Digital Product Passport
Verify a passport independently
- Obtain the cluster's public key from a trusted source (the cluster's official website, a contract annex) and compare the key fingerprint.
- Take the token from the QR code and download the passport JSON from
/api/pasport/<token>. - Verify the text in
haqiqiylik.bayonotagainsthaqiqiylik.imzowith the Ed25519 algorithm:
node vositalar/imzo-tekshir.js <passport URL> kalit.pem
Do not take the public key from the site that shows the passport: a fake site can display its own key.