# How contracts are verified on scdoscan.io (SCDO Shard0 (EVM), chainId 5680) Verification is **automatic**. Submit the form at https://scdoscan.io/verify-contract.html. A contract is marked **"Contract: Verified"** only when the submitted source, compiled with the stated settings, reproduces the code stored on chain. ## Who can submit - The submitter signs this text with `personal_sign` (MetaMask or the SCDO web wallet "Sign Message"): `SCDO contract verification ` - The signature must be less than 10 minutes old. Each signature can be used only once. - The signing address must be **KYC-verified** in the SCDO Shard0 (EVM) KYC registry (`isVerified(address, tier)`). The registry stores only a status, a tier, an expiry date and a record hash. It holds no personal data. Registry: `0x0d245fb56f9e9bdcf05fa93f39d5d29c4cd09335` (KYC 登記合約 / KYC Registry — 9Y9 PTY LTD). A revoked or expired status cannot submit. If an address is not verified yet, complete KYC in the SCDO web wallet (KYC tab): https://scdoscan.io/wallet/ ## Checks (service `scdo-verify`) 1. **Compiler.** Only official solc release builds from binaries.soliditylang.org are used. Each build is checked against the SHA-256 in `list.json` before use. 2. **Sandboxed compile.** solc runs in standard-JSON mode with your compiler version, optimizer on/off and runs, and evmVersion. It runs as an unprivileged user in an empty temp directory with CPU, memory and time limits. Imports are not fetched from the network. Put every file inline in standard JSON, or flatten the source. 3. **Runtime match.** The compiled `deployedBytecode` is compared with `eth_getCode(address, "latest")`, and `eth_chainId` must be 5680. `immutable` slots are masked. The trailing CBOR metadata hash is compared separately: - **Full match:** identical, including the metadata hash. - **Partial match:** identical except the metadata hash. The code is the same, but the source text, file names or settings recorded in the metadata differ. 4. **Creation check (where possible).** The creation transaction is found. Its input must start with the compiled creation bytecode. The remainder is the constructor arguments. If you entered constructor arguments, they must be equal to it. 5. **Publish.** `/verified/
.json` (source, ABI, settings, code sha256, creation tx, read/write descriptor, submitter address and KYC tier), `/verified/
.standard-input.json` and `/verified/index.json` are written immediately. The address page then shows the source code and the Read/Write panel. Your browser also re-checks `sha256(eth_getCode)` live against the published `codeSha256`. Limits: 2 MB per request, 1.5 MB of source, 300 files, 60 s compile time, 30 submissions per hour per IP. Problems? Report them here: https://github.com/SCDOLAB/scdoscan-web/issues/new?template=contract-verification.yml --- # scdoscan.io 合約驗證方式(SCDO Shard0 (EVM),chainId 5680) 驗證全自動完成。請在 https://scdoscan.io/verify-contract.html 提交。 只有當提交的原始碼按所填設定編譯後,與鏈上程式碼一致時,合約才會顯示"Contract: Verified"。 - **提交人:** 用 `personal_sign`(MetaMask 或 SCDO 網頁錢包"簽名訊息")簽署 `SCDO contract verification <合約地址小寫> `。 簽名 10 分鐘內有效,且只能使用一次。 簽名地址必須在 SCDO Shard0 (EVM) KYC 註冊合約(0x0d245fb56f9e9bdcf05fa93f39d5d29c4cd09335)中為"已認證";已撤銷或已過期的不能提交。該合約只存狀態、等級、有效期和記錄雜湊,不存任何個人資訊。 尚未認證的地址,請在 SCDO 網頁錢包 KYC 頁面完成認證:https://scdoscan.io/wallet/ - **檢查:** 1. 只使用 soliditylang.org 官方 solc 釋出版,並校驗 SHA-256。 2. 以非特權使用者在沙箱中編譯,有 CPU、記憶體和時間限制。 3. 與 `eth_getCode` 比對:immutable 位置會被遮蔽,後設資料雜湊單獨比較(完全匹配 / 部分匹配)。 4. 如能找到部署交易,還會核對建立位元組碼和構造引數。 - **釋出:** 驗證透過後立即寫入 `/verified/<地址>.json`,地址頁隨即顯示原始碼和讀/寫面板。 - **遇到問題?** 請在這裡反饋:https://github.com/SCDOLAB/scdoscan-web/issues/new?template=contract-verification.yml