WAF++ PASS ยท Official Validation

Verify, share, and inspect WAF++ PASS official validation certificates.

The public, machine-verifiable source of truth for WAF++ compliance runs. Anyone with a validation ID can confirm that a run was countersigned by the WAF++ validation gateway.

What you can do here

Quick example

A validation link shared by a project looks like this:

https://waf.lew-app.de/api/v1/validations/123e4567-.../verify

You can paste the validation ID into the verify page, or verify the envelope locally with the CLI:

wafpass verify wafpass-validation-<hash>.json --root-public-key waf++-root.crt

All verification data is served directly from the WAF++ validation gateway. This registry site only renders the results in a human-readable form.