# Verify a block in your browser Igneum's finality is a certificate: miners sign a checkpoint every 30 seconds, and when two thirds of the 30-day mining weight have signed, it is locked. A browser can check that certificate by itself. The site ships the verifier: `site/verify/core.js` does the work, `site/verify/verify.js` fetches the data and calls it. ## Twelve lines ``` ``` ## What is checked, in the tab 1. The header chain from the previous locked checkpoint to this one: each header's hash is recomputed and each links to its parent. 2. The voter table: each voter's key hash, and the weights the bitmap selects. 3. The BLS aggregate signature over the checkpoint message, against the aggregated public keys of the signers, and that the signed weight reaches two thirds of the total. Nothing is trusted from the server but the data itself. Change one bit of the signature, drop one signer from the bitmap, alter a header's nonce, and `verify` says `false` with the reason. The live run of exactly those cases is [igneum.network/verify/test.html](https://igneum.network/verify/test.html). ## The data `GET /api/checkpoint` returns the latest certified checkpoint: the certificate as carried in a block, the voter list with public keys and weights, and the selected-chain headers from the previous lock. `?source=test` returns the finality test network's instead. Libraries, pinned: BLAKE2b from `@noble/hashes` 2.4.0 and BLS12-381 from `@noble/curves` 2.4.0, pure JavaScript. ## From a node The same certificate is in the block that carries it, and `igneum_getProofRecords` returns a block's records. A light client that reads blocks from a node instead of the site's API verifies the same way; `core.js` has no dependency on the site.