Human Origin Label

Public API

Check a creator or a file from your own site, app or platform. Read-only, free, no key, open to other origins (CORS). It returns only what is already public on verification pages.

Endpoints

GET/api/v1/creators/{creator_id}

The status and public record of a creator.

curl https://human-origin-label.lochness-paris.com/api/v1/creators/HO-2026-0001

GET/api/v1/works?sha256={fingerprint}

Every certified work whose original file has this SHA-256 fingerprint. Compute the fingerprint on the user’s device: never upload the file.

sha256sum original-file.png
curl "https://human-origin-label.lochness-paris.com/api/v1/works?sha256=8f7ae72c2bf7e906038ff4b532f2d27d1f68cb429ada547d4a8781309cd02a3b"

Creator response

{
  "api_version": "1",
  "creator": {
    "id": "HO-2026-0001",
    "status": "reviewed",
    "demo": false,
    "name": "Jane Example",
    "disciplines": ["writing"],
    "website": "https://jane-example.com",
    "socials": ["https://www.instagram.com/jane.writes"],
    "scope": "Articles published on jane-example.com/blog",
    "reviewed_on": "2026-09-28",
    "method": "Live video walkthrough",
    "evidence": ["Google Docs version history for three articles"],
    "works": [{"hash": "8f7a…2a3b", "title": "On slow writing", "date": "2026-09-28"}],
    "charter": "1.0",
    "url": "https://human-origin-label.lochness-paris.com/verify/HO-2026-0001"
  }
}
FieldMeaning
statusreviewed or revoked. A revoked record also has revoked_on.
demotrue for fictional demonstration records. Never present them as real.
website, socialsThe only places where this creator may display the badge or watermark.
worksCertified works, identified by the SHA-256 of their original file.
urlThe verification page. Link to it wherever you show a reviewed status.

Errors

HTTPerrorWhen
400invalid_id, invalid_sha256Malformed creator ID or fingerprint
404not_foundNo creator with this ID
405method_not_allowedAnything other than GET (the API is read-only)
429rate_limitedMore than 60 requests per minute from one client

Rules of use

Rate limiting keeps only a salted, daily-rotated hash of the client address, for one minute.