Skip to content
Documentation (14 pages)

Verify a Transfer

Every claim Tallow makes about its build is checkable from this page. There are two fingerprints, and they are bound to different things (that is the point).

Build fingerprint — shown while no room is open. It is derived at runtime from the artifact actually served to your browser: /pkg/manifest.json → wasmHash (a SHA-384 SRI digest). Nothing is baked into the page copy — if the manifest cannot be read, the block says unavailable instead of showing a number.

Room-key fingerprint — shown while a room is open. The handshake mints an ephemeral session key; Tallow derives this fingerprint with the protocol’s own BLAKE3 — the first 8 bytes of BLAKE3(session key), printed as four hex groups. Both peers can compare it. When the key is wiped, the block reverts to the build fingerprint: a destroyed key never leaves a stale number on screen.

Reproduce the build fingerprint

Terminal window
# 1. Download the exact WASM your browser loads
curl -fsS -o tallow_web_bg.wasm https://sendtallow.com/pkg/tallow_web_bg.wasm
# 2. The full SRI digest — must equal `wasmHash` in /pkg/manifest.json
openssl dgst -sha384 -binary tallow_web_bg.wasm | openssl base64 -A
# 3. The short fingerprint shown on the home page (first 8 bytes, hex)
openssl dgst -sha384 -binary tallow_web_bg.wasm | head -c 8 | xxd -p -c 8

Step 3 prints the same sixteen hex characters the page displays — the page groups them by four, separated by ·.

Same treatment for the glue JS

Terminal window
curl -fsS -o tallow_web.js https://sendtallow.com/pkg/tallow_web.js
openssl dgst -sha384 -binary tallow_web.js | openssl base64 -A
# must equal `jsHash` in /pkg/manifest.json

The room-key fingerprint cannot be checked from outside — by design

The session key is an ephemeral secret that exists only inside your tab and your peer’s. That is why the fingerprint is derived in the browser, why you compare it across the two devices, and why no terminal recipe can reproduce it from the public artifact. Anyone who could recompute it from public data could also impersonate the session.

In-browser self-test

Visit /selftest.html: the page runs the engine self-test on your own device against the served bytes and reports PASS — engine bytes verified on this device when the WASM matches its SRI digest.