Flaschenpost Verify

TPM2 hardware attestation verification for signed JSON payloads

📨

Drop a Flaschenpost JSON file here
or click to select

Attestation
Method —
Signed at —
Version —
Content Hash (SHA-256)
Hash valid —
Stored
—
Computed
—
RSA Signature
Signature valid —
Key hash —
Signature —
Payload
Type —
Timestamp —
Language —
Content fields —
How verification works:
1. The content field is serialized as JSON (sorted keys, UTF-8).
2. A SHA-256 hash is computed and compared to the stored content_hash.
3. The RSA-2048 signature is verified against the TPM2 public signing key.

The signing key lives inside a Nuvoton NPCT75x TPM chip. The private key never leaves the hardware. All verification happens locally in your browser — no data is sent anywhere.

github.com/agentic-mingle/flaschenpost