Verification steps
- Load ToneThread Root public key…
- Verify Tenant Site Certificate signature…
- Verify Post Certificate signature…
- Recompute ToneHash of post content…
- Compare recomputed hash to certificate…
Revision history
Originally published 2026-09-14, updated 2026-09-14; 5 revisions (this active certificate plus 4 prior).
| Issued | Superseded | Content hash |
|---|---|---|
| 2026-09-14T05:35:36.722Z | 2026-09-14 05:39:07 | tth_v1_ddc91bf5be569b0b |
| 2026-09-14T05:39:07.498Z | 2026-09-14 05:49:27 | tth_v1_ea611b8c8ef4c4be |
| 2026-09-14T05:49:27.299Z | 2026-09-14 05:50:21 | tth_v1_5362d12ab251cda4 |
| 2026-09-14T05:50:22.022Z | 2026-09-14 06:34:00 | tth_v1_6c0b16cd0bff9b29 |
| 2026-09-14T06:34:00.753Z | — active — | tth_v1_014d6cfa6924a0cc |
What this page exposes
Verification runs on the server. The browser only sees the public summary in the sidebar and the step-by-step ok/fail result above — never the certificate's raw signature, the tenant's raw public key, the ToneHash salt, the per-axis tonal scores, or the compact fingerprint string. Those stay on the signing host.
The public JSON at
/tonehash/cert/pardon-dolli-tonehash-and-the-record-we-can-check mirrors the
same surface. To independently audit a certificate's raw
signed payload you must request an authenticated cert-bundle
export from the operator —
how to request access.