notbefore
Consumer CLI for the public qrng-beacon-log — an hourly, commit-then-reveal, host-attested randomness log
anchored to drand quicknet, RFC 3161 timestamps, Rekor and OpenTimestamps. Spec: NOTBEFORE.md (draft 0.2) in
https://github.com/docdailey/qrng-beacon-log.
What it proves: the 32-byte attested value (V) of hour (N) was fixed before drand round (R) and
not selected after (R) existed. What it does not prove: that the bits are quantum, secret, certified, or
unique. This is not a certification of anything; see CLAIMS.md in the log repository.
pip install notbefore # needs git and openssl on PATH; add [anchors] for OpenTimestamps proofs
notbefore verify 41 # commit 40 + reveal 41: signatures (pinned keys), drand BLS offline, RFC 3161, Rekor anchors
notbefore value 41 # V, only if verify passes
notbefore seed 41 --purpose clinic-qi-roster-2026-09-12 # S = SHA256("notbefore/derive/v1" || V || purpose)
notbefore shuffle 41 --purpose split:iris-csv:v3 rows.txt # deterministic shuffle of the lines of rows.txt
notbefore split 41 --purpose split:iris-csv:v3 --frac 0.8 rows.txt
seed, shuffle and split write a transcript JSON (notbefore-<seq>-<purpose>.json) — the engineering
artifact that lets anyone reproduce the result from the public log.
Trust model. The verifier, the signing keys, the drand group key, the Rekor log key, the freetsa CA and the
expected host configuration are vendored inside this package, pinned at a named commit of the log repository
(notbefore --version prints it). The CLI executes only those files; the log is read as data. Updating the
verifier means updating the package — deliberately.
Eligible pairs start at 0020/0021 (0026/0027 preferred, execution enforced). verify 19 fails by design (ERR-007).
Pulses 0001–0041 carry retroactive anchors (2026-09-12 12:47 UTC); from 0042 anchors are contemporaneous.
MIT. Data in the log: CC BY 4.0.
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file notbefore-0.2.0.tar.gz.
File metadata
- Download URL: notbefore-0.2.0.tar.gz
- Upload date:
- Size: 45.0 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
48fd7dc0b06a6d3d6a6b8782e8cf3079d96213c97bcd8899620b592dc7941ca1
|
|
| MD5 |
f4e6dc5fd38c24f73d8d8b83cda9007f
|
|
| BLAKE2b-256 |
84eb14279727d83597fcc67bddcd2bd68f0c3176650faa0f92c5a353adf586a2
|
Provenance
The following attestation bundles were made for notbefore-0.2.0.tar.gz:
Publisher:
cli.yml on docdailey/qrng-beacon-log
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
notbefore-0.2.0.tar.gz -
Subject digest:
48fd7dc0b06a6d3d6a6b8782e8cf3079d96213c97bcd8899620b592dc7941ca1 - Sigstore transparency entry: 2808171670
- Sigstore integration time:
-
Permalink:
docdailey/qrng-beacon-log@db5c480c28c3efc37c5d42ccc73db17d473e3f41 -
Branch / Tag:
refs/tags/cli-v0.2.0 - Owner: https://github.com/docdailey
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
cli.yml@db5c480c28c3efc37c5d42ccc73db17d473e3f41 -
Trigger Event:
push
-
Statement type:
File details
Details for the file notbefore-0.2.0-py3-none-any.whl.
File metadata
- Download URL: notbefore-0.2.0-py3-none-any.whl
- Upload date:
- Size: 55.0 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
c745f715f5f785b41a573c1c29db968daef6fc956492c5c4bcd2a2e25ae35046
|
|
| MD5 |
cf31a99ea2ec30cdb1715eb293d56178
|
|
| BLAKE2b-256 |
cb127ddceb2e6aee6eff56d866f5baf8daf8d0b55baac09e65df1fdecf4e93a3
|
Provenance
The following attestation bundles were made for notbefore-0.2.0-py3-none-any.whl:
Publisher:
cli.yml on docdailey/qrng-beacon-log
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
notbefore-0.2.0-py3-none-any.whl -
Subject digest:
c745f715f5f785b41a573c1c29db968daef6fc956492c5c4bcd2a2e25ae35046 - Sigstore transparency entry: 2808171861
- Sigstore integration time:
-
Permalink:
docdailey/qrng-beacon-log@db5c480c28c3efc37c5d42ccc73db17d473e3f41 -
Branch / Tag:
refs/tags/cli-v0.2.0 - Owner: https://github.com/docdailey
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
cli.yml@db5c480c28c3efc37c5d42ccc73db17d473e3f41 -
Trigger Event:
push
-
Statement type: