Documentation (14 pages)
Verify a Transfer
Every claim Tallow makes about its build is checkable from this page. There are two fingerprints, and they are bound to different things (that is the point).
Build fingerprint — shown while no room is open. It is derived at runtime from
the artifact actually served to your browser: /pkg/manifest.json → wasmHash
(a SHA-384 SRI digest). Nothing is baked into the page copy — if the manifest
cannot be read, the block says unavailable instead of showing a number.
Room-key fingerprint — shown while a room is open. The handshake mints an
ephemeral session key; Tallow derives this fingerprint with the protocol’s own
BLAKE3 — the first 8 bytes of BLAKE3(session key), printed as four hex groups.
Both peers can compare it. When the key is wiped, the block reverts to the build
fingerprint: a destroyed key never leaves a stale number on screen.
Reproduce the build fingerprint
# 1. Download the exact WASM your browser loadscurl -fsS -o tallow_web_bg.wasm https://sendtallow.com/pkg/tallow_web_bg.wasm
# 2. The full SRI digest — must equal `wasmHash` in /pkg/manifest.jsonopenssl dgst -sha384 -binary tallow_web_bg.wasm | openssl base64 -A
# 3. The short fingerprint shown on the home page (first 8 bytes, hex)openssl dgst -sha384 -binary tallow_web_bg.wasm | head -c 8 | xxd -p -c 8Step 3 prints the same sixteen hex characters the page displays — the page groups
them by four, separated by ·.
Same treatment for the glue JS
curl -fsS -o tallow_web.js https://sendtallow.com/pkg/tallow_web.jsopenssl dgst -sha384 -binary tallow_web.js | openssl base64 -A# must equal `jsHash` in /pkg/manifest.jsonThe room-key fingerprint cannot be checked from outside — by design
The session key is an ephemeral secret that exists only inside your tab and your peer’s. That is why the fingerprint is derived in the browser, why you compare it across the two devices, and why no terminal recipe can reproduce it from the public artifact. Anyone who could recompute it from public data could also impersonate the session.
In-browser self-test
Visit /selftest.html: the page runs the engine self-test on
your own device against the served bytes and reports PASS — engine bytes verified on this device when the WASM matches its SRI digest.