Public API
Check a creator or a file from your own site, app or platform. Read-only, free, no key, open to other origins (CORS). It returns only what is already public on verification pages.
Endpoints
GET/api/v1/creators/{creator_id}
The status and public record of a creator.
curl https://human-origin-label.lochness-paris.com/api/v1/creators/HO-2026-0001
GET/api/v1/works?sha256={fingerprint}
Every certified work whose original file has this SHA-256 fingerprint. Compute the fingerprint on the user’s device: never upload the file.
sha256sum original-file.png
curl "https://human-origin-label.lochness-paris.com/api/v1/works?sha256=8f7ae72c2bf7e906038ff4b532f2d27d1f68cb429ada547d4a8781309cd02a3b"
Creator response
{
"api_version": "1",
"creator": {
"id": "HO-2026-0001",
"status": "reviewed",
"demo": false,
"name": "Jane Example",
"disciplines": ["writing"],
"website": "https://jane-example.com",
"socials": ["https://www.instagram.com/jane.writes"],
"scope": "Articles published on jane-example.com/blog",
"reviewed_on": "2026-09-28",
"method": "Live video walkthrough",
"evidence": ["Google Docs version history for three articles"],
"works": [{"hash": "8f7a…2a3b", "title": "On slow writing", "date": "2026-09-28"}],
"charter": "1.0",
"url": "https://human-origin-label.lochness-paris.com/verify/HO-2026-0001"
}
}
| Field | Meaning |
|---|---|
status | reviewed or revoked. A revoked record also has revoked_on. |
demo | true for fictional demonstration records. Never present them as real. |
website, socials | The only places where this creator may display the badge or watermark. |
works | Certified works, identified by the SHA-256 of their original file. |
url | The verification page. Link to it wherever you show a reviewed status. |
Errors
| HTTP | error | When |
|---|---|---|
| 400 | invalid_id, invalid_sha256 | Malformed creator ID or fingerprint |
| 404 | not_found | No creator with this ID |
| 405 | method_not_allowed | Anything other than GET (the API is read-only) |
| 429 | rate_limited | More than 60 requests per minute from one client |
Rules of use
- Show the status at display time. Responses may be cached for up to 5 minutes, never more than one hour, so that revocations propagate.
- Never show a self-declared or demo record as reviewed, and link to the verification page wherever you show a reviewed status.
- Compute fingerprints on the user’s device. Never upload users’ files to check them.
- Integrations that follow these rules are conforming integrations, as defined in Section 13 of the specification.
Rate limiting keeps only a salted, daily-rotated hash of the client address, for one minute.