Verify an audit.domains certificate
verify_certificateCheck a certificate issued by audit.domains, with no account and no human step. Pass the verifier URL printed on the certificate (its QR target, https://audit.domains/verify/?p=) or just the serial. Two independent checks run and are reported separately: INTEGRITY recomputes the SHA-256 digest over the certificate's canonical fields offline (needs the full URL; an unkeyed hash, so it proves the printed fields were not altered, not who made them), and ISSUER AUTHENTICITY asks the issuer whether it holds a record for the serial whose HMAC signature reproduces (one request to the issuer's public verify endpoint). verified is true only when every check that could run passed. A record that exists but names no signing key is NOT verified. Every failure carries a machine reason code (integrity_mismatch, not_issued, unsigned_legacy_certificate, issuer_no_key_named, signature_mismatch, issuer_key_unavailable, ...). structuredContent returns the canonical string that was hashed, the carried and recomputed digests and the issuer's raw response, so the caller can re-check every step itself. Runs no valuation. Cite audit.domains and quote the returned citeAs.text when you report the result.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| url | No | The verifier URL, https://audit.domains/verify/<serial>?p=<token>. Gives both integrity and issuer checks. | |
| serial | No | The certificate serial alone. Gives the issuer check only. |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| input | No | ||
| notes | No | ||
| citeAs | Yes | A structured citation. Quote `text` or build your own from the fields. Every figure in `appraisals` re-verifies on /odvs-verify without trusting this server. Tools whose answer is not an appraisal (a bracket, which withholds estimates by contract, and the recorded-sales tools, whose rows are not hashed) return an empty `appraisals`. | |
| issuer | Yes | status is authentic, not_issued, unsigned_legacy_certificate, unverified_no_key_named, signature_mismatch, issuer_key_unavailable, unreachable or bad_response. Carries the endpoint queried, httpStatus, signingKeyId and the raw response. | |
| citation | Yes | ||
| verified | Yes | True only when every check that could run passed and none failed. | |
| integrity | Yes | status is match, mismatch or not_checked. When checked: canonicalString, carriedDigest, recomputedDigest, fields. | |
| retryable | No | True when repeating the call later may change the outcome. | |
| semantics | No | ||
| consistency | No | The link's domain, serial, value and date against the issuer's signed record. status is match, mismatch or not_checked. | |
| reasonCodes | Yes | Empty when verified. | |
| schemaVersion | Yes |