REWORK Proof for Hugging Face
Who actually controls a repository: checked, dated, and allowed to expire.
A full id or a huggingface.co URL. Models, datasets and Spaces all work.
How a claim is proven
- 1. REWORK issues a challenge. A signed file, bound to one repository, one Hugging Face account and a single-use nonce.
- 2. You commit it to the repo. Only someone with write access can do that. A pull request is not enough. The file has to be on the branch itself.
- 3. REWORK reads it back. Pinned to a head commit it resolved independently, so a stale or substituted copy cannot pass.
- 4. It keeps being checked, and allowed to die. Every claim is re-checked nightly and expires on its own. Delete the file, rename the repo, or make it private, and the claim goes away rather than quietly aging into a lie.
REWORK's access to Hugging Face is read-only. It never writes to your account, and it cannot create a claim on your behalf. You prove control yourself, which is the entire point.
What a claim does not prove: that the claimant trained or authored what is inside the repository. Control is control. Where REWORK can say more (a benchmark it ran itself, training datasets it checked against the Hub), it shows the receipt alongside, so you can tell the two apart.