Verification without installing anything

Verify the manifest.

This site's PROVENANCE.json lists every file with its SHA-256 hash. Verify it here in your browser: nothing is uploaded, nothing is installed.

If you downloaded this site (the public ZIP), this page verifies two things against the manifest:

  1. The manifest was not altered: the hash of PROVENANCE.json must match the published fingerprint (sealed declaration + layer-1 card).
  2. The files were not altered: the hash of each file listed in the manifest must match the recorded one.

Honest scope: this verifies that the files match the manifest. It does not verify Bitcoin anchoring (that needs ots verify), and it does not prove who wrote the content — only that the package is intact.

Step 1 — Drop the PROVENANCE.json

Drag the PROVENANCE.json file from the package you downloaded into here.

Drop PROVENANCE.json here

Step 2 — Drop the site files

Drag all the package files (the same ones the manifest lists). Each file is re-hashed in your browser and compared against the recorded hash.

Drop the site files here

No computer handy

If you prefer the classic route: the manifest fingerprint is published on the method page and on the sealed declaration card. Compare hashes by hand or with sha256sum.