Drop the generator, the release checksums, any official PDF, the Complete Package ZIP, or either defensive publication to verify, in your browser, that the file matches the version published by Https Card — Internet Identity Card Ltd. Verification runs entirely on your device using the W3C Web Crypto API. Nothing is uploaded.
Drop any published IIC file below. Verification runs entirely on your device — nothing is uploaded.
Every file listed in the manifest below can be checked here, including
the generator, the Wallet viewer and its service worker, and the
SHA256SUMS files. Verification is by content: a file
renamed by your browser still verifies.
These are the cryptographic fingerprints of the published IIC releases. Compare locally-computed hashes against these values. The v9.0 entries are retained: a file issued under that release remains verifiable here.
This covers the eleven-file release package. The seventeen-file Complete Package has its own manifest and its own anchor, in section 1 below.
This is the digest committed to
Bitcoin and Ethereum for v10.0.1. It is the digest of SHA256SUMS, not of
any archive: a ZIP embeds timestamps and compression choices that differ between
runs, so its digest cannot be reproduced and proves nothing about the contents.
Verify the package with shasum -c SHA256SUMS, then check this value. Anchored on Bitcoin at block 961512 (8 Aug 2026, 00:36:47 UTC) and on Ethereum at block 25704773 (7 Aug 2026, 18:06:47 UTC). The Ethereum leg precedes the Bitcoin leg by six hours; the two chains are batched independently and that ordering is normal. The v10.0 release package was anchored a day earlier, at Bitcoin block 961351 and Ethereum block 25701188. Times are block times in UTC, read from the explorers; OriginStamp certificates render them in local time.
Not downloadable from this site. The generator is supplied under controlled onboarding; this fingerprint lets a recipient confirm the file they hold is the published build. A modified copy no longer matches it and cannot be verified by anyone.
Retained: a card issued by this build remains verifiable, and the fingerprint remains evidence of what was published.
Two different claims, deliberately
separated. The manifest digest is anchored on both chains and each of the seventeen files is
verifiable against it with shasum -c SHA256SUMS. The archive digest is not
anchored and never will be: a ZIP embeds timestamps and compression choices that vary
between runs, so it cannot be reproduced. It is published for one purpose only — to
confirm that a copy received through onboarding arrived without corruption.
Neither file is downloadable from this site. The Complete Package contains the generator, which is not publicly distributed. The v9.0 archive was withdrawn for the same reason; its digest remains in the anchor timeline below, where it documents a historic state without inviting a download.
Files inside the Complete Package are individually listed in its SHA256SUMS file; the generator file is internet-identity-card-v9.html, SHA-256 17aea67549cdf0214c04e9c89b0849efe08e74d3632efe2bc78d32fbe93f5bfc.
Used to verify the ECDSA signature of the Complete Package ZIP.
Prefer the command line? Compute the SHA-256 of the file you downloaded and compare with the published hash above.
# Holding the Complete Package: verify all seventeen files at once, # then check the manifest against the anchored digest in section 1. shasum -c SHA256SUMS shasum -a 256 SHA256SUMS # Any single published file: shasum -a 256 internet-identity-card-v10.0.1.html shasum -a 256 IIC-User-Guide-v10.0.pdf shasum -a 256 IIC-Technical-Specification-v10.0.pdf shasum -a 256 IIC-Engineering-Specification-v10.0.pdf shasum -a 256 IIC-Threat-Model-v10.0.pdf shasum -a 256 IIC-Wallet-User-Guide-v1.0-r5.pdf shasum -a 256 IIC-Defensive-Publication-MultiZone-v2.pdf shasum -a 256 IIC-Defensive-Publication-StapledFreshness.pdf
Get-FileHash SHA256SUMS -Algorithm SHA256 Get-FileHash internet-identity-card-v10.0.1.html -Algorithm SHA256 Get-FileHash IIC-User-Guide-v10.0.pdf -Algorithm SHA256 Get-FileHash IIC-Technical-Specification-v10.0.pdf -Algorithm SHA256 Get-FileHash IIC-Engineering-Specification-v10.0.pdf -Algorithm SHA256 Get-FileHash IIC-Threat-Model-v10.0.pdf -Algorithm SHA256 Get-FileHash IIC-Wallet-User-Guide-v1.0-r5.pdf -Algorithm SHA256 Get-FileHash IIC-Defensive-Publication-MultiZone-v2.pdf -Algorithm SHA256 Get-FileHash IIC-Defensive-Publication-StapledFreshness.pdf -Algorithm SHA256
PowerShell has no equivalent of
shasum -c. On Windows, check the manifest digest above, then compare each
file individually against the values in section 1.
If the computed hash exactly matches the published value above, the file is bit-for-bit identical to the published release (integrity verified).
A successful match between your locally-computed SHA-256 hash and the published value provides:
For the Complete Package ZIP, an additional ECDSA P-256 signature can be verified against the published public key. The signature provides cryptographic evidence that the release was issued by the holder of the corresponding private key, assuming the public key has been obtained from a trusted source.
Every release is anchored on the Bitcoin and Ethereum blockchains via OriginStamp, and additionally on Bitcoin via OpenTimestamps. Anchors are cumulative: superseding a release never removes the proof that its predecessor existed. The complete chronology:
SHA256SUMS 2980397441afd0fe9c6fb3746b4197ceb074318d5381129a7803a004f95086b5SHA256SUMS 265e7eafa6ecff90cd2d3e878bd57efd10c225eacd8014a9febc504ca625a67bSITE-SHA256SUMS 818ceb7f4e9d2528b0e7e35453749ef7c118665a10334ccce6ab23e9d6f513b5SITE-SHA256SUMS.SHA256SUMS ae6dfef06058e9e32427f6ba256bf96ba9fd40476a264dc3d074ac6d5d2799baThe cryptographic architecture verified here is disclosed as open prior art on Technical Disclosure Commons, released under the Creative Commons Attribution 4.0 license:
This verification confirms file integrity only. It does not constitute legal recognition, certification, accreditation, or endorsement by any authority. Internet Identity Card ™ is a private software-based identity and verification platform developed by Https Card — Internet Identity Card Ltd. References to electronic signatures, eIDAS, or regulatory frameworks are informational only.
In addition to file verification, you can verify the SHA-256 integrity of every HTML page on this site in real time — directly in your browser, using the W3C Web Crypto API. Nothing is uploaded.