Verify a file's provenance

Every GLB AXIS Foundry delivers carries a signed provenance manifest. Drop one here to check it. The first checks run in this browser and the file stays on your machine. Checking the signature means sending the file to the AXIS server, because only the server holds the signing key.

Uploads the file to POST /api/verify. It is checked, not stored.

What the browser check proves

The file is a readable GLB with an AXIS manifest. Each recorded pipeline step's input hash matches the previous step's output hash. If the manifest records a content hash, the file (with the manifest removed) still matches it, so the geometry, textures and scene are unchanged. It does not prove AXIS wrote the manifest: none of these hashes use a key, so anyone could build a manifest that checks out. The step hashes also cover in-between pipeline states that aren't in the file, so they can't be recomputed from it.

What the signature proves

The whole manifest, including the content hash and every step hash, carries a valid HMAC-SHA256 made with the AXIS signing key, so AXIS issued exactly this manifest. Combined with a matching content hash, the file is exactly what AXIS delivered. HMAC uses a shared secret, so only the key holder can check it. That's why this check runs on the AXIS server and never in your browser.

From a terminal

python -m axis_foundry verify model.glb          # offline checks
curl -sS --data-binary @model.glb -H 'Content-Type: model/gltf-binary' \
  https://api.avatar.jonathanarvay.com/api/verify   # signature, checked by the server
© 2026 X AXIS LLC — a Last Man Up Inc. company · Terms · Privacy · Refunds · Site by Jonathan Arvay