Verify any Deliver Hub shipment.
Independently.
Every lifecycle event — pickup, in-transit, out-for-delivery, delivered, RTO — is signed with an Ed25519 key owned by the actor that reported it, and hashed into a tamper-evident chain. No one can rewrite history after the fact — not Deliver Hub, not the courier, not the merchant.
Paste a shipment id to verify
You’ll be taken to the shipment’s signed event timeline.
What this proves
Every event is cryptographically signed
Pickup, in-transit, out-for-delivery, delivered, RTO — each one carries an Ed25519 signature from the actor who reported it (platform, courier, or merchant).
Events are hash-linked
Each event hashes its own payload together with the previous event’s hash. Inserting, re-ordering or deleting an event anywhere in the chain breaks every hash after it.
Public key fingerprints are published
The verifier at /verify/<id> re-checks every signature against the actor’s published key. If a key rotates, the old fingerprint is still verifiable.
Anyone can verify, without an account
The verify endpoint is public and read-only. Insurance adjusters, auditors, buyers and regulators get the same answer as a logged-in merchant.
Technical details
For engineers and auditors.
ExpandCollapse
Technical details
For engineers and auditors.
Ed25519 (RFC 8032). Each actor — the platform, each courier integration, and any merchant that enrols a key — holds a private key; the corresponding public key is published and referenced by its SHA-256 fingerprint. Signatures are computed over the canonical JSON encoding of the event payload plus the previous event’s hash, so a signature only validates in its original position in the chain.
SHA-256. Event n’s hash is SHA256(payload_n ‖ hash_(n-1)). The genesis event uses a null previous-hash. Changing a single byte in any event invalidates its hash and every subsequent hash in the chain.
Events live in an append-only table. There is no in-place update path in application code; even a Deliver Hub operator with database access cannot amend an event without the hash check at /verify/<id> flagging the chain as broken.
GET /api/public/verify/<shipmentId> returns the ordered event list plus per-event hashValid and signatureVerified flags. The response is deterministic — the same inputs always yield the same badge. Chains that include legacy webhook events (recorded before signing was available for a given courier) are reported as partially verified rather than broken.
Verification covers what was reported into the chain. It confirms that the recorded events were signed by the stated actors and have not been altered since; it does not independently witness the physical events themselves.