v3

latestOpenAPI 3.0.32026-08-05363479.3 KB

Verify immutable NHS signature separately from freshness and current accounting state

post/action-receipts/verify

Request body

signed_receiptstring required

Exact canonical JSON returned by NHS

signaturestring required

Unpadded base64url HMAC

Response

Signature validity, time-window status, and current online commercial state when available

signature_validboolean
within_validity_windowboolean
time_status'current' | 'expired' | 'not_yet_valid' | 'invalid_time'
current_state_availableboolean
current_state_status'current' | 'not_found' | 'unavailable'