Every change, signed.

Each passport change becomes a signed block linked to the one before it. Save today’s NDJSON and diff it against tomorrow’s; honest updates only append lines.

ChainVerified1 signed block
AdaptermockchainSHA-256 · Ed25519
Heade0f2787d29af…b69b08ffBlock 1

Ledger blocks

diff -u saved.ndjson latest.ndjson
BlockPassportEventStatusRecordedDocumentHash
#1SB-VA97R3-9issuedactive20/07/2026, 12:43:49826e6516518c…80781113e0f2787d29af…b69b08ff

Copies make rewriting visible.

Every block is issuer-signed, commits to the private document snapshot, and links to the prior hash. Keep an older file to detect edits, removals, reordering, or a changed signing key. Sunbeam still hosts the current copy; it is auditable, not immutable.

npm run ledger:verify -- ./sunbeam-passport-ledger.ndjson

Holder names, account IDs, stamp titles and notes are not published. Their canonical snapshot is represented only by its SHA-256 commitment.