Check a receipt without trusting FullCup.ai
Every request a funded project makes produces a signed receipt. This page explains what that signature means, what it does not mean, and how to check one yourself.
What a receipt is
A record of one request: which model ran, how many tokens it used, what it cost, when it happened, and which cup it belongs to. FullCup.ai signs that record with Ed25519 and publishes the public key.
A receipt never contains the prompt, the completion, or any user content. There is nothing in it to leak, because the content was never written down.
What the signature proves, and what it does not
a product that sells verifiability owes you its edges- It proves the record was not altered
If the signature checks out, those numbers are exactly the ones FullCup.ai issued for that request, and nobody changed them afterwards, not the creator and not FullCup.ai. The ledger is hash-chained on top of that, so removing a receipt breaks the chain.
- It does not prove the work was useful
The signature says a request happened and what it consumed. It does not say the model produced anything good, and it is not independent attestation of the upstream provider, because FullCup.ai is the one signing. That is the second rung of the attestation ladder, not the third, and this page would rather say so than let you assume otherwise.
How to check one
three steps, none of them ask FullCup.ai for permission-
1
Fetch the public key
/.well-known/fullcup-signing-key
-
2
Rebuild the canonical form
In the field order below, exactly.
-
3
Check the signature
Runs on your machine, never calls FullCup.
Canonical field order. Rebuild the body in exactly this order.
["id","cup_id","key_id","model","prompt_tokens","completion_tokens","total_tokens","cost_micro_usd","price_source","upstream_id","workload_tag","created_at"]
Public key
HiJHv/xlhWVV5GijGczyyq86EBQT1oZiTwqBK7IV570=
Check one right here
runs in your browser; nothing is sent anywhereThis form does not send anything to FullCup.ai. Paste a receipt from any cup, or one you saved earlier, and the check runs locally against the published key.