Sunlit Bytes Timestamping Authority
This service issues RFC 3161 timestamp tokens attesting that a given
hash existed no later than the stated time. It is operated by Sunlit Bytes
primarily to timestamp Sunlit Workshop provenance artifacts; the endpoint is
public and free within the posted rate limits.
Policy
- Policy OID:
1.3.6.1.4.1.66538.1.1 (IANA PEN 66538,
ZDN Enterprises). Tokens issued before 2026-08-14 carry the interim OID
2.25.312690151706139119217803799449385446861; both are valid.
- Accepted request digests: SHA-256, SHA-384, SHA-512
(SHA-1 and MD5 are refused with
badAlg).
- Token signature: ECDSA P-256 with SHA-256, chaining to the
Sunlit Bytes Root CA (download).
- Accuracy: genTime is UTC, whole-second precision, claimed
accuracy ±1 second (NTP-disciplined host clock).
- Serial numbers: strictly increasing integers, unique for
the lifetime of the TSA, persisted across restarts.
- Revocation: no CRL/OCSP is published for the signing
certificate. Compromise or misissuance would be disclosed here. Sunlit
Workshop artifacts are additionally timestamped by an independent public TSA
and by OpenTimestamps (Bitcoin), so no single authority — including this one —
must be taken on faith.
- Certificate validity: verifiers should evaluate the
signing certificate at genTime; tokens remain valid after the
certificate expires.
What a token proves
A token proves that Sunlit Bytes attested to a specific hash at a specific
time. It does not prove anything about the truth of a document's contents.
Questions: hello@sunlitbytes.com ·
TSR viewer