Tools
Stamp. Plot. Verify.
Files and location stay on this device. No account. Checking a stamp never touches the network.
Link to an earlier stamp optional
A later stamp names an earlier content id inside the bytes it seals: source → harvest → mill → product. A matching parent shows the named bytes exist. It does not show the claim is true.
Open this page on a phone
Stamp from the device that was at the stump or the mill desk. Same page, no app to install.
…
This device's signing key
Every seal from this browser is signed by a key that never leaves it. Its hash is the record's device id; a reader's roster says whose it is.
See a mill contradiction
Two output lots claim overlapping input from one sealed harvest. The arithmetic runs on this page; the verdict comes from the numbers, not from the button.
Limits of the free page
Loading remaining stamp capacity for this network…
Stamping needs the network once: a public randomness beacon and two free timestamp authorities — and a qualified third where this deployment has contracted one — receive a fingerprint, never the file. Checking a stamp needs nothing. Files up to 8 MB, one at a time, and twelve stamps a day on this browser close their upper edge here.
Past that this page keeps stamping. The stamps come out one-sided: the envelope remains bound to a beacon round, without dating the original content, and only the closing edge is missing. A plan closes it — see the plans and your account.
Agents, ChatGPT and what is honest
Nobody should need ChatGPT in a forest. An agent or a GIS may draft GeoJSON; a person pastes it into the Plot task, sees the ring on the map, and stamps from the phone that was there. ChatGPT is not a GNSS source.
The account page provides API keys for the stamp endpoint. No MCP server is offered here today. GeoLibre is an export picture, not something this page loads.