GuideSystem3 min read
The Crucible: checks & permissions
A MarkA file's computed fingerprint, also called a digest or hash. A reader recomputes it to check the bytes.For exampleChanging the sketch's background color changes its Mark. A filename alone would not reveal that change.Full glossary entry → checks which file arrived. The CageThe isolated browser box where creator code runs. The default environment does not give it a wallet or unrestricted network access.For exampleAn animated work can draw inside its box without receiving control of the gallery's wallet.Full glossary entry → limits what the artwork can do when it runs.
Select an underlined word to see what it means.
In this guide
The expected text is background("blue");. Change “blue” to “red” and watch the Mark change.
- Expected Mark
- Computing…
- Received Mark
- Computing…
Checking the text…
A matching fingerprint answers one question.
The CrucibleThe verification layer. Its browser checks compare recovered files with the fingerprints and sizes the work declared.For exampleA changed script fails its check before the default shell opens it.Full glossary entry → compares recovered files with the sizes and MarkA file's computed fingerprint, also called a digest or hash. A reader recomputes it to check the bytes.For exampleChanging the sketch's background color changes its Mark. A filename alone would not reveal that change.Full glossary entry → declared for that work. A PourOne run through the Crucible's checks.For exampleOpening a work triggers a Pour for the resources that presentation needs.Full glossary entry → is one run through those checks. The accepted resources form the HaulThe resources recovered and accepted by those checks.For exampleThe checked sketch, drawing library, and image become the Haul used to open the work.Full glossary entry → used to open the presentation.
CleanThe declared resource checks passed. It is a statement about those checks, not a license, value judgment, or promise of perfect code.For exampleThe received script matches the revision's Mark and length.Full glossary entry → means the declared checks passed. It does not certify authorship, permission to reuse, market value, or that the code has no bugs. Try the fingerprint example above to see the specific question being answered.
The artwork cannot grade itself.
The authentic default ShellThe opening program and interface around creator content. The canonical KEEL verification shell owns the protected checks and K controls.For exampleOpen the K control to inspect the files and checks behind the displayed work.Full glossary entry → owns the checks and K interface. Creator code runs in the CageThe isolated browser box where creator code runs. The default environment does not give it a wallet or unrestricted network access.For exampleAn animated work can draw inside its box without receiving control of the gallery's wallet.Full glossary entry →, a separate restricted browser box. It cannot turn a failed check into a successful one by changing its own screen.
The ShellThe opening program and interface around creator content. The canonical KEEL verification shell owns the protected checks and K controls.For exampleOpen the K control to inspect the files and checks behind the displayed work.Full glossary entry → itself must be the expected version. A website that substitutes its own verifier is making a different trust claim.
Technical detail: sandbox and trust boundary
The protected parent shell verifies the declared resource graph before mounting an opaque child iframe. The extension interface carries bounded read-only data. Sandbox isolation, graph integrity, shell authenticity, provider authenticity, and any external attestation are separate checks. Inspect the exact claim rather than treating a generic verified badge as proof of all of them.
Read the actual verdict and evidence.
KEEL’s vocabulary includes RawA verification verdict meaning this resource has not been tested. It makes no integrity claim.For exampleA file waiting to be checked is Raw. This differs from choosing a raw artifact with no shell.Full glossary entry → (unchecked), CleanThe declared resource checks passed. It is a statement about those checks, not a license, value judgment, or promise of perfect code.For exampleThe received script matches the revision's Mark and length.Full glossary entry → (checks passed), StaleA previously accepted revision has been superseded in the context being inspected.For exampleRevision 1 can still be the correct pinned version for an older Slab even when revision 2 is current.Full glossary entry → (superseded in this context), and SlagThe resource failed verification and was rejected.For exampleA recovered image with different bytes is Slag; do not bypass the check to display it as verified.Full glossary entry → (checks failed). BurnedA record deliberately retired or destroyed through an authorized action, rather than rejected for bad bytes.For exampleRead the exact contract event: a deliberate burn is a different event from a failed verification check.Full glossary entry → records a deliberate authorized action. A raw artifact without a shell is a presentation choice, separate from the RawA verification verdict meaning this resource has not been tested. It makes no integrity claim.For exampleA file waiting to be checked is Raw. This differs from choosing a raw artifact with no shell.Full glossary entry → verdict.
If a file cannot be reached, the reader cannot check it yet. A mismatching MarkA file's computed fingerprint, also called a digest or hash. A reader recomputes it to check the bytes.For exampleChanging the sketch's background color changes its Mark. A filename alone would not reveal that change.Full glossary entry → means a file was recovered but differs from the recorded version. The verdict helps you tell these situations apart.

