beta 1.28.3

Verify it’s us

Three proofs, one certificate. Every raw text below verifies offline with GnuPG.

senpera.ioprimary senpera.netmirror senpera.appmirror senperaskyrqhyqeikrsix4qpw6twz2fjzph5lftb453vj4ef2vckfid.oniontor · live
✓ signedDomain statement signed 2026-07-21key 27B0 91BB … 6BCB 896B

Exactly these domains, bound by one PGP key. Any other domain claiming to be Senpera is not us.

raw signed text · statement.txtselect all · copy
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 SENPERA DOMAIN & KEY STATEMENT ============================== Date signed: 2026-07-21 Re-signed on every change; the date above is the version. The only domains operated by Senpera: senpera.io (primary) senpera.net (mirror) senpera.app (mirror) senperaskyrqhyqeikrsix4qpw6twz2fjzph5lftb453vj4ef2vckfid.onion (tor) Primary key: 27B0 91BB 1502 93DD FF74 0403 11C1 E4B2 6BCB 896B Per-swap receipts are signed by the dedicated signing subkey of this same certificate: EE98 4E06 4464 F749 5289 E47E 20C0 56FC 4C1E F61C Verifying a receipt against the published key (senpera.asc) shows that subkey ID (20C056FC4C1EF61C) — the primary fingerprint above stays the identity to check on /pgp. Anything else claiming to be Senpera is fake. -----BEGIN PGP SIGNATURE----- iQJPBAEBCAA5FiEEJ7CRuxUCk93/dAQDEcHksmvLiWsFAmpfdd4bFIAAAAAABAAO bWFudTIsMi41KzEuMTIsMiwxAAoJEBHB5LJry4lrw1oQAMCuO7qXrQUYenEusvqt fOgPl2miQ4k1PXZ/4ljctQuck3TcQptasFawGXNIgTQvlKEcpTtt1wQ5F7jLsCdB mBtsaX9uDNhqFLYUDqlefIUKIdRcr0ZxenIVeyEGaynXWrf7nQsE9lKBYkaZXpoA VbSTuDcURbT3wy7xFZDu29r/l/WDIJJ8aQBSSLYHGmXy8grmTkBYnd4wW1ScRgR0 0S+ZEKkwo9YCdUklFp9ydCQFICYaeGbh2SUNnwRiUKqu5v5gefoqUUFICNsV73wQ 7mqn69MGN5lKAtD84XYRckmbGSRReRT5pggA+M1Gt8YrpS3sUt/BaKbwy/4GirG7 tNczopMfEIiDkaggd1qxbHMyOhIA2Yy+VcVKSEu2guIq5tP/veoDzejbpNNvVbtn WaFMGlVlCgif/20bpcafJw67Zngxk01pMl7mYZTVDN4RVJJO0Jqe/S9pv1UiqjLc tbLY6l443BpW6RI08iK166p1jS1j0li2YbBcTR39VvjCBPcZGa3ajmr/++YlvhSB yxA9k8FxIJ5iB2TSp+TIwePpvTGU9nVtmx3JoPppt8tGx+7CanX5Dr0DaW74inOx 3OxwqQkAgohBPCDIQkMjVmz1nFp+JYXRLrrRYZzbR07nsJ8Wcy9qv6HY5t+PP5zD lfdzE/phHWRMrPl/nIjtX4gD =dv7f -----END PGP SIGNATURE-----
✓ signedWarrant canary valid through 2026-08-20block 959005key 27B0 91BB … 6BCB 896B

Re-signed at least every 30 days with the same key. A missing or stale canary is itself the signal — we can be prevented from updating it, never forced to update it into a lie. It asserts: no warrants, subpoenas, national-security letters or gag orders; no key or infrastructure compromise; full control of the domains. A fresh Bitcoin block hash inside proves it wasn't signed in advance.

raw signed text · canary.txtselect all · copy
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 SENPERA WARRANT CANARY ====================== Date signed: 2026-07-21 Valid through: 2026-08-20 (re-signed at least every 30 days) Signing key: 27B0 91BB 1502 93DD FF74 0403 11C1 E4B2 6BCB 896B As of the date above, Senpera states: 1. We have received no warrants, subpoenas, court orders, national security letters, or gag orders of any kind. 2. We have not been compelled to modify our systems to facilitate surveillance or data disclosure. 3. Our PGP signing key and server infrastructure are under our exclusive control and are not compromised. 4. We retain full control of the senpera.io domain and the onion service. 5. We log nothing that could identify a user or link a swap to a person, and no third party has requested such data. Proof of freshness — Bitcoin block 959005: 00000000000000000001da550b5e9cb332445a1609bf90b4b82de5a9c397909e If this canary is missing, stale beyond its validity window, or unsigned, treat that as the signal. -----BEGIN PGP SIGNATURE----- iQJPBAEBCAA5FiEEJ7CRuxUCk93/dAQDEcHksmvLiWsFAmpfddwbFIAAAAAABAAO bWFudTIsMi41KzEuMTIsMiwxAAoJEBHB5LJry4lrPocQAJgoUbLIVeeHzyeqTZBO dnUgXPD91M0MBfGAN0yeiLMTMrTQHMy6lbLzEfo6ktbJo2sUACjeX60HsSQdaFN9 v6lAFDRiRYOut6eNURhfthT/XP+YWVyHVrBl9XHMBHVQvDnQRo7gZzwXpbTWKKjO 8NnCWYSDwUPUQ18wa/qkIMtN+cx68acg0xrn5A1ebQXCVF2wyG237ueK5XsbNobU OB00GZXAjbyJhVQMqicpADLqHCscbNfbRygDcZpwwfnjby8BA8bbn1XbaH/f+fSK DkIvAs4J6Jp4qP4YC5DtD7gM7OhkqKFfpHtdG0Sbjeai3bCrUttAUwG7KBxB0K3L 3pYmWtcyMl0hUxDTXq+Jb2m8I/UCRWDxK1MsfX+kI9LQv+a7zUD2nvwkARODrg86 fyZXmku4zSM9SDdwSqQOvp2VluwXeNFyCtZYKtpRDlhRzCl96zqu/B5IDE6m1nyp E/DewZDcZozM0O8QEEBY5Brn+SEhJZVau8YNhP+MA0gLawcCdcYUDFuMwFpv1Opq TidaYp4Yr6wlr3VJcxCSmQ4829lWacC45CZYk4Z+lmOOEO5AbTyZfYkVR1CRvZ0i M+VhJ+s8qZ6D90EjIYlNewMk6bTLCn0XI0kCxP/Egw904k4c3Xzc6Y9CH6RvVsY9 LfjsCWNmgP+CzTuTSET93yon =bkZq -----END PGP SIGNATURE-----
subkeyPer-swap receipt signature subkey 20C056FC4C1EF61Csame certificate

The same certificate signs the per-swap receipt — terms and deposit address at the moment of issue. If a receipt doesn’t verify against it, the quote didn’t come from us.

gpg on a receipt shows subkey ID 20C056FC4C1EF61C — a dedicated signing subkey of the same certificate; the primary fingerprint you verify on /pgp does not change, and the subkey’s full fingerprint is pinned in the signed statement.

Verify a signature — tool

The honest no-JS path is the GnuPG blocks above: everything runs on your device, nothing reaches us, it works offline. A paste-a-message checker may land in a later bundle — and it will say plainly: pasted text does reach the server, so for zero-trace verification GnuPG stays the reference path.

ratesBTC $79,903ETH $2,460XMR $543SOL $102RUNE $0.483 protocol pool mid · xmr via public market data · refreshed each minute

Product

SwapPopular pairsTrack a swapAPI for agents

Learn

How to useGuidesFeesCoins & limitsDepth by size

Trust

VerifyPGPCanaryLines statusAbout & contact

Legal

TermsPrivacyDisclaimersecurity.txt