A consistent outcome
A Pact moving from sequence 7 to sequence 8, with a matching DPC1 anchor. Every check this tool can perform passes.
Interactive · client-side only
A recorded outcome claims that a Pact moved from one state to the next. This tool checks that the claim holds together: same Pact, sequence advanced by one, roots that line up, and a successor that commits to this exact transition and no other.
One static JavaScript file, no network calls, no storage. Nothing you paste is transmitted, logged or cached anywhere, including on the server hosting this page. Read the source. It works offline once the page is saved.
This tool needs JavaScript. The rules it applies are written out as P-1 through P-9 on the Drop Pacts page, and the same worked cases appear with expected results under Pact test vectors. Nothing here is available only through the tool.
Both samples are real records built with the same encoding the reference implementation uses. The commitment is recomputed in your browser from the preimage you load, so the pass and the failure are both genuine.
A Pact moving from sequence 7 to sequence 8, with a matching DPC1 anchor. Every check this tool can perform passes.
The same records with one byte changed in the successor cell descriptor. Rule P-7 fails while P-9 still passes, so the tool points at the altered record rather than at the stated terms.
This tool runs five of the nine outcome rules. It says so in its own output, every time, rather than presenting a partial check as a complete one.
| Rule | Checked here | Why |
|---|---|---|
| P-1 Pact ids agree | yes | All three records carry it. |
| P-2 Sequence advances by one | yes | Both descriptors carry a sequence. |
| P-3 Roots line up | yes | State and policy roots are in the records. |
| P-4 Ruleset result equals the next state root | no | Needs the deterministic CBOR proof pack, which is off-chain material rather than a record. |
| P-5 OP_DROP effect hash matches its payload | no | |
| P-6 Proof pack payload hash matches | no | |
| P-7 Successor commits to this transition | yes | Recomputed from the preimage with a BIP 340 tagged hash. |
| P-8 Successor proves its Taproot commitment | no | Needs the control block, the successor output script, and secp256k1 point arithmetic. |
| P-9 DPC1 anchor carries the same commitment | yes | Checked when you supply the anchor script. |
Every rule here asks the same kind of question: do these records agree with each other? None of them can tell you that money moved, that goods arrived, or that a party did what they said they would. What Bitcoin itself guarantees for a given Pact is written in its enforcement floor, and for a recorded floor the honest answer is: that these terms were committed and not edited afterwards.
tag = SHA256("Drops/PactTransition")
commitment = SHA256(tag || tag || preimage)
That is the BIP 340 tagged-hash construction. The successor cell descriptor carries the result in its last 32 bytes, and the DPC1 anchor carries it in its last 32 bytes. Both must equal the value computed from the preimage, which is why changing a single byte anywhere in the stated terms breaks the outcome.