Verify a release
Don't trust the file. Check it.
Drop a Mizani Carbon CSV and your browser recomputes its fingerprint, then checks it against the API's published record and the release's attestation on Base. If anyone changed a single character, it won't verify.
Your file
The file stays in this tab. It's hashed here, and only the release number is sent to the API.
No file to hand?
Result
Checks appear here: the file against the API's published record, then against the attestation on chain.
What the checks mean
- File hash. The SHA-256 of the file's exact bytes, compared with the hash published for the release's CSV download.
- Merkle root. Every row is hashed, and the hashes are combined pairwise up to one root. It changes if any value in any row changes, and it lets a single factor be proven part of a release.
- Attestation. The release's root and file hashes were written to the Ethereum Attestation Service when it was published. The attestation can't be edited or revoked, so a match means the file is what was published then.
The checks run on @mizani/verify, the same open-source (MIT) code as the command-line verifier. The algorithm is in the API docs, with a Python version you can run yourself.