How it works
Evidence, not endorsements
The Open App Registry links an app’s onchain identity to its programs, domains and source code. OAR Explorer shows that evidence, one link at a time, so you can decide what to trust.
What each state means
- Program linked
- The program’s upgrade authority published a backlink to this App ID, and the app’s manifest lists the program.
- Domain linked
- The domain serves
/.well-known/oar.jsonor an_oarDNS TXT record naming this App ID, and the manifest lists the domain. - Repository linked
- The repository’s root
oar.jsonnames this App ID, and the manifest lists the repository. - Attested
- A trusted issuer signed a Solana Attestation Service attestation for the link. This explorer trusts no issuer by default.
- Unverified
- Claimed in the manifest, but no proof was found. An app with no linked program or domain is labelled “Unverified” before its name.
- Disputed / invalid
- The proof points to a different app or cluster.
What the explorer checks
- The AppRecord on Solana: owner, layout and address, and the manifest hash it pins.
- The manifest: fetched from its URI, hashed in canonical form, and compared with the onchain hash. Any mismatch makes it unavailable, never partly trusted.
- Each link it claims, checked live from the other side, every time you look. Results are cached for about a minute.
What it does not mean
A linked program, domain or repository shows who controls them, not whether the app is safe, audited or endorsed. There is no overall “verified app” badge, by design. Names, publishers and descriptions are self-declared.
Status
This explorer runs on Solana Devnet against OAR v0.1.1-rc.1. Mainnet is not live yet: it waits on an independent security review, multisig governance and operations readiness. Read the specification or the protocol source.