In our records.
Yenta Girl Canvas Print
You’re viewing the workshop file — not a live check of the object in front of you. Scan the QR or tap the chip on the work to verify.
You can check more strongly. Marks & tags
Match this seal to the piece.
Placement: QC Label, Back Side, Bottom Center.
701085
Missing, lifted, or a different look or number? Write to us before you rely on this work.
Photographs
About this work
Yenta Girl, Printed in Layers
- Made
- 24 Aug 2026
- Kind
- Commission print
- Chip
- NFC · UID ending 2390
- Hologram
- 701085 · QC Label, Back Side, Bottom Center
- Certificate
- Signed and sealed
Made and given its serial
Finished and entered in our workshop records as SW-2026-257068. No other work carries that number.
Certificate sealed
The certificate’s fingerprint was recorded and sealed, and the record it belongs to is filed in the public log below — so neither can be quietly rewritten.
Record published
The record’s fingerprint was written to a public log nobody can edit — entry 2,777,409,373. That shows this exact record existed and was signed by the workshop at that time. It does not by itself prove the physical piece.
Chip paired
An NFC chip on the work was locked to this serial and this page.
Certificate reissued
Public transparency log entry 2,777,325,185
Record updated
Public transparency log entry 2,777,387,763
Certificate reissued
Public transparency log entry 2,777,393,746
Record updated
Public transparency log entry 2,777,409,456
How it has been checked
How this work has been checked, strongest first. Each entry shows that method’s most recent pass.
Live proofs
The chip was present and answered live
Record lookups
Printed mark matched our workshop records
Owner certificate
Published in a public log
On 10 Sept 2026, a fingerprint of this record was written to a public log that nobody can edit or erase — like a notary’s dated stamp anyone can check. It shows this exact file existed and was signed by Sunlit Workshop at that time.
The certificate’s own fingerprint is sealed the same way, so any later edit to it is detectable.
It does not prove the physical piece in your hand. For that, match the seal on the work to the one on this page.
Open the log entryWhat this meansSee how this record reached the log
What is this log?
The log is Sigstore Rekor, an open, append-only ledger run for the software world. Anyone can add an entry; nobody can change one afterwards. Our entry is number 2,777,409,373 — the raw record and the checking commands are under Technical proofs below.
Technical proofs
The record’s fingerprint is filed in a public log as entry 2,777,409,373 on 10 Sept 2026. The certificate PDF carries its own fingerprint and timestamp files below; the log entry is the check that needs no file from us.
These fingerprints belong to the certificate PDF. Anyone can download the files and confirm the certificate is unchanged.
Certificate fingerprint · SHA-256
9cdb923b3f1e9c1c8a4bb36c4a1bfb38747b161f2b433a5caeb6b0b6574d49acThe certificate is also independently timestamped (OpenTimestamps). Anyone can verify the timestamp independently with the standard OpenTimestamps client:ots verify coa.pdf.ots
Convenience checksum · MD5
e23b9a4dcf1a4796a1bed9fe460b6e4dPublic log · Sigstore Rekor entry 2,777,409,373
108e9186e8c5677ad52cf87366442327924a6f12aeec6486ffa4045a08d25a75a53d1d47a392ade6Check offline with rekor-cli and the workshop’s public signing certificate at /trust/doc-signing.pem:rekor-cli verify --artifact provenance.json --signature provenance.json.sig --public-key doc-signing.pem
Who signs what
This work carries two digital certificates. Its identity certificate names the work and signs nothing. Its signing certificate signs the certificate PDF and countersigns the record. Sunlit Workshop signs the record and publishes it to the public log.
Check the countersignature offline with OpenSSL, the record file, and the published Sunlit Bytes roots (roots.pem, from the certificate page). Swap in provenance.json.p7s to check the workshop’s signature the same way:openssl cms -verify -binary -inform DER -content provenance.json -in provenance.json.item.p7s -CAfile roots.pem -purpose any
A digital ID card for this one work, issued by the workshop’s own certificate authority; it names the serial and this page, and signs nothing. It does not prove the physical piece. What this means
