Verification steps
- Load ToneThread Root public key…
- Verify Tenant Site Certificate signature…
- Verify Post Certificate signature…
- Recompute ToneHash of post content…
- Compare recomputed hash to certificate…
Revision history
Originally published 2026-09-14, updated 2026-09-14; 7 revisions (this active certificate plus 6 prior).
| Issued | Superseded | Content hash |
|---|---|---|
| 2026-09-14T03:15:22.335Z | 2026-09-14 03:16:24 | tth_v1_26cd85032d68597b |
| 2026-09-14T03:16:24.565Z | 2026-09-14 03:20:59 | tth_v1_26cd85032d68597b |
| 2026-09-14T03:20:59.588Z | 2026-09-14 03:23:04 | tth_v1_1967e4e93c81d3c9 |
| 2026-09-14T03:23:04.988Z | 2026-09-14 05:01:30 | tth_v1_d2ceef7eb17d09ba |
| 2026-09-14T05:01:30.383Z | 2026-09-14 05:45:42 | tth_v1_a96c8ce5e6117d91 |
| 2026-09-14T05:45:42.928Z | 2026-09-14 06:09:07 | tth_v1_bf4c96ff9099b2fd |
| 2026-09-14T06:09:07.813Z | — active — | tth_v1_bf4c96ff9099b2fd |
What this page exposes
Verification runs on the server. The browser only sees the public summary in the sidebar and the step-by-step ok/fail result above — never the certificate's raw signature, the tenant's raw public key, the ToneHash salt, the per-axis tonal scores, or the compact fingerprint string. Those stay on the signing host.
The public JSON at
/tonehash/cert/virtual-tattoos mirrors the
same surface. To independently audit a certificate's raw
signed payload you must request an authenticated cert-bundle
export from the operator —
how to request access.