Skip to main content
Encypher Logo
Sample data: a fixed, fictional catalog signed with sandbox keys.
Authorized Supply (Ad Tech)

Prove which offers you authorized.

Give buyers a way to distinguish inventory you authorized from an offer that merely claims your name. Six short chapters, one fixed catalog, and every proof checkable in this browser.

Publish and sign

A fictional publisher, The Meridian Ledger, signs an article at publication. The signature names the property and the signing key, so anyone holding the article can confirm what was published and by whom.

The Meridian Ledger

Harbor District Approves the Port Expansion

Content identity
meridian-ledger/port-expansion-2026-07
Property
article_inventory
Signer
listing-2026-07
Verified state
Signed at publication. Verification passes.

Authorize the offer

The article backs a publisher-authorized ad-space listing. The offer terms below, six fields exactly, are canonicalized, hashed, and bound into the publisher listing signature. Change any field and the signed digest no longer matches.

The six signed terms behind the publisher listing proof.

currency
USD
price
10
pricing_model
cpm
pricing_option_id
po-verified-encypher
product_id
verified-encypher
property_id
article_inventory

A counterfeit appears

Another seller re-uses the publisher listing signature for a different offer, syndicated inventory the publisher never authorized.

The counterfeit signature is cryptographically valid. What fails is the binding: the digest inside the signature covers the terms the publisher authorized, and the substituted terms hash to a different value. Signatures do not stop copying. Digest binding makes the substitution detectable by any buyer who checks.

The buyer checks, automatically

A buyer sets a policy once and the check runs on every offer. The table below is already computed under the strictest policy, Require proof. Prefer and Ignore are one tap away for comparison.

The buyer requires publisher-authorized provenance. Both authorized offers stay eligible and the buyer selects among them, in this run the compatibly signed offer. The substituted offer and the unproven rows are excluded, each with a reason a person can read.

OfferProvenanceEligibilityWhy
Northfield Sports Daily
Sports section ad space, signed with a compatible provenance key.
verified-compatible / sports_inventory
Verified
EligibleSelected
Publisher listing proof verified. The terms are the ones the publisher signed.
The Meridian Ledger
Article backed ad space, signed by the publisher at publication.
verified-encypher / article_inventory
Verified
Eligible
Publisher listing proof verified. The terms are the ones the publisher signed.
Harbor Weather Report
Ad space whose listing proof carries a signature that does not verify.
invalid-proof / weather_inventory
Unverified
Excluded
The listing proof failed signature verification.
Culture Notes Weekly
Ad space offered without any listing proof.
ordinary-unsigned / culture_inventory
Unverified
Excluded
No listing proof was presented for this offer.
Syndicated Reseller Offer
An offer that reuses a valid listing signature for different terms.
counterfeit-listing / syndicated_inventory
Unverified
Excluded
Valid signature, substituted terms. The signed digest does not match this offer.

The publisher win is eligibility and demand access: authorized offers stay in the running with buyers who check, and an offer that borrowed the publisher name is excluded with a stated reason.

The Require outcome, translated for your team

Commercial lead

Authorized offers stay eligible with buyers who require proof, and a substituted offer that uses your name is excluded with a stated reason.

Ad operations

Every row carries a reason you can read and forward. Exclusions come from failed checks on signed terms, not from a vendor score.

Editorial and product

The article is signed at publication. The listing proof extends that discipline to the ad-space offer the article backs.

Technical evaluator

Every artifact is one disclosure away: compact JWS, public JWK, key thumbprint, and two checks that run in this browser against committed sample vectors.

The signed receipt

The run ends with a receipt you can keep and forward. Four things were proved, and the evidence for each sits one disclosure away.

  • Content proof: the article was signed at publication and verifies.
  • Listing proof: the offer terms were bound into the publisher listing signature.
  • Policy decision: every offer carries its eligibility and a stated reason under the buyer policy.
  • Run-key receipt: the run record is signed with the sandbox run key.

Receipt fields, sanitized sample values.

sandbox_run_key
1f6a2c3e-8d4b-4f0a-9c2d-5e7b1a3c9d40
signature_verified
true
proof_scope
schema_digest_and_run_key_signature
record_key_thumbprint
uM9xpCqvv29Z6IC-gh17R_AmwM_3YFOFdH6Po0a9760

Run a pilot

Test one property, ten URLs, and one buyer policy. Your team reads the outcomes in a table like the one above, with every proof attached.

More demos: try it yourself, no accountfor AI teamsfor publishersper-sentence signing liveprivate team walkthrough