Artifact without assurance
A GitHub PR can prove code was merged, but not the scope of a maintainer's claim about the contributor's work.
Turn one public merged GitHub pull request into a credential that keeps artifact facts, issuer assurance, and Solana lifecycle state separate—and independently inspectable.
Working MVPGitHub OAuth, Phantom signing, SAS issuance, public verification
Live on Solana devnetBrowser receipt + two finalized sponsored issuance transactions
Honest stagePre-revenue; no users, partnerships, or regulatory approval claimed
This page downloads the real browser-issued credential and runs all six portable integrity checks locally. No account, wallet, or server-side verdict is involved. One opt-in judge-mode audit then asks GitHub for six stable artifact bindings, asks Solana RPC for eight SAS bindings, and attacks three fresh in-memory copies. The detailed transcripts remain open below so every pass, failure, and unavailable source can be inspected or retried separately.
The cryptographic checks run inside this browser after the bundle arrives.
This reproducible walkthrough uses no staged wallet secrets or private repository data. Captions are burned in.
Independent engineers already have public merged pull requests, but a link shows only the artifact. Generic references are vague, platform reviews are trapped inside one marketplace, and recruiters still spend time reconstructing who confirmed what.
A GitHub PR can prove code was merged, but not the scope of a maintainer's claim about the contributor's work.
Testimonials and marketplace ratings lose provenance or disappear when a developer changes platform.
Each employer repeats manual checks and depends on the issuer's or ProofPort's database remaining available.
Plain signed JSON already makes a claim portable. SAS adds the part unrelated issuers and verifiers otherwise cannot share cleanly: a neutral credential authority, schema, authorized signer, expiry, and closable lifecycle state.
Each issuer deterministically owns an isolated SAS credential and schema. A bounded sponsor pays fees and account rent, while the issuer's wallet remains the required authority and signer. ProofPort cannot manufacture an issuer receipt with the sponsor key.
With a team and resources tomorrow, the priority is not another chain feature. It is evidence that real maintainers and hiring teams value this workflow.
Complete one receipt signed by the actual maintainer of a merged contribution and document where the flow creates friction.
Test verification value with Vietnamese outsourcing firms, developer platforms, and remote hiring teams before pricing.
Add a GitHub App, managed PostgreSQL, durable hosting, issuer recovery, and Vietnam-focused legal review for a narrow pilot.
Tang Minh Vu is a Vietnam-based full-stack engineer and independent SaaS/developer-tools builder with 3+ years of experience shipping end-to-end products. He operates 10+ production systems, built ContribAI (244 GitHub stars), has 10+ upstream pull requests merged, and won a Standouts award at the Agora Agents Hackathon 2026.
Sponsor CCfSes… paid; unfunded issuer GemHKZ… remained the authority.