Ga naar inhoud

The evidence bundle of a process

GET
/api/v1/evidence/bundles/{process_id}
curl --request GET \
--url https://example.com/api/v1/evidence/bundles/example \
--cookie bl_%3Cslug%3E_session=%3Cbl_%3Cslug%3E_session%3E

Everything needed to prove what happened in a negotiation, transfer or delegation, without the connector: the entries, the chain up to the latest anchor, the anchors, the DID documents and histories, signed by the participant. bl evidence verify <file> checks it offline.

process_id
required
string

The id of the negotiation, transfer or delegation.

OK.

Media typeapplication/json

What a participant can prove about one process, verifiable offline (bl evidence verify).

object
format
required
string
participant_did
required
string
environment

Environment of the connector that made the bundle (decisions #39). Absent in bundles from before environments existed.

string | null
process_id
required
string
created_at
required
string format: date-time
summary

Human-oriented description of the process (type, state, dataset, …).

object
entries
required
Array<object>

An entry of the evidence chain.

object
seq
required
integer format: int64
id
required
string
at
required
string format: date-time
kind
required
string
process_id
string | null
counterparty_did
string | null
summary
required
string
payload
string | null
payload_sha256
required
string
counterparty_signature
string | null
meta
object
content_hash
required
string
prev_hash
required
string
entry_hash
required
string
signature
required

JWS by the log owner over {iss, seq, entry_hash}.

string
leaves

Data plane requests of the process, each with the proof that the root of its window (an evidence.window entry above) holds it.

Array<object>

A leaf with the proof that its window root holds it.

object
leaf
required

A data plane request on record (a leaf of a window, decisions #44).

object
id
required
string
at
required
string format: date-time
kind
required
string
process_id
required
string
counterparty_did
string | null
content
required
object
window_seq

The chain entry of the window that holds this leaf, once sealed.

integer | null format: int64
leaf_index
integer | null format: int64
tree_size
required

Number of leaves in the window.

integer format: int64
proof
required

Inclusion proof, hex, leaf side first.

Array<string>
chain
required

Content-free chain links from the first entry up to the latest anchor (or head), proving the entries are part of one unbroken log.

Array<object>

Link of the chain without content (for proving continuity).

object
seq
required
integer format: int64
prev_hash
required
string
content_hash
required
string
entry_hash
required
string
anchors
Array<object>

An anchor: the notary’s receipt for the head of the chain at seq.

object
id
required
string
seq
required
integer format: int64
head
required
string
anchored_at
required
string format: date-time
receipt
required

JWS by the Trust Authority over {participant, seq, head, anchored_at}.

string
qualified

A qualified timestamp on the receipt (decisions #45), once the notary has stamped it.

object | null
authority_did
string | null
did_documents
required

Snapshots of every DID document needed for verification.

Array<object>
object
did_histories

Did:webvh histories of the parties (docs/decisions.md #42). Where a history verifies, the key in force at the time of a signature comes from it instead of from the snapshot.

Array<object>
object
consent

Present when the bundle is disclosed to a third party.

object | null
signature

JWS by the participant over the canonical bundle (without this field).

string

Example generated

{
"format": "example",
"participant_did": "example",
"environment": "example",
"process_id": "example",
"created_at": "2026-04-15T12:00:00Z",
"summary": {},
"entries": [
{
"seq": 1,
"id": "example",
"at": "2026-04-15T12:00:00Z",
"kind": "example",
"process_id": "example",
"counterparty_did": "example",
"summary": "example",
"payload": "example",
"payload_sha256": "example",
"counterparty_signature": "example",
"meta": {},
"content_hash": "example",
"prev_hash": "example",
"entry_hash": "example",
"signature": "example"
}
],
"leaves": [
{
"leaf": {
"id": "example",
"at": "2026-04-15T12:00:00Z",
"kind": "example",
"process_id": "example",
"counterparty_did": "example",
"content": {},
"window_seq": 1,
"leaf_index": 1
},
"tree_size": 1,
"proof": [
"example"
]
}
],
"chain": [
{
"seq": 1,
"prev_hash": "example",
"content_hash": "example",
"entry_hash": "example"
}
],
"anchors": [
{
"id": "example",
"seq": 1,
"head": "example",
"anchored_at": "2026-04-15T12:00:00Z",
"receipt": "example",
"qualified": "example"
}
],
"authority_did": "example",
"did_documents": [
{}
],
"did_histories": [
{}
],
"consent": "example",
"signature": "example"
}

No valid session, DPoP-bound token or API key.

Media typeapplication/json

The body of every failed call to a management API.

object
error
required
object
code
required

Stable, machine-readable: invalid_request, unauthenticated, forbidden, not_found, conflict, upstream_unavailable, unavailable, internal, or a more specific code of the operation.

string
message
required

For people; may change between versions.

string

Example

{
"error": {
"code": "not_found",
"message": "unknown negotiation"
}
}

The caller lacks the role this operation needs; or a change with the session cookie came from a page of another site (cross_site_request, decisions #83).

Media typeapplication/json

The body of every failed call to a management API.

object
error
required
object
code
required

Stable, machine-readable: invalid_request, unauthenticated, forbidden, not_found, conflict, upstream_unavailable, unavailable, internal, or a more specific code of the operation.

string
message
required

For people; may change between versions.

string

Example

{
"error": {
"code": "not_found",
"message": "unknown negotiation"
}
}

Not found.

Media typeapplication/json

The body of every failed call to a management API.

object
error
required
object
code
required

Stable, machine-readable: invalid_request, unauthenticated, forbidden, not_found, conflict, upstream_unavailable, unavailable, internal, or a more specific code of the operation.

string
message
required

For people; may change between versions.

string

Example

{
"error": {
"code": "not_found",
"message": "unknown negotiation"
}
}