Metadata hash
The timing fingerprint, a SHA-256 hash (prefix 0x12) over the small system-generated record naming the witnesses an item was submitted after, committing to the submitted-after edge without touching user data; a bundle carries the record itself, so the hash is recomputed, never trusted.
Overview
The metadata hash, in prose the timing fingerprint, is one of the two independent
fingerprints described in
the item’s composite fingerprint: a SHA-256 hash under
byte prefix 0x12, computed over a small system-generated
record canonicalized with JCS. That record
holds one thing, a map of the witnesses the item was submitted
after: the hash of the block at the head of Truestamp’s chain at that
moment, plus the hash of the newest captured observation from each entropy source that had
one. Hashing it commits to the submitted-after edge of the
submission window without touching your data, and fixes
the choice of witnesses permanently, since the hash cannot change afterwards. Together with
the claims hash it is bound into the composite
item hash.
Blocks and entropy observations carry metadata hashes of their own under their own byte prefixes, computed the same way over their own metadata maps.
A proof bundle never carries a metadata hash. It carries the metadata maps themselves, for the subject and for every block it names, so a verifier recomputes each metadata hash from bytes it can read rather than accepting an opaque value on trust. The field layout is in the proof bundle wire format.