OpenChainGraph · Explainer One file and six steps

The catalog file behind the suite

Every compute node and every ordered workflow in this estate is indexed by one JSON file. This page walks through what chaingraph.json contains, how the per-node shard files on disk become that one file, where copies of it live, and how you can verify a downloaded copy with two public checks. Every number and hash on this page was measured on 3 October 2026 against the live site and the repository at commit e6ca04443.

Presenter mode shows one step per screen. Arrow keys move, A toggles autoplay, Esc exits.
Nothing on this page asks you to take the file on faith. Download it, hash it, compare the hash with the published checksum list, and check that list against the Sigstore attestation GitHub recorded when the deploy ran.
Part one · What the file is

The catalog and the shards it comes from

Three steps: what the catalog holds, which source files the assembler reads, and which workflow is allowed to write the result.

1
Step 1 · The catalog

One file that indexes every node and workflow

chaingraph.json is the machine-readable index of the whole graph: every compute node, every ordered workflow, and the edges that record which node feeds which. The OpenChainGraph standard expresses it as a W3C DCAT 3.0 catalog in JSON-LD, published under a CC BY 4.0 license (SPEC.md §7).

an agent asks chaingraph.jsondcat:Catalog · JSON-LD · CC BY 4.0 669 nodes 374 workflows measured 3 October 2026

On 3 October 2026 the catalog held 669 nodes and 374 workflows, and the served file was 3,737,587 bytes. The shape is a common one among registries: ethereum-lists/chains assembles one chains.json from per-chain source files, and a dbt project publishes a generated manifest.json whose artifacts each carry a schema-version URL.

SPEC.md §7 DCAT 3.0 Graph Indexainumbers.co/chaingraph/chaingraph.json
Who asks at this stepagents welcome
Fetch https://ainumbers.co/chaingraph/chaingraph.json and list every workflow whose steps include node art-129-webbotauth-signature-verifier.
2
Step 2 · Shards

One shard per node and per workflow

Nobody edits chaingraph.json by hand. The file is assembled from source shards: one JSON file per node under chaingraph/graph/nodes/, one per workflow under chaingraph/graph/chains/, and a chaingraph.meta.json header that lists the shards each build includes. The assembler is node scripts/assemble-chaingraph.mjs.

graph/nodes/ · 669 filesgraph/chains/ · 374 fileschaingraph.meta.json scripts/assemble-chaingraph.mjs chaingraph.jsonone file, sorted a check gate fails when the committed catalog drifts from its shards

The assembler re-sorts the output at build time, so nodes land in natural order by tool_id and workflows by name regardless of shard order. On 3 October 2026 the meta header listed 669 node shards and 374 workflow shards, and the assembled file matched them exactly.

CONTRACT.md §A4.0 shards and canonical orderscripts/assemble-chaingraph.mjs check mode
Who asks at this stepagents welcome
Read chaingraph/graph/nodes/art-591-x402-signer-recovery-verifier.json and name the kernel file that computes this node's execution_hash.
3
Step 3 · One writer

The file has a single writer

A pull request never edits chaingraph.json. After a merge lands on main, one GitHub Actions workflow, derived-artifacts-regen.yml, reassembles the file from its shards and commits it. Two branches editing the same generated bytes in parallel is the failure mode a single writer removes.

merge lands on mainnext merge lands derived-artifacts-regen.ymlreassembles the catalog on main chaingraph.jsoncommitted

The same workflow regenerates the estate's other shared artifacts, sitemap and feeds included, from their own single writers. The discipline is general: for every generated surface there is exactly one writer, and everything else reads.

.github/workflows/derived-artifacts-regen.ymlCONTRACT.md §A4.0
Who asks at this stepagents welcome
Show the workflow that regenerates chaingraph.json on main and name the check that fails when the committed catalog drifts from its shards.
Part two · Get the file and check it

Where the file goes and how to check it

Where the same bytes surface, how to hash a download against the published checksum list and its attestation, and which version field actually answers the question you asked.

4
Step 4 · Where it goes

Where copies of the file live

The catalog is served at https://ainumbers.co/chaingraph/chaingraph.json. The MCP worker at mcp.ainumbers.co/mcp boots from a data directory generated from the same file at its last vendor step. Discovery surfaces point readers and agents at it: llms.txt links the catalog directly, and the MCP discovery shim at .well-known/mcp.json points agents at the MCP registry surfaces and at llms.txt.

chaingraph.jsonassembled once ainumbers.co/chaingraph/the served file MCP worker data/mcp.ainumbers.co/mcp boots from it llms.txtlinks the catalog for agents .well-known/mcp.json points atthe MCP surfaces and llms.txt

On 3 October 2026 the served file returned HTTP 200 with the same 3,737,587 bytes as the repository copy at commit e6ca04443, and the deploy manifest recorded that commit as deployed_commit.

llms.txt.well-known/mcp.json.well-known/deploy-manifest.json
Who asks at this stepagents welcome
Download https://ainumbers.co/chaingraph/chaingraph.json and report the deployed_commit value in https://ainumbers.co/.well-known/deploy-manifest.json alongside the catalog size you received.
5
Step 5 · Verify a copy

Two checks on the copy you downloaded

A checksum list published at /.well-known/deploy-checksums.txt carries one sha256 line per deployed file. Compare your download against its line, then check the list itself against the Sigstore attestation GitHub recorded when the deploy ran.

your downloadchaingraph.json sha256 f5a4543c...095e7hash what you received deploy-checksums.txtline matches gh attestation verifyexit 0 on 3 October 2026
  1. Download the catalog and hash it: curl -sS -O https://ainumbers.co/chaingraph/chaingraph.json then sha256sum chaingraph.json.
  2. Compare the digest with the catalog's own line in the published list: curl -sS -O https://ainumbers.co/.well-known/deploy-checksums.txt then grep "chaingraph/chaingraph.json" deploy-checksums.txt.
  3. Check the list against its attestation: gh attestation verify deploy-checksums.txt --repo PostOakLabs/ainumbers.

On 3 October 2026 the served file hashed to f5a4543ca31b43291088a9f7036f0bcb3c729b9fec1371455f0cb3136cb095e7, that digest appeared on the catalog's line in a 9,912-line checksum list, and gh attestation verify exited 0 on the list from the same download. The attestation step is advisory in the deploy workflow, so a deploy can complete without a fresh attestation; the checksum comparison above is the check to run on any given file. The page you are reading is itself one of the files that list covers.

.well-known/deploy-checksums.txtgh attestation verifyactions/attest-build-provenance
Who asks at this stepagents welcome
Verify a fresh download of chaingraph.json: hash it, confirm the digest appears on its line in /.well-known/deploy-checksums.txt, and run gh attestation verify on that list against repo PostOakLabs/ainumbers.
6
Step 6 · Header fields

Which version field answers which question

The standard layers its version identifiers on purpose, in the style of in-toto and SLSA, so that an additive release does not move a wire identifier. spec_version is the version of record: on 3 October 2026 it read 0.8.13. Each artifact envelope carries chaingraph_version, frozen at 0.4.0 until a breaking schema change, and a @context URL that names the JSON-LD vocabulary in force.

spec_version 0.8.13 · the version of record chaingraph_version 0.4.0 · every artifact envelope @context v0.3 · the JSON-LD vocabulary measured 3 October 2026

The header also carries version and updated fields. Both have shown the same values since July 2026, so read the release from spec_version and check a copy by its hash instead.

SPEC.md Versioning modelchaingraph.json spec_version
Who asks at this stepagents welcome
Read spec_version from https://ainumbers.co/chaingraph/chaingraph.json and confirm the chaingraph_version value declared by an artifact envelope you received from the MCP worker.
🔒 All inputs are processed locally in your browser. No data is transmitted. Do not enter real personal data — use synthetic or anonymised inputs only.