Document verification

Check your file matches the approved version.

Register the approved version. Let anyone check whether their file matches, through a public link or your software.

Already have a certificate? Enter its code.

Exact file
Compare the version
No account
For the recipient
No upload
Compare in your browser

Matching bytes do not prove authorship or truth. Local development version.

Same name. Not necessarily the same document.

You approve a proposal, then receive a copy with a changed clause. Both files have the same name. CheckThisFile lets you check that the second one is not the approved file.

One check. Many workflows.

Where documents change hands.

Keep the software you already use. Add a way to check the approved file, wherever it goes.

CONSTA / INTEGRITYIllustrative workflow
Approved versionSHA-256 · 7c8a…
Received attachmentSHA-256 · 7c8a…
Same bytesValid signatureCurrent certificateverified: true

Email attachments

Your provider delivers the email. CheckThisFile checks the attachment, not delivery, reading or recipient identity.

Build this integration

Integration patterns, not pre-installed plugins or partner endorsements. Every certificate requires the recorded review and approval workflow.

Built for integration

A check, not another document platform.

Calculate the hash in your system. CheckThisFile compares it with the signed record and checks the certificate's current status. No file upload is needed for this request.

REST APIJavaScript / TypeScriptMCPOpenAPI 3.1
Read the quickstart

API access requires an enabled plan and a scoped server-side key. SDK available as a local download, not yet on npm.

SERVER / JAVASCRIPTUsage example
const result = await ctf.verifyBytes({
  publicId: certificate.publicId,
  bytes: await readFile(documentPath),
});

if (result.verified) {
  // Exact approved version, current certificate
}
POST /api/v1/verify{ "verified": true, "reason": "MATCH" }Extract from an illustrative response

Start free. Grow when you need to.

One unit: a new registered file version. Public certificate checks are free.

Free

€0 / month

100 file registrations / month

  • 3,000 API + MCP requests / month
  • 1 API keys
  • Version history and signed records
  • Usage warnings at 80%, 95% and 100%
Start free · ES

Pro

€29 / month

1,000 file registrations / month

  • 30,000 API + MCP requests / month
  • 5 API keys
  • Version history and signed records
  • Usage warnings at 80%, 95% and 100%
Choose plan · ES

Scale

€149 / month

10,000 file registrations / month

  • 300,000 API + MCP requests / month
  • 20 API keys
  • Version history and signed records
  • Usage warnings at 80%, 95% and 100%
Choose plan · ES

Occasional extra usage, without a subscription

100 additional registrations for €5. Buy a prepaid pack explicitly; no automatic charges or upgrades. Purchased registrations carry over between months.

Included quotas reset on the first day of each month at 00:00 UTC. Extra registrations do not increase API, storage or notification limits. Launch prices, excluding applicable taxes. Purchases require configured Stripe billing; warnings by email require configured Resend.

How it works

A record for the exact version. A check for whoever receives it.

  1. Register the file

    CheckThisFile calculates a SHA-256 hash for the uploaded version. Registration and review send bytes to the server; the original is not retained by default after analysis.

  2. Record the review

    The reviewer supplies that exact file and states what they checked. This records a declaration, not independent proof of the work.

  3. Approve and issue

    An authorised account assumes responsibility and issues the signed certificate with explicit public-disclosure consent.

  4. Check the received copy

    Use the link to compare in the browser, or send the hash through REST. Check the file match, signature and certificate's current status together.

Three checks. Separate answers.

File integrity, signed record and current status. None should be mistaken for a guarantee about the content.

Exact bytes · SHA-256
Any byte change gives a different hash. This includes metadata changes: visually identical files can differ. No automatic monitoring takes place; compare the file again.
Signed record · Ed25519
The service verifies the certificate's signature. The signature belongs to CheckThisFile, not to an independent authority or the document's author.
Current certificate
Check whether the certificate is valid, revoked or superseded. A matching hash does not make a revoked certificate current.
Original file and privacy
Hash verification sends no file bytes. Registration and review do. Metadata and process records remain; an organisation may opt into temporary encrypted storage.
A record of review and approval. Not a guarantee of truth.

No qualified electronic signature, notarisation, authorship guarantee, certified delivery or independent identity check.

Before you integrate

The important limits, without the fine print.

Can an agent use CheckThisFile?

Yes, through a scoped REST key or read-only MCP. An agent must not fabricate a human review or approval. OAuth connectors are not yet supported.

Do you send secure email?

No. Your email service sends the message. CheckThisFile can be used to check the approved attachment, but does not prove delivery or reading.

Can I check any document immediately?

You need an issued CheckThisFile certificate for comparison. The current issuance workflow requires a recorded review and approval; a hash alone is not an approval certificate.

Is the entire product in English?

This website, the public verification and integration documentation support English. The authenticated workspace currently uses Spanish.

Is this production-ready worldwide?

No. Deployment, operational support, billing and parser isolation must be completed before public untrusted file ingestion. API quotas are limits, not measured global capacity.

Make the approved version
easy to check.

Add document verification to your product, without building another document platform.

Start with the API Private deployment. Access follows the registration policy.