Skip to content
Swellread

Tamper evidence

Recompute the chain and find the first broken link

Every create, update, decision, ride and delete is appended to a per-entity chain. This page recomputes all of it from the genesis value using the same canonical JSON the writer used, and names the first sequence where the two disagree.

Paste a session id to replay its chain

Every session page links straight to this tool with its id filled in. Open your sessions.

The rule

Exactly what is hashed

seal_n = SHA-384( UTF-8(prevSeal) || canonicalJson(event_n) )

genesis = 000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000

  • The hashed body is exactly six fields: seq, entityType, entityId, action, createdAt and payload.
  • seal and prevSeal are stored beside the body, never inside it, so editing a stored seal cannot be laundered by re-hashing.
  • Canonical JSON sorts object keys recursively and keeps array order, so the same event always produces the same bytes regardless of which client wrote it.
  • Delete keeps a tombstone, which is why a deleted session still replays. The session.delete event is the last link.
Integrity replay · Swellread