# Verifiability & authenticity {#verifiability}
\htmlonly
ELI5. The proof rides on the same walk as the payload. verifiable checks that the correction seeds were the honest ones. extractable checks that the path is weight 1, so a second programmed point fails. A MAC checks the leaf share after it is opened.
\endhtmlonly
Prove that a DPF walk used honest correction seeds, or that a weight-1
sketch over the path is consistent. The tags ride along as extra
`make_dpf` arguments; eval still returns the usual leaf share.
| Tag / call | What you get |
| --- | --- |
| [dpf::verifiable](@ref dpf/verifiable.hpp) | Proof token folded on the path (de Castro–Polychroniadou, EUROCRYPT 2022 / [ePrint 2021/580](@ref bib_vdpf)). Equal tokens across parties mean honest seeds. |
| [dpf::extractable](@ref dpf/verifiable.hpp) | Weight-1 `fp61` sketch on the same walk. A second hot point fails the check. |
| [dpf::output_mac](@ref dpf/verifiable.hpp) / `mac_authenticate` | Authenticated leaf shares and batch checks. |
| Path sketches | [path_sketch.hpp](@ref dpf/path_sketch.hpp) for prefix / parent sketches used by application mockups. |
```cpp
auto [k0, k1] = dpf::make_dpf(std::uint8_t{42}, std::uint64_t{7},
dpf::verifiable{});
auto [e0, e1] = dpf::make_dpf(std::uint8_t{42}, std::uint64_t{7},
dpf::extractable{});
```
Multipoint keys take the same `dpf::verifiable{}` tag for a batched
proof (one token for the cuckoo set). Three-party keys can be
verifiable or extractable as well; see [Multiparty & 3-server](@ref multiparty).
**Go deeper:** [guided tour](@ref tour_vdpf), ideal figures
[F_VDPF](@ref verifiable.hpp) / [F_Sketch](@ref verifiable.hpp),
[bibliography](@ref bibliography).