Public trust registry

Every TraceHumanity certificate is digitally signed, like a notary stamping a document. These are the keys we sign with, published so you can check any certificate without trusting us.

Why the keys are public

Anyone can use these keys to confirm a certificate is genuine, without trusting our website, our servers or our staff.

  • What a valid signature proves

    The certificate is genuine: issued by TraceHumanity, for the specific work and creator named, on the date shown. It has not been forged or altered since it was issued.

  • What it doesn’t prove

    Whether the work itself is human-made. That assessment is the job of the certificate’s verification level, based on the evidence reviewed at certification. A signature only proves the certificate exists in the form we issued it.

Active signing keys

Each entry is one cryptographic identity authorised to issue TraceHumanity certificates. Most of the time there is a single primary key; more appear here when keys are rotated or delegated to partner institutions.

Key IDIssuerAlgorithmStatusTrust levelCreated
tracehumanity-primaryTraceHumanity Certification AuthorityECDSA P-256Active521 May 2026

Public key for tracehumanity-primary (ECDSA P-256, SPKI / PEM)

-----BEGIN PUBLIC KEY-----
MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEnkwA781EOgzh23hbU1QklRJRbvFG
tpLEYfmvUqlK+WNjYhReAjE84aBqkLzIOYfMI14sGWCX5iNVI50Hg/jqfA==
-----END PUBLIC KEY-----

Verify a signature yourself

If you’re auditing a certificate or building a verification tool, this is exactly how the signatures are constructed. You only need standard cryptography libraries, with no TraceHumanity-specific dependencies.

  1. Reconstruct the signed payload

    Join these fields with the literal | character.

    {certificateNumber}|{assetHash}|{level}|{ownerId}|{issuedAt}
    certificateNumber
    The certificate number, e.g. TH-2026-001002
    assetHash
    SHA-256 of the original (pre-watermark) file, lowercase hex
    level
    The verification level, e.g. LEVEL_3
    ownerId
    The creator’s UUID
    issuedAt
    ISO-8601 timestamp normalised through new Date(x).toISOString() (millisecond UTC, e.g. 2026-05-22T23:39:26.571Z)
  2. Verify with ECDSA P-256 and SHA-256

    The signature is hex-encoded DER. Use any standard ECDSA library and a public key from the registry above.

    import { createVerify, createPublicKey } from 'crypto'
    
    const payload = [
      cert.certificate_number,
      cert.asset.file_hash,
      cert.level,
      cert.owner_id,
      new Date(cert.issued_at).toISOString(),
    ].join('|')
    
    const v = createVerify('SHA256')
    v.update(payload, 'utf8')
    const ok = v.verify(createPublicKey(publicKeyPem), cert.signature, 'hex')

The same data as JSON

If you’re writing software that verifies certificates automatically, such as a browser extension, a content-management plugin or a museum’s provenance database, fetch the same keys and payload schema as machine-readable JSON. No authentication is required. Treat it as a public ledger.

GET /api/trust-registry (opens in a new tab)