Verification steps
- Load ToneThread Root public key…
- Verify Tenant Site Certificate signature…
- Verify Post Certificate signature…
- Recompute ToneHash of post content…
- Compare recomputed hash to certificate…
Revision history
Originally published 2026-08-02, updated 2026-08-12; 9 revisions (this active certificate plus 8 prior).
| Issued | Superseded | Content hash |
|---|---|---|
| 2026-08-02T14:12:56.246Z | 2026-08-02 14:14:52 | tth_v1_880128435beb32e9 |
| 2026-08-02T14:14:52.258Z | 2026-08-02 18:44:50 | tth_v1_1f35e11932c6fa4d |
| 2026-08-02T18:44:50.557Z | 2026-08-02 18:46:17 | tth_v1_928bb3ca17aea508 |
| 2026-08-02T18:46:17.104Z | 2026-08-12 18:19:19 | tth_v1_032f9c86690bc7c5 |
| 2026-08-12T18:19:19.441Z | 2026-08-12 18:21:59 | tth_v1_ddb88edca3d95a73 |
| 2026-08-12T18:21:59.359Z | 2026-08-12 18:30:27 | tth_v1_28a5fc6a6e48ad25 |
| 2026-08-12T18:30:27.421Z | 2026-08-12 18:36:12 | tth_v1_3b21bf582938cabd |
| 2026-08-12T18:36:12.958Z | 2026-08-12 18:46:24 | tth_v1_3b21bf582938cabd |
| 2026-08-12T18:46:24.655Z | — active — | tth_v1_3b21bf582938cabd |
What this page exposes
Verification runs on the server. The browser only sees the public summary in the sidebar and the step-by-step ok/fail result above — never the certificate's raw signature, the tenant's raw public key, the ToneHash salt, the per-axis tonal scores, or the compact fingerprint string. Those stay on the signing host.
The public JSON at
/tonehash/cert/the-defect-was-in-the-description mirrors the
same surface. To independently audit a certificate's raw
signed payload you must request an authenticated cert-bundle
export from the operator —
how to request access.