Trust
How to verify a dev log
Our dev logs are built so that you, or your agent, don't have to take our word for them.
What's in a dev log
- Generated from git only. One entry per commit that touched the API's code, with commit date, commit ID, the git tree hash of the API's code at that commit, and the commit message. Nothing is written by hand.
- Hash chain. Each entry contains
prev(the previous entry's hash) andhash = sha256(canonical JSON of n, date, commit, tree, message, prev). Canonical JSON means sorted keys, no whitespace, UTF-8. Changing or inserting any past entry changes every later hash. - Signature.
head.signatureis an Ed25519 signature over the 32 raw bytes of the newest hash, made with the Syntropic dev log key. - Timestamps. Every new chain head is timestamped with OpenTimestamps and anchored in the Bitcoin blockchain. The stamped file is the head hash as 64 hex characters. A timestamp proves the whole chain up to that entry existed at that time, so entries cannot be backdated later.
The public key
It is published in two independent places, which must match the public_key in every dev log:
- DNS:
TXT _devlog.syntropicapi.com - /.well-known/syntropic-devlog-key.txt
v=SYNDEVLOG1; k=ed25519; p=Hug9+yADw7A8l6U/ZYcuhqJGXMmi29Pp8CT1lpPNFAo=
Verify in one command
pip install cryptography opentimestamps
curl -sO https://syntropicapi.com/devlog/verify_devlog.py
python verify_devlog.py https://syntropicapi.com/apis/<api>/devlog.json
The script is short and readable; please read it. It recomputes the chain, checks the key against DNS (via DNS-over-HTTPS) and the well-known file, and verifies the signature. For every timestamp it checks that the proof commits to the chain hash and that its Bitcoin attestation equals the merkle root of the stated block, fetched from a public block explorer. No Bitcoin node is needed. You can also check a proof at opentimestamps.org, using the <hash>.txt and <hash>.txt.ots files.
What it does and doesn't prove
It proves the history is ours, unaltered, and existed at the stated times. It does not prove anything about the quality of each change: for that, read the changes and the API's docs. Timestamping started when dev logs launched; entries from before then are proven to exist as of the first timestamp.