Verify a chain head independently

The hash chain on a proof room shows that recorded rows were not altered after they were written. External anchoring publishes those chain heads somewhere Proofroom does not solely control, so a rewrite of the whole history would have to also rewrite the public anchor and its timestamp.

What you need

  1. The proof room URL (and its public id, which is the room slug).
  2. The public anchors repository: https://github.com/Proofroom/proofroom-anchors
  3. Optional: the OpenTimestamps .ots proof next to that day's manifest.

Steps

  1. Open the live proof room and note the latest event hash (chain head) and sequence number from a receipt or the chain integrity panel.
  2. Compute SHA-256(public id) where the public id is the room slug. Private and unclaimed rooms never appear by slug in the public file; you still find your entry by matching this subject hash.
  3. Open anchors/YYYY/MM/DD.json (or anchors/latest.json) in the anchors repo. Find the entry whose subject equals your hash. Confirm head_hash and head_seq match the room.
  4. Confirm the git commit timestamp on that file. That is the earliest moment a third party can attest the head existed.
  5. Optional: download the sibling .ots file and verify it with OpenTimestamps tooling against the manifest Merkle root.

Worked example: Ops room

Live room: /trust/proofroom-ops

Public id (slug)
proofroom-ops
Subject (SHA-256 of slug)
deb5126a3313af51b9c595343a781df9e91f70cadfcfc8996ad0fb958e640a1d
Current chain head
seq 14983 · b53ddcc98709c6faa16b2a50c12526dacbf200bb045050eaa730515d816e2188

Look up subject deb5126a3313af51… in the latest anchor manifest. Public rooms also list the slug in plain text for convenience.

Latest external anchor

2026-09-30 02:02:20 UTC · status timestamped · 12 entries

Open anchor file · OpenTimestamps proof

merkle 98125c0a06fa3a943a7de9687a39f6d00dc718e2261abc2c5268667317e7d46a · commit 47b7fb82751d

Verify a signed receipt offline

Each new Action Receipt carries an Ed25519 signature over its structural fields. You can check it without calling the Proofroom API.

  1. Copy the receipt JSON (receipt id, use case public id, event type, authority status, evidence level, approval status, timestamp, event hash, config fingerprint, signature, key id) from the receipt page or an Evidence Pack export.
  2. Fetch the public key document from /.well-known/proofroom-signing-key.json or from keys/proofroom-signing-key.json in the anchors repository. Match the key id.
  3. Run the standalone script in the anchors repository: node scripts/verify-receipt.mjs receipt.json key.json. It performs no network call.

A signature proves this receipt was issued by Proofroom and has not been altered since. It does not evidence that the underlying action occurred.

Honest limitation

External anchoring proves this chain head existed at the anchor time. It bounds any retrospective alteration to the period since the last anchor. It does not prove that events recorded before an anchor were genuine at the moment they were reported.

We never rewrite evidence. Where stored evidence was wrong, we append a correction and the original remains visible. A chain may therefore show a permanent, explained discontinuity. We regard that as more credible than a chain that appears to heal.