Check a capture, or bring your own
The check starts by itself when the page loads, using capture 3. You do not need to do anything. Each line ends in PASS or FAIL, and the last line gives the verdict: ACCEPTED means the report is genuine.
To check something else, click another capture, or load a quote file from your own computer. Your file is read in this browser and never sent anywhere. New to these terms? See the site's plain-English list.
How to read the result
- profile: the file is the kind of report this page knows how to check (TDX version 4).
- step 1: the processor's attestation key signed the report.
- step 2: Intel's quoting enclave, a small Intel program on the same chip, vouches for that key.
- step 3: that vouching is signed by the chip's own Intel certificate (PCK).
- step 4: the certificates lead back to Intel's root certificate, which is built into this page.
- key binding (capture 3 only): the report names the key that signed a TRACE receipt published beside it.
Capture 3 links the hardware report to a signed TRACE receipt. Software inside the protected machine created a signing key and wrote its fingerprint (a SHA-256 hash) into the report. The receipt and the program that made both are published here. Captures 1 and 2 are earlier reports from a different protected virtual machine. They carry fingerprints of manifests whose contents were not published, so they show only that the chip is genuine.
What the quote says
MRTD and RTMR0 to RTMR3 are fingerprints of the software the machine loaded. REPORTDATA is a 64-byte field the software inside can fill; capture 3 puts the key fingerprint in its first half. The certificates are the chain back to Intel.
What this proves, and what it does not
A pass means a genuine Intel TDX processor produced and signed this report, through a chain of certificates that ends at Intel's root.
For capture 3 it also means the TRACE receipt was signed by a key created inside that protected machine. In the TRACE runtime evidence profile, this is the attested grade.
It does not show that the software inside was the software anyone intended. The page shows the software fingerprints but does not compare them with expected values. The receipt names no model and no policy: it exists only to show the key link, and says so in its own fields.
It checks signatures only. It does not check whether the chip's firmware is up to date (what Intel calls TCB status), or whether any certificate has been revoked.
Certificate dates are checked against your device's clock.
Technical detail: the key binding and what a measurement match does not prove
The key binding holds when the SHA-256 of the record's cnf.jwk.x equals REPORTDATA[0:32], and the record carries this quote and claims its MRTD. The record's own signature is checked in CI with the Python SDK, not in this page.
Captures 1 and 2 come from one trust domain and share an MRTD. Matching a record's claimed measurement against a quote's MRTD binds the record to a measurement, never to a particular quote. Only the key binding ties a record to one quote.
A port, held to its original
The code on this page, verify/tdx-verify.js, is a JavaScript copy of the Python verifier in the Agent Manifest SDK, agent_manifest._tdx_verify. It reads the report the same way and runs the same four steps in the same order.
On every change, CI runs both verifiers over the three captures and 5,526 deliberately damaged copies of them. The build fails if the two disagree on a single one.
Technical detail: what the differential test covers
The port does the same parse and the same checks on every length the quote declares. The 5,526 generated inputs are byte flips across every length and type field and the certificate text, a stride over everything else, and truncations at each structure edge. The same CI job checks capture 3's record with the Python SDK: its signature, the key binding, the quote and MRTD it carries, and that the published capture program is the one the record names.
To run the original yourself:
python -m pip install agent-manifest
curl -fsSLO https://agentrust-io.com/verify/fixtures/gcp-tdx-2026-09-14-keybind_quote.bin
python -c "from agent_manifest._tdx_verify import verify_tdx_quote; print(verify_tdx_quote(open('gcp-tdx-2026-09-14-keybind_quote.bin', 'rb').read()))"
A genuine quote prints True.