Verification steps

  1. Load ToneThread Root public key…
  2. Verify Tenant Site Certificate signature…
  3. Verify Post Certificate signature…
  4. Recompute ToneHash of post content…
  5. Compare recomputed hash to certificate…

Revision history

Originally published 2026-09-14, updated 2026-09-17; 7 revisions (this active certificate plus 6 prior).

IssuedSupersededContent hash
2026-09-14T02:57:38.744Z 2026-09-14 03:07:16 tth_v1_9d79de35b393422e
2026-09-14T03:07:16.509Z 2026-09-14 03:52:49 tth_v1_bdf27339683056f8
2026-09-14T03:52:49.786Z 2026-09-14 05:00:59 tth_v1_1ee14c96b92c14a3
2026-09-14T05:00:59.859Z 2026-09-14 05:45:30 tth_v1_f8a22830652c1cc3
2026-09-14T05:45:30.302Z 2026-09-14 06:01:03 tth_v1_7260b2c3d61623aa
2026-09-14T06:01:04.423Z 2026-09-17 10:39:37 tth_v1_7de810136bcfcbb3
2026-09-17T10:39:37.427Z — active — tth_v1_ce98901043c0ae18

What this page exposes

Verification runs on the server. The browser only sees the public summary in the sidebar and the step-by-step ok/fail result above — never the certificate's raw signature, the tenant's raw public key, the ToneHash salt, the per-axis tonal scores, or the compact fingerprint string. Those stay on the signing host.

The public JSON at /tonehash/cert/levee-fourteen-stamped-records mirrors the same surface. To independently audit a certificate's raw signed payload you must request an authenticated cert-bundle export from the operator — how to request access.