Verify a Locitime proof
A proof is a signed summary of someone's visits, saved as a .json file from Settings → Integrity Proof → Share. Choose that file to check it. The check runs in your browser and the file is not uploaded.
What this does and does not show
- Signature: the numbers and the visit records are exactly what the key in the phone signed. Changing one digit breaks it.
- Official build: the phone's hardware recorded which app made the key. If that app is not the one signed with the Locitime release key (certificate SHA-256
), someone changed and re-signed the app, and its proofs should not be trusted. - Not shown: that the phone was physically at the places. Place names and the key protection field in the file are not signed; the page reads the protection level from the attestation instead.
- Proofs without attestation (older phones, or a shared QR code, which is too small to hold the chain) can still have a valid signature but cannot show which build made them.