Skip to content
Integration guide Mining5 source only Source e0617449

Verify visuals and metadataLink to this section

TL;DRLink to this section

  • DotGrid generates each NFT's image and metadata from fixed visual data, a collection seed and its token ID.
  • Check the renderer, validator and page code; a renderer ID or URL alone is not enough.
  • An API card image is a display format, not proof that the onchain output is correct.

Before you startLink to this section

Verify the collection and its connected contracts, then select one Ethereum block for all code and view reads. Use the independently pinned Solidity 0.8.28 NFT build, not the root contracts' Solidity 0.8.36 build.

Obtain expected hashes from the pinned SqueekGenesisPageIdentity and DotGridRendererRuntime sources or a verified release manifest. A matching hash verifies bytes only if you trust the expected hash.

StepsLink to this section

  1. Read NFT renderer(), art(), artCodehash(), sceneHash(), assetSetHash() and collectionSeed(). art is the existing ABI identifier for the page root; it is not a mutable URL.
  2. Fetch runtime code for the renderer and compare keccak256(code) with the pinned renderer runtime hash. Read pageValidator() and separately compare its runtime hash; the renderer runtime alone does not commit to the validator.
  3. Check rendererId() against the canonical ID and the root runtime hash against artCodehash and the pinned root identity. The root commits to the chunk runtime identities used for strict page reading.
  4. Call validatePage(page) to perform a strict chunk-checked read and full validation. Compare its logical page hash and asset-set hash with the NFT's sceneHash and assetSetHash plus the expected Genesis identities.
  5. Require a nonzero collection seed and an existing NFT ID. Read tokenURI(id) at the same Ethereum block and decode the JSON data URI, then decode its SVG image data URI.
  6. If checking an API card, scope it to the expected release and compare collection/token identity. Rasterization changes the delivery format; verify the onchain SVG independently rather than comparing raster bytes with SVG bytes.

Decode without executing contentLink to this section

This example assumes uri was returned by the verified collection's tokenURI. It parses the embedded data without injecting untrusted SVG into a page.

function decodeBase64DataUri(value: string, prefix: string): string {
  if (!value.startsWith(prefix)) throw new Error("Unexpected data URI");
  return Buffer.from(value.slice(prefix.length), "base64").toString("utf8");
}
const metadata = JSON.parse(decodeBase64DataUri(
  uri, "data:application/json;base64,",
));
if (typeof metadata.image !== "string") throw new Error("Missing SVG image");
const svg = decodeBase64DataUri(metadata.image, "data:image/svg+xml;base64,");
console.log({ name: metadata.name, attributes: metadata.attributes, svg });

Treat decoded SVG as content, not trusted application markup. If presenting it, isolate it using your application's image/content security policy.

Expected resultLink to this section

Identity What it verifies
Renderer runtime hash Exact rendering code
Validator runtime hash Exact page-validation code
Root codehash Root code, including its stored chunk hashes
Page hash (sceneHash) Logical page bytes, not root bytecode
Asset-set hash Renderer ID and logical page identity under the asset-set domain
Collection seed and token ID Inputs that produce the same traits and image on every render

The collection validates these dependencies at construction and checks the root codehash on every tokenURI call. Later renders skip full page validation because the exact page was already validated at construction.

Common failuresLink to this section

  • ArtCodehashMismatch, RendererCodehashMismatch or ValidatorCodehashMismatch indicates an identity mismatch, not a missing media cache.
  • SceneHashMismatch and AssetSetMismatch indicate different logical content or renderer-bound identity.
  • Nonexistent or burned NFTs cannot use collection tokenURI, even though a standalone renderer can derive an image for a valid numeric ID.
  • DotGridInvalid(130) rejects token IDs outside 1..2^192-1; code 131 rejects a zero seed and 132 rejects a pinned codehash mismatch.
  • Confusing SHA-256 file digests with keccak256 EVM code/page hashes causes false comparisons.

Verify the resultLink to this section

Record the contract addresses, block number/hash, renderer and validator code hashes, root hash, logical page hash, asset-set hash, seed and token ID. Render the same verified inputs again and check that the output bytes match.

BatchMetadataUpdate asks clients to refresh metadata; it does not change the fixed renderer or page.

SourceLink to this section

Mining5 source specification e0617449. First-party source is private; see source and release scope.