Verification steps

  1. Load ToneThread Root public key…
  2. Verify Tenant Site Certificate signature…
  3. Verify Post Certificate signature…
  4. Recompute ToneHash of post content…
  5. Compare recomputed hash to certificate…

Revision history

Originally published 2026-08-01, updated 2026-08-01; 12 revisions (this active certificate plus 11 prior).

IssuedSupersededContent hash
2026-08-01T08:31:12.085Z 2026-08-01 09:06:42 tth_v1_2d8885e75c6907d5
2026-08-01T09:06:42.359Z 2026-08-01 09:27:11 tth_v1_77fa578a951bad78
2026-08-01T09:27:11.539Z 2026-08-01 09:30:53 tth_v1_4481d17c803166ca
2026-08-01T09:30:53.235Z 2026-08-01 09:30:54 tth_v1_08c77d987b1b9d5f
2026-08-01T09:30:54.222Z 2026-08-01 09:31:28 tth_v1_08c77d987b1b9d5f
2026-08-01T09:31:28.017Z 2026-08-01 09:36:42 tth_v1_08c77d987b1b9d5f
2026-08-01T09:36:42.730Z 2026-08-01 10:21:35 tth_v1_dbfb854579607f2b
2026-08-01T10:21:35.128Z 2026-08-01 10:58:48 tth_v1_5c93332365a6cac2
2026-08-01T10:58:48.217Z 2026-08-01 10:59:57 tth_v1_85e7beb279645610
2026-08-01T10:59:57.970Z 2026-08-01 10:59:58 tth_v1_f98ddd49e31b5a9a
2026-08-01T10:59:59.836Z 2026-08-01 10:59:59 tth_v1_f98ddd49e31b5a9a
2026-08-01T10:59:59.867Z — active — tth_v1_f98ddd49e31b5a9a

What this page exposes

Verification runs on the server. The browser only sees the public summary in the sidebar and the step-by-step ok/fail result above — never the certificate's raw signature, the tenant's raw public key, the ToneHash salt, the per-axis tonal scores, or the compact fingerprint string. Those stay on the signing host.

The public JSON at /tonehash/cert/the-defect-was-in-the-description mirrors the same surface. To independently audit a certificate's raw signed payload you must request an authenticated cert-bundle export from the operator — how to request access.