Every result-producing analysis endpoint — MGA, HOC, moderation, IPMA, NCA, NCA-ESSE, fsQCA, robustness checks, FIMIX, PLS-POS, LCA, moderated mediation, nomological validity, measurement invariance, CTA, multi-group CB-SEM, EFA, CVI, Bayesian SEM, bootstrap, HTMT, predictive relevance, CMB, and indirect effects — now attaches a fingerprint and anchor status to its result, not just the main SEM fit.
_compute_fingerprint_generic() — a reusable fingerprinting function not tied to SEM-specific fields, so it works across fundamentally different result shapes (fsQCA solutions, LCA class assignments, CTA tetrad tests, etc). The original SEM-specific fingerprint function is now a thin wrapper around it._attach_provenance() helper shared by every endpoint — computes the fingerprint, optionally submits it for Bitcoin timestamping, and registers it so /fingerprint/{run_id}, /proof, and /upgrade work uniformly everywhere.fingerprint and anchor_status fields added to all 22 corresponding response schemas — additive, optional fields on already-frozen result models.run_id and an anchor parameter (default false), matching /run's existing pattern./run: anchor=true with no internet access still returns the full result, with anchor_status reporting timeout/failed instead of the request failing.Set anchor: true on any supported endpoint to submit the fingerprint hash to free public OpenTimestamps calendar servers, which batch many users' hashes into one Bitcoin transaction someone else pays the fee for — a decentralized analogue of RFC 3161 trusted timestamping.
.ots proof is never written to disk; download it promptly after a run or before restarting the server, or it's lost.Previously the fingerprint only existed inside the running app session — nothing that actually left the system carried it, which defeated the point of timestamping a result meant to be cited in a paper.
"Provenance" section with fingerprint and Bitcoin timestamp status.provenance object plus a one-line verification note.#-comment provenance header..docx report gets a new "Reproducibility & Provenance" section right after the title, spelling out exactly what the hash covers and that only the hash — never data, syntax, or results — ever left the machine._build_provenance_section in app/export_pdf.py.A bare JSON array cannot carry a top-level fingerprint field, so this is the one endpoint in the release whose response shape had to change.
The analysis output itself did not change. compute_nomological_validity() and every per-item field are byte-for-byte identical to v1.x. What breaks is purely mechanical: the top-level JSON is now an object instead of an array.
If you don't call /nomological directly, no code changes are required. All other endpoints only gained optional run_id/anchor parameters and optional fingerprint/anchor_status response fields.
Change response[0].r_squared / response.map(...) to response.entries[0].r_squared / response.entries.map(...). The in-app frontend already handled both shapes defensively before this shipped, so no in-app behavior changed — this only affects external scripts calling the endpoint directly. Full guide: docs/v2.0 → Migration Guide.
New files introduced in this release:
app/anchor.pyUpdated files:
app/main.py app/schemas.py app/export_pdf.py static/index.html pyproject.toml GET /fingerprint/{run_id} GET /fingerprint/{run_id}/proof POST /fingerprint/{run_id}/upgrade