Lavisho Trust

Check a proof yourself

Every issue, suspension, reinstatement and revocation is sealed each night into one fingerprint that is timestamped in the Bitcoin blockchain. You don't have to trust us: with the proof file from the verify page you can check it on your own computer. The file contains only fingerprints, no personal data.

Get the proof

On the document's verify page, press “Download proof”. Unzip it: you get one JSON file per event, a .ots file for the day, and a README.

1. Recompute the leaf hash

Open the JSON file. Take the values in “leaf_fields” in the order listed in “leaf_order”, join them with the | character, and compute SHA-256 of that text. The result must equal “leaf_hash”. Any change to the code, event, time, file fingerprint, QR data, key or salt gives a different hash.

printf '%s' 'org_id|code|event|time|file_sha|qr_sha|kid|salt' | sha256sum

2. Hash up the Merkle path to the day root

Start with the leaf hash. For each step in “merkle_path”: if side is R, hash (current + sibling); if side is L, hash (sibling + current), joining the raw 32-byte values. The final value must equal “tree_root”. Then hash (tree_root + previous_root): it must equal “day_root”. Because each day includes the previous day's root, the days form an unbroken chain.

3. Confirm the Bitcoin block

Install the free OpenTimestamps client (pip install opentimestamps-client) and run:

ots verify -d <day_root> <date>.ots

Or drop the .ots file on opentimestamps.org. It names the Bitcoin block that contains the day root; it must match the block shown on the verify page. You can look the block up on any public explorer. opentimestamps.org

For developers

Read-only, no key needed:

GET https://lavishotrust.com/api/public/anchors/<code>
GET https://lavishotrust.com/api/public/proofs/<code>
GET https://lavishotrust.com/api/public/day-roots/<organisation>/<YYYY-MM-DD>

Back to verify