United States federal court · Authentication
Federal Rules of Evidence 902(13) and 902(14), effective December 1, 2017, let a written certification replace a foundation witness for electronic records in United States federal court. A qualified person must sign it under penalty of perjury per 28 U.S.C. 1746. ProofSnap generates that declaration, pre-filled and unsigned, with every web capture.
This page covers what each subsection actually reaches, why the certification does not have to prove the business-records conditions of Rule 803(6) and should not try, the digital identification process Rule 902(14) makes you describe, the notice obligation people forget, and the boundary where self-authentication stops being useful.
By Radim Motycka, founder of ProofSnap · Published August 25, 2026 · Last reviewed August 25, 2026
Before December 2017, getting a web capture into evidence in federal court usually meant putting a person on the stand to say how it was made. Rules 902(13) and 902(14) took effect on December 1, 2017 and added electronic records to the list of items that authenticate themselves, so a written certification can stand in for that testimony. If you are starting from the more basic question of whether a screenshot is admissible in court at all, read that first and come back here for the certification mechanics. The two subsections divide the work.
| Subsection | What it reaches | In a web capture package |
|---|---|---|
| 902(13) | A record generated by an electronic process or system that produces an accurate result | The capture itself: the rendered screenshot, the page source, the DOM text, the network metadata, and the pipeline that produced them |
| 902(14) | Data copied from an electronic device, storage medium or file, authenticated by a process of digital identification | The copy and the SHA-256 values that tie each file in the package to what was captured |
A forensic web capture normally engages both at once, which is why a certification written for only one of them tends to leave a gap. Both subsections require the same thing procedurally: a certification of a qualified person that complies with the certification requirements of Rule 902(11) or (12).
Rules 902(13) and 902(14) borrow only the procedural machinery of Rule 902(11): the certification must comply with a federal statute or a rule prescribed by the Supreme Court, which in practice means a declaration under 28 U.S.C. 1746 or a notarized affidavit, and the proponent must give the notice Rule 902(11) requires. They do not borrow Rule 803(6). This matters more than it sounds: a one-off litigation capture is not kept in the course of a regularly conducted activity, so a declarant who recites the business-records conditions is swearing to something false.
"The reference to the 'certification requirements of Rule 902(11) or (12)' is only to the procedural requirements for a valid certification. There is no intent to require, or permit, a certification under this Rule to prove the requirements of Rule 803(6). Rule 902(13) is solely limited to authentication, and any attempt to satisfy a hearsay exception must be made independently."
Advisory Committee note to Federal Rule of Evidence 902(13), 2017 amendment. Cornell Legal Information Institute
What the note does set is a single functional test, and it is the most useful sentence in either note: a certification must contain "information that would be sufficient to establish authenticity were that information provided by a witness at trial." Ask yourself what you would have to say on the stand, then write that down.
Rule 902(14) adds a requirement of its own. The certification must explain the process of digital identification used to confirm that the record is an authentic copy of what was taken from the device, medium or file. In practice that means stating when the identification was performed, not only that it was: name the algorithm, give the moment the values were computed, and state exactly what they cover.
Hash comparison is not one option among many here. The Advisory Committee note to Rule 902(14) names it as the expected method:
"If the hash values for the original and copy are the same, it is highly improbable that the original and copy are not identical. Thus, identical hash values for the original and copy reliably attest to the fact that they are exact duplicates."
Advisory Committee note to Federal Rule of Evidence 902(14), 2017 amendment. Cornell Legal Information Institute
That sentence is why a per-file SHA-256 value in a signed manifest is the practical shape of a Rule 902(14) certification, and why a capture tool that produces only a PDF report leaves the declarant with nothing to describe. The note does not make hashing the only route, though: it adds that the rule is "flexible enough to allow certifications through processes other than comparison of hash value, including by other reliable means of identification provided by future technology."
The note describes a certifier who "checked the hash value of the proffered item and that it was identical to the original." In a web capture there is no original in your hands to hash. The manifest hashes prove the package has not changed since capture, which is an integrity claim, not the original-to-copy identity claim the note contemplates. Expect an opponent to argue that a live web page is not "an electronic device, storage medium, or file" from which data was "copied" at all, and that 902(14) therefore does not apply. The answer is that the weight sits on 902(13), which authenticates the capture on its own, and 902(14) reaches the copying inside the package. Plead both, rely on 902(13).
The failure mode is a conclusory certification. A declaration that asserts the tool is reliable, without stating the declarant's qualifications, the substance of the testimony they would give at trial, and the process actually followed, gives the opposing party nothing to test and gives the court no basis to accept it.
Both subsections also inherit the notice obligation of Rule 902(11). The rule requires the proponent, before the trial or hearing, to do two separate things:
"give an adverse party reasonable written notice of the intent to offer the record," and "make the record and certification available for inspection, so that the party has a fair opportunity to challenge them."
Federal Rules of Evidence, Rule 902(11), incorporated by Rules 902(13) and 902(14). Cornell Legal Information Institute
Serving that notice is the proponent's job. Missing it is a procedural way to forfeit an otherwise sound certification, which is why it belongs on a checklist rather than in someone's memory.
Two of these steps have to happen before the capture, which is why the order matters more than the list length.
Rules 902(13) and 902(14) require "a qualified person" and do not define the term. Unlike Rule 902(11) they do not even say "the custodian or another qualified person," and nothing in either subsection requires a disinterested certifier. A party, its employee or its investigator may certify; interest goes to weight, not competence. The working test comes from the note: could this person, testifying live, establish authenticity? Someone who ran the capture and uses the tool in the ordinary course qualifies. A partner who never touched it does not.
If the lawyer handling the matter signs the declaration and the certification is challenged, that lawyer becomes the witness who has to testify to the process, and Model Rule 3.7 puts their trial advocacy at risk. Have a paralegal, an in-house investigator or a third party run and certify the capture, and keep the trial team out of the chain of custody. Decide this before capturing, not when the objection lands.
The person with knowledge of the capture is the person who ran it, which is why the declarant should be chosen before the capture rather than after the objection.
Serving the certification does something specific: by following the approach of Rules 902(11) and 902(12), Rule 902(13) puts the burden of going forward on authenticity onto the opponent. If they do not object in time, no authenticating witness is needed at trial. That is the whole payoff, and it is why the certification is worth writing properly rather than filing a form.
A certification is only as good as its worst answer to the six arguments below. Work out yours before you serve the notice, because the notice starts the clock on the challenge.
A rendering is personalised by session, account, geography, A/B bucket and installed extensions. Answer: say so in the declaration. The exhibit is the page as served to that browser at that moment, and that is usually the fact in dispute anyway.
Capture tools dismiss cookie banners, freeze animations and unstick headers. Answer: a disclosure that lists every modification cuts both ways, and the version that survives is the one where the declarant can explain each entry. Read the disclosure before you sign it, not after you are asked about it.
Long pages get truncated. Answer: a certification that states the truncation is far stronger than one that is silent and gets caught. Never sign a clean bill of health over a package that records a gap.
The black-box attack, and it goes straight at the note's test. Answer: the declaration has to describe the process in enough detail that the same words would work from the stand. If the declarant cannot explain a step, cut the step from the declaration or find a declarant who can.
See the caution above. Answer: 902(13) authenticates the capture on its own and does not depend on an original-to-copy comparison.
The Advisory Committee note is explicit that a challenge "may require technical information about the system or process at issue, including possibly retaining a forensic technical expert," and that this affects whether the notice gave a fair opportunity. Answer: serve earlier than you would for a bank record.
Self-authentication under Rule 902 concerns authenticity only. It relieves the proponent of the need to offer extrinsic evidence that the item is what it is claimed to be. That is the whole of it, and the gap between that and what people assume it means is where cases go wrong.
Authenticity and admissibility are separate questions. A certification does nothing to a hearsay objection, a relevance objection, or any other rule.
A certified capture of a page proves what the page showed at that moment. It says nothing about who wrote, published or controlled the content on it.
A hash value shows that a file has not changed since the hash was computed. Whether the captured content is true is a different question entirely.
A program has no personal knowledge and cannot be prosecuted for perjury. Every statement in a Rule 902 declaration is the declarant's, not the vendor's.
The district court admitted auction terms it could not otherwise authenticate by taking judicial notice of a Wayback Machine printout. The Fifth Circuit held that was an abuse of discretion, and that the error was not harmless, so it reversed and remanded. The court's reason:
"a private internet archive falls short of being a source whose accuracy cannot reasonably be questioned as required by Rule 201."
The clearest appellate statement of why a third-party archive is not a substitute for a certified first-party capture. Full opinion on CourtListener.
Judge Grimm's framework opinion on electronically stored information, walking authentication, hearsay, best evidence and Rule 403 in sequence. Predates the 2017 amendments but remains the map every clerk knows.
The government offered a printout of a Russian social networking profile said to be the defendant's, supported only by an agent's testimony that the biographical details on it matched him. The Second Circuit held that was not enough, vacated the conviction and remanded: nothing in the record showed the defendant created the page or that the site verified who did. The standing reminder that resemblance is not a foundation, and the reason a capture has to record where the bytes came from rather than what they depict. Full opinion on CourtListener.
The note to Rule 902(13) works through a defamation plaintiff offering a printout of a web page. It is the drafters describing exactly this use case, and it is free to cite.
Capturing a page you are logged into is the most useful thing a browser-based tool does and the one that carries the most risk. Two consequences follow, and both belong in the declaration rather than in a footnote.
The exhibit is the page as served to that account. A logged-in view is personalised by session and identity. State which account was used and that the capture reflects what that account was shown. A declaration that says only "the page" invites the question of who was looking.
Capture only from accounts you are authorized to use. Using a client's ex-spouse's credentials, a shared password or a pretext profile raises exposure under the Computer Fraud and Abuse Act and the Stored Communications Act, and for lawyers it runs into Model Rules 4.2 and 8.4(c) and ABA Formal Opinion 466 on reviewing a represented party's social media. Private-account content has to come from the party, through a Rule 34 request or the party's own consented disclosure, because the Stored Communications Act bars a provider from divulging content to a civil litigant and a court order under 18 U.S.C. 2703 is available to governmental entities, not to a party in a civil case. Self-help capture is not a substitute.
Rule 901(b)(9) is the general authentication route for evidence produced by a process or system: describe the process and show that it produces an accurate result, ordinarily through a witness. Our companion page covers that route in full, including what Rule 901 requires to authenticate a screenshot and how Maryland, Texas and Pennsylvania split on social media. Rule 902(13) is the self-authenticating shortcut over the same ground, swapping live testimony for a written certification.
They are alternatives, not opposites, and that matters practically. If an opponent successfully challenges the certification, the proponent falls back on a witness describing the same process under Rule 901(b)(9). A capture package documented well enough for the certification is also the package that witness will need, which is an argument for over-documenting rather than under-documenting the process.
Nothing here is law yet, and it will not be before December 1, 2028 at the earliest. Proposed Rule 707 addresses evidence produced by artificial intelligence and offered at trial without an expert. Most commentary still describes the 2025 draft, which applied Rule 702's reliability standard to machine-generated evidence. That is no longer the operative text: on May 7, 2026 the Advisory Committee replaced it with a revised draft, retitled "Evidence Produced by Artificial Intelligence and Presented at Trial Without an Expert," which ordinarily requires an expert foundation. Because the text changed after the comment period closed on February 16, 2026, it must be republished for comment, so the widely repeated December 2027 date is not on track.
The proposal is aimed at analytical and AI-generated output rather than at a deterministic capture-and-hash pipeline. But the direction is the one Rules 902(13) and 902(14) already set in 2017: courts want the process described and testable, not asserted. A workflow that can already show its work is the one least disturbed by whatever Rule 707 becomes. We go through the practical consequences in more depth in deepfake evidence, provenance certificates and proposed FRE 707.
Every ProofSnap capture entitled to a Bitcoin OpenTimestamps anchor also writes rule_902_certification.pdf into the evidence package. A package runs from 11 to 15 files depending on plan, and one that carries this declaration is 12 to 15, because the declaration is itself one of the files. It is a fillable PDF and it is deliberately unsigned. The generator transcribes every fact a declarant would otherwise copy out of manifest.json by hand: one SHA-256 value for every artifact the manifest covers, the full source URL, the capture timestamp and the time source used to fix it. The number of hash values follows the page rather than the file count, because the manifest hashes the images embedded in the page as well as the files written to disk. The capture of a single news article shown below, taken on August 25, 2026, produced 32 hash values, 17 of them for images embedded in the page. Nothing in that list is typed by the declarant.
These are the parts only a person can supply. Boilerplate qualifications the declarant did not write are exactly the conclusory content the guidance warns against.
This is the real rule_902_certification.pdf from the capture described above, exactly as the generator wrote it, four pages including the full hash list. Open it in the browser or save a copy. It is the same file that lands in the evidence package.
The source page was a public news article, so nothing in it is confidential. The declarant fields are blank, because that is how the generator writes them.
CERTIFICATION OF AUTHENTICITY
OF ELECTRONIC EVIDENCE
Fed. R. Evid. 902(13) and 902(14); 28 U.S.C. § 1746
ProofSnap generated this document from the contents of the evidence package identified below. It is an unsigned template. It has no effect until a qualified person with personal knowledge reviews it, completes the blank fields, and signs it. Where a blank below already contains text, that text was taken from the record of this capture and ProofSnap has not verified it: check it, and correct it if it is wrong. Read every statement before you sign. You, not the software, make this certification. Do not place the signed copy back inside the package: the package's integrity rests on the SHA-256 hash values recorded in manifest.json, so any change to this file would make its hash value no longer match the recorded value, and verification would report the package as altered.
I. Declarant
1. My name is
2. My position or title is
3. My employer or organization is
4. My qualifications to make this certification, and the basis of my familiarity with the process described in Section III, are as follows:
(State facts rather than conclusions. For example: I performed the capture described in Section III, I am familiar with how the capture system works, and I use it in the ordinary course of my work.)
5. I have personal knowledge of the matters stated in this certification, and if called as a witness, I could and would testify competently to them.
II. The records this certification covers
6. This certification covers the electronic evidence package (referred to below as the package) identified as follows:
| Evidence ID: | ps_e41dffe2-eda0-4652-bf04-76bfcd1f3ff4 |
| Source URL: | https://www.arabnews.com/node/2655769/middle-east |
| Captured (UTC): | 2026-08-25T06:53:54Z (UTC) |
| Capture software: | ProofSnap Chrome Extension version 1.19.4 |
| ProofSnap account: | f5RWV90LkzU4BYrpmGKxAyDcid83 |
| Files hashed before this certification was written: | 36 |
The hash values of those files are set out in Section IV, subject to the length limit stated there. Not every file in the package carries a hash value there, because a file created after those values were computed cannot carry one: that is the case for the signature over the manifest, for the public key that verifies it, and for the timestamp files.
III. The process that generated the records (Rule 902(13))
7. The records were generated by an electronic process running in a Chrome browser on the computer I used to make the capture. The system performed the following steps, in this order:
(a) It obtained the current time from independent network time sources and compared those times against each other.
(b) It loaded the source URL in a browser tab and recorded the HTTP response headers returned by the server, and the addresses to which the hostname resolved, as reported by two independent DNS resolvers queried separately.
(c) It saved the page as displayed: a screenshot of the page, the page HTML with its stylesheets, and the text content of the page as rendered. Where it added a band of its own to the top of the screenshot, recording the address, the time and the identifier of this capture, it did so before the hash values in Section IV were computed, so those values are of the annotated image; the page content below the band is unchanged.
(d) It recorded the changes it made to the page in order to capture it, such as hiding a cookie banner or a floating header, and it recorded how much of the page the screenshot covered.
(e) It computed a SHA-256 hash value and a SHA-512 hash value for every file that existed when manifest.json was written, and wrote those values into manifest.json together with the length of each of those files in bytes.
(f) It generated an RSA-4096 key pair for this capture and signed manifest.json with the private key. The signature is manifest.sig, and the public key is publickey.pem.
The system also wrote a step-by-step log of the capture (forensic_log.json) in which each entry carries the hash value of the entry before it, so that the removal or alteration of an entry can be detected. The log is sealed before the hash values in step (e) are computed, because manifest.json records a hash value for the log itself.
8. The records identified in paragraph 6 were generated by the process described in paragraph 7. Based on my familiarity with that process and on my observation of this capture, that process produces an accurate result, and it produced an accurate result here.
IV. Digital identification of the records (Rule 902(14))
9. Each file included in the count "Files hashed before this certification was written" stated in paragraph 6 was identified by a SHA-256 hash value at the time the file was produced. A SHA-256 hash value is computed from the entire contents of a file. Changing a single byte of a file changes its hash value.
10. The hash values below were computed by the system at the time of capture. They are reproduced from manifest.json. Any person who has the package can recompute these values from the files and compare them with the values listed there.
metadata.json
SHA-256: 76b3870bb90b092963e9f1fb266075f4f00a3dac87ce01da91e19727be7173a6
page.html
SHA-256: ec84861551c0be529731fe9bfd52f6c4aabf325fea7c5ec3236df017e9b1d9fe
screenshot.jpeg
SHA-256: bf41177408410e50ed51dbccbca230d9075cd1425b528f70e221079a07fcb851
images/001_4743007-217510164.jpg
SHA-256: 42dc35ee97ca51e272cfdcb23fa9c5eda2a299e01e6b3d0c074368477ba2b3ad
... and so on, ending with a note that the remaining 8 files and their hash values are listed in manifest.json
[ Section V. Time, and the network time sources relied on, omitted from this excerpt ]
VI. Declaration
I declare under penalty of perjury under the laws of the United States of America that the foregoing is true and correct.
Executed on (date):
Executed at (city and state, or country):
Signature:
Printed name:
VII. Notice to the adverse party and limits of this certification
Self-authentication under Rule 902 concerns authenticity only. It does not make a record admissible, it does not affect an objection based on hearsay, relevance, or any other rule, and it does not establish who wrote, published, or controlled the captured content. ProofSnap is software: it certifies nothing and testifies to nothing, and every statement in this document is the declarant's.
Wording is verbatim from the generator, abridged for length: Section V is omitted where marked above, and a few of the longer explanatory paragraphs are shortened. Note that the declaration speaks in the first person throughout, because the declarant is the one making it. Paragraph 8, highlighted, is the Rule 902(13) showing: it is the sentence that says the process produces an accurate result and produced one here.
Declarant, then the records the certification covers, then the process that generated them under Rule 902(13), then digital identification under Rule 902(14), then time, then the declaration under 28 U.S.C. 1746, and finally a standing note on the notice requirement and the limits of self-authentication. The document is English only by design, because it is a United States court filing.
What ProofSnap looks like
There is no desktop client to roll out and no separate portal to log into before the first capture. You open the page you need on the record, open the ProofSnap side panel, and press Capture. The capture runs on your machine, so a page behind your own login is captured as you see it.
rule_902_certification.pdf written into the same package, pre-filled and unsignedShown in English. The panel ships in 29 languages, though the Rule 902 declaration itself is English only by design, because it is a United States court filing.
ProofSnap side panel, English interface
The Rule 902 certification is generated on every capture entitled to a Bitcoin OpenTimestamps anchor: every plan except Essential, plus every SnapPack capture. It is not a paid add-on.
All plans include a 7-day trial. A credit card is required at sign-up. Cancel any time. Billed in USD.
$4.99
one-time, $0.50 a capture
$8.99
per month
$16.99
per month
$28.99
per month
Working as a team? Company is $18.99 per seat per month, minimum two seats and no upper limit, with shared member management, whitelabel branding and the eIDAS qualified timestamp.
Most people arriving at this page have a single exhibit to authenticate, not a workflow to buy. A SnapPack covers 10 captures for $4.99 with no subscription and no auto-renewal, and every one of them writes the Rule 902 declaration into its package. You do have to create an account and enter a card at checkout.
Rule 902(13) covers a record generated by an electronic process or system that produces an accurate result, so it is the subsection for the capture itself. Rule 902(14) covers data copied from an electronic device, storage medium or file, authenticated by a process of digital identification, so it is the subsection for the copy and for the hash values that tie the copy to what was captured. A web capture package normally engages both: 902(13) for the process that produced the record, 902(14) for the hashes proving the files have not changed since. Both took effect on December 1, 2017 and both require a certification by a qualified person meeting the requirements of Rule 902(11).
No, and any vendor claiming otherwise is misreading the rule. Rules 902(13) and 902(14) each require a certification of a qualified person that complies with the certification requirements of Rule 902(11) or (12), which in practice means a declaration subscribed under penalty of perjury under 28 U.S.C. 1746. A program has no personal knowledge and cannot be prosecuted for perjury, so it cannot be the declarant. This is why ProofSnap generates rule_902_certification.pdf as an unsigned template: it fills in every fact a declarant would otherwise transcribe by hand from manifest.json and leaves the identity, qualifications and signature blank for a person to complete.
It must not be conclusory. The guidance on these rules is consistent that a certification has to state the certifier's qualifications, the substance of the testimony they would give at trial if called, and the process actually followed, rather than asserting compliance in the abstract. For Rule 902(14) it must additionally explain the process of digital identification used to confirm the copy is authentic, which for a hash-based workflow means naming the algorithm, when the hash values were computed and what they cover. A certification that says only that the tool is reliable gives the opposing party nothing to test and gives the court no basis to accept it.
No. Self-authentication concerns authenticity only. It relieves the proponent of the need to offer extrinsic evidence that the item is what it is claimed to be, and nothing more. It does not answer a hearsay objection, it does not establish relevance, and it does not prove who wrote, published or controlled the captured content. A hash value shows that a file has not changed since the hash was computed; it says nothing about whether the content of the page is true. Treating a Rule 902 certification as a general admissibility ticket is the most common way to lose the argument.
Both subsections incorporate the notice requirement of Rule 902(11). Before the trial or hearing, the proponent must give an adverse party reasonable written notice of the intent to offer the record, and must make the record and the certification available for inspection, so the party has a fair opportunity to challenge them. Serving that notice is the proponent's responsibility, not the software's. Missing the notice is a procedural way to forfeit an otherwise sound certification, so it is printed as a standing reminder inside the ProofSnap template.
Rule 901(b)(9) is the general authentication route for evidence produced by a process or system: the proponent describes the process and shows that it produces an accurate result, usually through a witness. Rule 902(13) is the self-authenticating shortcut over the same ground, replacing live testimony with a written certification. They are alternatives rather than opposites. A well-documented capture package supports both, which matters when an opponent challenges the certification and the proponent has to fall back on a witness describing the same process.
Proposed Rule 707 addresses evidence produced by artificial intelligence and offered at trial without an expert. The version published for comment in 2025 would have applied Rule 702's reliability standard to machine-generated evidence, but the Advisory Committee replaced that text on May 7, 2026 with a substantially revised draft, retitled "Evidence Produced by Artificial Intelligence and Presented at Trial Without an Expert," which drops the phrase machine-generated, adds a requirement that the evidence help the trier of fact, and ordinarily requires an expert foundation with non-expert proof allowed only in exceptional circumstances. Because the text changed after the comment period closed on February 16, 2026, it has to be republished for comment, which puts December 1, 2028 at the earliest and later in practice. It is aimed at analytical and AI-generated output rather than at a deterministic capture-and-hash pipeline, but the direction of travel is the same one Rules 902(13) and 902(14) already set: courts want the process described and testable, not asserted.
A fillable PDF organized as Declarant, the records this certification covers, the process that generated the records under Rule 902(13), digital identification of the records under Rule 902(14), time, the 28 U.S.C. 1746 declaration, and a closing section on notice and the limits of self-authentication. Every fact is pre-filled from the capture: the ProofSnap evidence identifier, the full source URL, capture times, and the SHA-256 value and byte size of each file in the package. Any disclosed gap, such as a truncated capture or a screen recording that is not a copy of the source media, is printed inside the certification rather than omitted, because a declarant must not sign a document their own evidence package contradicts. The document is English only by design, since it is a United States court filing.
Every fact a Rule 902 declarant would otherwise transcribe by hand from a manifest comes pre-filled. You supply who you are and your signature.
SnapPack from $4.99 for 10 captures, one-time, no auto-renewal. The 7-day trial requires a credit card at sign-up.