ARCHIVED V1 — HISTORICAL RECORDS ONLY
This specification describes the former discovery experiment. New generation is closed: POST /api/mine returns HTTP 401 without authentication and HTTP 410 for authenticated requests. Existing records and their deterministic verification rules are retained. The current continuous run has no discovery drop, collectible, NFT or token reward. Read the current run specification.
The canonical discovery record
Only the core payload is hashed. ID, rarity, score, visual seed, server signature and optional transaction receipt sit outside that payload; this avoids a circular definition.
version, minerId, wallet, miningNonce, solanaSlot, network, measurement, entropyCommitment, timestamp, circuitId, qubits, shots, entropy, probabilities
That is the exact property order for qee-discovery-v1. Canonicalization validates the schema, constructs those properties in order, and uses compact JSON.stringify encoded as UTF-8. It is this explicit versioned format, not a claim of generic RFC 8785 canonicalization. Unknown core properties are rejected. Timestamps use ISO UTC with milliseconds; the wallet is a base58 address or null.
probabilities contains 16 measured marginals ordered q0…q15, each a multiple of 1/2,048. These marginals do not sum to one. The verifier checks their range, resolution, and agreement with the stored entropy, plus the measurement’s even parity.
hash = SHA256(UTF8(canonicalPayload)) id = "Q-" + hash.slice(0, 24).toUpperCase() rarity = rarityFromHash(hash) visualSeed = hash serverSignature = Ed25519.sign(UTF8(hash), serverPrivateKey)
Server signature envelope
The envelope contains algorithm: "Ed25519", keyId, a raw 32-byte public key encoded as base64, and a base64 64-byte signature. The signed message is the 64-character lowercase hash encoded as UTF-8, not the raw 32 digest bytes.
A verifier must obtain a trusted public key independently of the submitted record. A mathematically valid signature under a key carried only inside an untrusted record does not establish QEE origin. The deployed key is published by /api/config; independent users can pin it. Trusting the site and its key publication remains part of the security model.
Data availability
The database stores canonical records and optional verified anchor receipts. A Memo transaction stores the hash, not the full payload. Save the exported record if you need independent long-term verification; a public URL depends on database retention and service availability.