kar-canon

Canonical JSON equivalence prover. Paste two JSON documents that should mean the same thing — different key order, whitespace, or number formatting — and get a byte-identical canonical hash if, and only if, they truly encode the same data. If they don't, it points at exactly where they diverge.
sovereign / offline single file, no server no LLM judge SHA-256 via crypto.subtle third-party re-runnable

What this proves

AI pipelines re-serialize the same structured decision (a tool call, a policy verdict, a cached response) through different libraries, languages, and formatters. Key order shifts, whitespace changes, 1.50 becomes 1.5 — and a naive string or byte comparison flags a false mismatch, or worse, a naive "looks similar" check misses a real one.

kar-canon converts each document to a single, fully-specified canonical byte string (closely following RFC 8785, the JSON Canonicalization Scheme), hashes it with SHA-256, and compares hashes. Anyone — in any language — can re-implement the algorithm below and reproduce the identical hash from the identical data. There is no model in the loop and nothing to trust but the arithmetic.

Honest limits

Algorithm — reproduce this hash yourself
  1. Parse the input as JSON (RFC 8259). Reject on parse failure.
  2. Canonicalize recursively:
    • null, true, false → the literal token.
    • number → the ECMAScript Number::toString form (shortest round-tripping decimal any compliant JS engine produces); negative zero canonicalizes to 0.
    • string → a JSON string literal with only the mandatory escapes (", \, and control characters U+0000–U+001F); every other code point is emitted as literal UTF-8, unescaped.
    • array → [ + canonicalized elements, comma-separated, original order preserved + ].
    • object → keys sorted by UTF-16 code unit order, duplicates resolved last-wins, then { + "key":value pairs, comma-separated, no extra whitespace + }.
  3. UTF-8 encode the resulting canonical string.
  4. SHA-256 the bytes; render the digest as lowercase hex.

Compare two documents

Self-test

Ten built-in cases exercise the exact same canonicalize / hash / diff functions used above — including one that must verify (equivalent documents, superficially different) and one that must be caught (a tampered value). Nothing here is hand-picked after the fact: the assertions and the engine are the same code that runs your input above.