2 independent browsers2 non-extractable keysRelay is never the judge
01 / main proof · two browsers
Create once. Continue elsewhere.
Ready to create in Browser A
Choose a real file in Browser A. Its file-bearing Capsule crosses only a direct WebRTC data channel; the relay carries public evidence and connection signals, never the file. Browser B creates recovery copies only after accepting custody.
Browser A · originNo organism yet
Create one state-bearing organism to generate a private 128-bit room link.
Authority boundary: The relay stores and forwards public canonical messages and WebRTC connection signals, but not file bytes. Each browser verifies locally; relay sequence and presence are never a validity verdict. This demo proves two browser contexts, not independent hosts or arbitrary-NAT reachability.
What this proof does—and does not—claim
It proves
Two separate browser contexts use different non-extractable keys to authorize one canonical handoff. A real selected file moves directly, one corrupt recovery copy is rejected, and after A closes B downloads the exact bytes and advances the same identity.
It does not prove
The relay is not an authority, a room link is not authentication, and no finite observation is a globally complete death certificate.
Open advanced evidence and falsification workbench
02 / advanced · falsification workbench
Canonical bytes bind. The kernel decides.
Ready
The primary proof is local and deterministic. An optional model may choose one allowlisted mutation, but never receives a secret or signing capability and never decides validity.
1
Establish a deterministic baseline
Run the committed lifecycle, replay, fork, resurrection, and qualified-mortality fixtures.
Not run
2
Run one bounded falsification
Optional network witness. Complete the anti-abuse check to make one capped API request. The proof does not depend on it.
Loading anti-abuse check…
Waiting for baseline
3
Compare the untrusted proposal with kernel truth
Proposal prediction—
Kernel actual—
Canonical input digest—
No proposal yet.
4
Replay the exact bytes with every network dependency off
No API call. The compiled digest and kernel result must remain identical.
Not run
Proof complete — the kernel stayed authoritative
The static release digest and exact source revision below bind this public artifact to reviewed evidence.
Authority boundary: A curated proposal or GPT‑5.6 may be wrong. Only the actual kernel result is authoritative, and a mismatch is shown rather than repaired or hidden.
02 / advanced · live incubator
Create in this browser
Not created
Each dedicated Worker keeps one private key in memory. The page receives only public keys and signatures; the main-page kernel is the sole verdict authority.
The second signer must be different; all three 2-key combinations are valid.
Pulse Seed v1Pulse count 0
The same canonical state bytes always render the same avatar.
Identity—
Continuation—
Quorum2 of 3
Failure domains1
A
Waiting for creation
B
Waiting for creation
C
Waiting for creation
One-key candidateNot run
The exact pending body is retained when the second signature is added.
Two-key candidateNot run
Acceptance must come from canonical R1 result bytes.
Replay attemptNot run
Reusing accepted evidence must not move the head.
Controlled local authority loss
Terminates the three local signing Workers. This is not an erasure proof or a global death certificate.
Not run
Experimental public evidence
Exact canonical envelope and payload bytes only. No key capability or accepted-context object is serialized.
No bundle yet
Verify on another browser
Import a canonical public bundle. Verification is local and read-only; no signing key is transferred.
Drop evidence hereor choose a JSON fileMaximum 2 MiB · canonical JSON only
No imported proof
Verified proofNo signing authority
Identity
—
Head
—
Sequence
—
Accepted objects
—
Disabled: this browser has public evidence but none of the current private signing keys.
Durable Participant
Optional and consent-gated. Stores one non-extractable browser key, public evidence, and schema metadata in IndexedDB.
Ephemeral mode · nothing stored
Identity
—
Sequence
—
State
—
Stored items
—
Private key bytes are never exported. English/Korean locale remains URL-only and is not stored.
03 / advanced · fixed public reference
One identity, complete custodian turnover
Not run
This is a committed, pre-signed public fixture—not the random organism above. Every experiment starts from raw evidence in a fresh lineage and asks the kernel again. Its mortality card is a closed local experiment whose pending-evidence inventory is explicitly complete; it is not a global death certificate.
A · B · C→B · C · D→C · D · E→D · E · F
Replay, four mutations, signed fork, resurrection, complete-scope conditional mortality, and clone separation will appear here.
04 / advanced · cross-runtime contract
Run the complete committed corpus
A separate Worker runs the named negatives, trust-boundary and mortality-safety probes, and fixed-seed 10,000-case corpus, then compares the whole result with the committed reference. The result reports the committed case counts dynamically.