Verification steps
- Load ToneThread Root public key…
- Verify Tenant Site Certificate signature…
- Verify Post Certificate signature…
- Recompute ToneHash of post content…
- Compare recomputed hash to certificate…
Revision history
Originally published 2026-09-14, updated 2026-09-14; 7 revisions (this active certificate plus 6 prior).
| Issued | Superseded | Content hash |
|---|---|---|
| 2026-09-14T03:53:33.910Z | 2026-09-14 05:05:08 | tth_v1_ef3460b57fe4848e |
| 2026-09-14T05:05:08.153Z | 2026-09-14 05:49:00 | tth_v1_e4ce7a6d765c8ac4 |
| 2026-09-14T05:49:00.434Z | 2026-09-14 05:57:44 | tth_v1_9d57a0c75003aa72 |
| 2026-09-14T05:57:44.458Z | 2026-09-14 06:01:39 | tth_v1_9d57a0c75003aa72 |
| 2026-09-14T06:01:39.950Z | 2026-09-14 06:10:00 | tth_v1_d6a98c5fa68319d7 |
| 2026-09-14T06:10:00.259Z | 2026-09-14 11:07:56 | tth_v1_d6a98c5fa68319d7 |
| 2026-09-14T11:07:56.332Z | — active — | tth_v1_2a9877a165f88bff |
What this page exposes
Verification runs on the server. The browser only sees the public summary in the sidebar and the step-by-step ok/fail result above — never the certificate's raw signature, the tenant's raw public key, the ToneHash salt, the per-axis tonal scores, or the compact fingerprint string. Those stay on the signing host.
The public JSON at
/tonehash/cert/pardon-dolli mirrors the
same surface. To independently audit a certificate's raw
signed payload you must request an authenticated cert-bundle
export from the operator —
how to request access.