Public trust registry
Every TraceHumanity certificate is digitally signed, like a notary stamping a document. These are the keys we sign with, published so you can check any certificate without trusting us.
Why the keys are public
Anyone can use these keys to confirm a certificate is genuine, without trusting our website, our servers or our staff.
What a valid signature proves
The certificate is genuine: issued by TraceHumanity, for the specific work and creator named, on the date shown. It has not been forged or altered since it was issued.
What it doesn’t prove
Whether the work itself is human-made. That assessment is the job of the certificate’s verification level, based on the evidence reviewed at certification. A signature only proves the certificate exists in the form we issued it.
Active signing keys
Each entry is one cryptographic identity authorised to issue TraceHumanity certificates. Most of the time there is a single primary key; more appear here when keys are rotated or delegated to partner institutions.
| Key ID | Issuer | Algorithm | Status | Trust level | Created |
|---|---|---|---|---|---|
| tracehumanity-primary | TraceHumanity Certification Authority | ECDSA P-256 | Active | 5 | 21 May 2026 |
Public key for tracehumanity-primary (ECDSA P-256, SPKI / PEM)
-----BEGIN PUBLIC KEY----- MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEnkwA781EOgzh23hbU1QklRJRbvFG tpLEYfmvUqlK+WNjYhReAjE84aBqkLzIOYfMI14sGWCX5iNVI50Hg/jqfA== -----END PUBLIC KEY-----
Verify a signature yourself
If you’re auditing a certificate or building a verification tool, this is exactly how the signatures are constructed. You only need standard cryptography libraries, with no TraceHumanity-specific dependencies.
Reconstruct the signed payload
Join these fields with the literal
|character.{certificateNumber}|{assetHash}|{level}|{ownerId}|{issuedAt}- certificateNumber
- The certificate number, e.g.
TH-2026-001002 - assetHash
- SHA-256 of the original (pre-watermark) file, lowercase hex
- level
- The verification level, e.g.
LEVEL_3 - ownerId
- The creator’s UUID
- issuedAt
- ISO-8601 timestamp normalised through
new Date(x).toISOString()(millisecond UTC, e.g.2026-05-22T23:39:26.571Z)
Verify with ECDSA P-256 and SHA-256
The signature is hex-encoded DER. Use any standard ECDSA library and a public key from the registry above.
import { createVerify, createPublicKey } from 'crypto' const payload = [ cert.certificate_number, cert.asset.file_hash, cert.level, cert.owner_id, new Date(cert.issued_at).toISOString(), ].join('|') const v = createVerify('SHA256') v.update(payload, 'utf8') const ok = v.verify(createPublicKey(publicKeyPem), cert.signature, 'hex')
The same data as JSON
If you’re writing software that verifies certificates automatically, such as a browser extension, a content-management plugin or a museum’s provenance database, fetch the same keys and payload schema as machine-readable JSON. No authentication is required. Treat it as a public ledger.
GET /api/trust-registry (opens in a new tab)