# Pieces registered by lot (anchored mode)

For high-volume QR brands: each lot is recorded on the blockchain in one single entry, and a piece's token is created only when its buyer claims it.

Source: https://docs.sealtrust.io/en/pieces-ancrees/

---

By the end of this page, you will know what anchored mode changes for your
pieces, what its record proves and does not prove, when a piece gets its own
token, and how a third party checks a piece's proof without trusting us.

## The principle

By default, every minted piece immediately gets its own token on the Base
blockchain. This is the "one piece, one token" mode.

In anchored mode, the pieces of a lot are created in SealTrust, with their
serial number and their signed QR code, exactly as today. The whole lot is
then recorded on the blockchain in one single entry: a Merkle root, a
fingerprint that sums up every piece of the lot. Each piece keeps its own
proof that it belongs to that root.

A piece gets its token only on the day it first moves: when its buyer claims
it, or when your brand transfers it. A piece that is never claimed never gets
a token.

This mode suits a brand that prints QR codes in large numbers to fight the
grey market: it needs a provable serial number for each piece, not one token
per piece from the factory.

## Who turns it on

The SealTrust team, at your request. The setting applies to the whole brand.
It never changes while one of the brand's mints is in progress, and every
change is written to the audit log.

Nothing changes for pieces already created: a piece that has its token keeps
it, and a piece recorded through its lot gets its token on its first claim,
whatever the brand's mode is at that time.

Anchored mode covers QR-only pieces. An NFC chip is encoded with its token:
an NFC lot is still minted piece by piece.

## Minting a lot

The gesture is the same: "Mint the batch (grouped)" on the batch page. There is
nothing else to do.

The pieces exist from the click. QR codes, the archive to print and purchase
codes are prepared as usual. The lot's record is sent right away, in one
single transaction. If it cannot be sent at once (network unavailable, fees
too high), it is sent again automatically within the hour: the lot page shows
"Waiting to be recorded on the blockchain. It happens automatically within
1 hour".

Once the transaction is confirmed, the batch page shows "Recorded on the
blockchain on …", with the link to the transaction and the gas used.

If the blockchain refuses the record, or if the transaction stays without
confirmation for an hour, it is sent again automatically at the next hourly
pass. Nothing is sent blindly: when the root is already recorded, the
transaction that recorded it is kept. Until then, the piece's public page
shows "Registered, record refused" or "Registered, record pending", and
nothing is presented as proven.

A mint in anchored mode covers one lot at a time. Every piece must belong to
the lot, and to your brand.

## What the record proves

It proves that your brand registered this serial number, in this lot, no
later than the date of the block that carries the transaction, and that the
recorded fields have not changed since.

On its own, it does not prove that the object a person holds carries this
number, nor who owns it. Ownership starts with the claim, with the token.

The piece's public page, the one its QR code opens, shows "Registered and
anchored" once the transaction is confirmed, with the date, the link to the
transaction and the proof. Before confirmation, it shows "Registered, record
pending".

## When a piece gets its token

On its first claim, the token is created then handed to the buyer, in the
same request. Your brand's claim rules apply as for any piece: purchase code
required, in-store activation, time window. A second claim is refused as
today.

On the first transfer made by your brand, the token is created then
transferred, once the transfer's confirmation code has been entered: a request
abandoned before that code creates nothing.

The token of a piece registered by its lot is created by a single signature.
A brand that signs through a multisignature vault (Safe) therefore cannot
switch to anchored mode, and a vault cannot be activated while pieces of the
brand are waiting for their token.

The grey-market check applies to the piece, not to its token: it applies
from the moment the piece is created.

## Checking a piece's proof

The proof is read without an API key, with the serial number printed on the
QR code:

```bash
curl https://api.sealtrust.io/v1/verify/unit-anchor/K4QNAFCHDETK
```

The response gives `status` (`recorded` once the transaction is confirmed,
`pending` before, `failed` if the blockchain refused it), the recorded fields
`leaf_fields`, the leaf `leaf`, its position `leaf_index`, the proof `proof`,
the root `merkle_root`, the lot identifier on the contract
`onchain_batch_id`, the transaction and its link `explorer_url`, the date
`recorded_at`, and `token_minted`. The same information comes in the
`unit_anchor` field of `GET /v1/resolve/{identifier}`.

To redo the check yourself:

1. recompute the leaf from `leaf_fields`:

```text
keccak256(abi.encode(
  bytes32 keccak256("sealtrust.unit-anchor.v1"),
  string  serial,
  string  brand_code,
  uint256 product_model_id,
  string  lot_code,
  bytes32 uid_hash,
  uint64  created_at_unix
))
```

2. climb the proof: at each step, hash the current value with the next value
   of `proof`, the smaller of the two first (OpenZeppelin's `MerkleProof`
   convention). The result must be `merkle_root`;
3. read `anchoredRootByBatch(onchain_batch_id)` on the contract: the value
   must be the same root. `onchain_root_matches` gives the result of that
   read made by our servers, for information.

`uid_hash` is also the fingerprint of the token the piece will get: its token
number is that fingerprint read as a number. The token created later is
therefore the token of the recorded piece.

A piece that was not created in anchored mode answers 404: it has its own
token, and its proof is elsewhere ([trust and proofs](/en/confiance-et-preuves/)).

## What to remember

- Anchored mode records a whole lot in one single transaction; each piece
  keeps its proof.
- Nothing more to click: the record leaves with the mint, and is sent again
  on its own within the hour if needed.
- A piece gets its token on its first claim or its first transfer, never
  before.
- The record proves the registration of the number and its date, not the
  possession of the object.
