syntropic Get a free key

Trust

How to verify a dev log

Our dev logs are built so that you, or your agent, don't have to take our word for them.

What's in a dev log

  • Generated from git only. One entry per commit that touched the API's code, with commit date, commit ID, the git tree hash of the API's code at that commit, and the commit message. Nothing is written by hand.
  • Hash chain. Each entry contains prev (the previous entry's hash) and hash = sha256(canonical JSON of n, date, commit, tree, message, prev). Canonical JSON means sorted keys, no whitespace, UTF-8. Changing or inserting any past entry changes every later hash.
  • Signature. head.signature is an Ed25519 signature over the 32 raw bytes of the newest hash, made with the Syntropic dev log key.
  • Timestamps. Every new chain head is timestamped with OpenTimestamps and anchored in the Bitcoin blockchain. The stamped file is the head hash as 64 hex characters. A timestamp proves the whole chain up to that entry existed at that time, so entries cannot be backdated later.

The public key

It is published in two independent places, which must match the public_key in every dev log:

v=SYNDEVLOG1; k=ed25519; p=Hug9+yADw7A8l6U/ZYcuhqJGXMmi29Pp8CT1lpPNFAo=

Verify in one command

pip install cryptography opentimestamps
curl -sO https://syntropicapi.com/devlog/verify_devlog.py
python verify_devlog.py https://syntropicapi.com/apis/<api>/devlog.json

The script is short and readable; please read it. It recomputes the chain, checks the key against DNS (via DNS-over-HTTPS) and the well-known file, and verifies the signature. For every timestamp it checks that the proof commits to the chain hash and that its Bitcoin attestation equals the merkle root of the stated block, fetched from a public block explorer. No Bitcoin node is needed. You can also check a proof at opentimestamps.org, using the <hash>.txt and <hash>.txt.ots files.

What it does and doesn't prove

It proves the history is ours, unaltered, and existed at the stated times. It does not prove anything about the quality of each change: for that, read the changes and the API's docs. Timestamping started when dev logs launched; entries from before then are proven to exist as of the first timestamp.