content. The proof-of-transit object acts as a digital notary receipt.
Credential Rotation Audits
After rotating API keys or secrets via sealed envelopes, batch-verify that every credential was delivered and the ephemeral content was stripped.
Contract Delivery Verification
High-stakes document handovers can be verified after the fact — confirming the envelope reached the intended DID, the content was fetched, and the bubble was sealed.