Verify an evidence bundle
const url = 'https://example.com/api/v1/evidence/verify';const options = { method: 'POST', headers: { cookie: 'bl_%3Cslug%3E_session=%3Cbl_%3Cslug%3E_session%3E', 'Content-Type': 'application/json' }, body: '{"format":"example","participant_did":"example","environment":"example","process_id":"example","created_at":"2026-04-15T12:00:00Z","summary":{},"entries":[{"seq":1,"id":"example","at":"2026-04-15T12:00:00Z","kind":"example","process_id":"example","counterparty_did":"example","summary":"example","payload":"example","payload_sha256":"example","counterparty_signature":"example","meta":{},"content_hash":"example","prev_hash":"example","entry_hash":"example","signature":"example"}],"leaves":[{"leaf":{"id":"example","at":"2026-04-15T12:00:00Z","kind":"example","process_id":"example","counterparty_did":"example","content":{},"window_seq":1,"leaf_index":1},"tree_size":1,"proof":["example"]}],"chain":[{"seq":1,"prev_hash":"example","content_hash":"example","entry_hash":"example"}],"anchors":[{"id":"example","seq":1,"head":"example","anchored_at":"2026-04-15T12:00:00Z","receipt":"example","qualified":"example"}],"authority_did":"example","did_documents":[{}],"did_histories":[{}],"consent":"example","signature":"example"}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://example.com/api/v1/evidence/verify \ --header 'Content-Type: application/json' \ --cookie bl_%3Cslug%3E_session=%3Cbl_%3Cslug%3E_session%3E \ --data '{ "format": "example", "participant_did": "example", "environment": "example", "process_id": "example", "created_at": "2026-04-15T12:00:00Z", "summary": {}, "entries": [ { "seq": 1, "id": "example", "at": "2026-04-15T12:00:00Z", "kind": "example", "process_id": "example", "counterparty_did": "example", "summary": "example", "payload": "example", "payload_sha256": "example", "counterparty_signature": "example", "meta": {}, "content_hash": "example", "prev_hash": "example", "entry_hash": "example", "signature": "example" } ], "leaves": [ { "leaf": { "id": "example", "at": "2026-04-15T12:00:00Z", "kind": "example", "process_id": "example", "counterparty_did": "example", "content": {}, "window_seq": 1, "leaf_index": 1 }, "tree_size": 1, "proof": [ "example" ] } ], "chain": [ { "seq": 1, "prev_hash": "example", "content_hash": "example", "entry_hash": "example" } ], "anchors": [ { "id": "example", "seq": 1, "head": "example", "anchored_at": "2026-04-15T12:00:00Z", "receipt": "example", "qualified": "example" } ], "authority_did": "example", "did_documents": [ {} ], "did_histories": [ {} ], "consent": "example", "signature": "example" }'Checks a bundle, also one of another participant: signatures, the chain, the anchors and qualified timestamps, and the keys in force at the time. Changes nothing.
Authorizations
Section titled “Authorizations”Request Bodyrequired
Section titled “Request Bodyrequired”What a participant can prove about one process, verifiable offline
(bl evidence verify).
object
Environment of the connector that made the bundle (decisions #39). Absent in bundles from before environments existed.
Human-oriented description of the process (type, state, dataset, …).
object
An entry of the evidence chain.
object
object
JWS by the log owner over {iss, seq, entry_hash}.
Data plane requests of the process, each with the proof that the
root of its window (an evidence.window entry above) holds it.
A leaf with the proof that its window root holds it.
object
A data plane request on record (a leaf of a window, decisions #44).
object
object
The chain entry of the window that holds this leaf, once sealed.
Number of leaves in the window.
Inclusion proof, hex, leaf side first.
Content-free chain links from the first entry up to the latest anchor (or head), proving the entries are part of one unbroken log.
Link of the chain without content (for proving continuity).
object
An anchor: the notary’s receipt for the head of the chain at seq.
object
JWS by the Trust Authority over {participant, seq, head, anchored_at}.
A qualified timestamp on the receipt (decisions #45), once the notary has stamped it.
Snapshots of every DID document needed for verification.
object
Did:webvh histories of the parties (docs/decisions.md #42). Where a history verifies, the key in force at the time of a signature comes from it instead of from the snapshot.
object
Present when the bundle is disclosed to a third party.
JWS by the participant over the canonical bundle (without this field).
Example generated
{ "format": "example", "participant_did": "example", "environment": "example", "process_id": "example", "created_at": "2026-04-15T12:00:00Z", "summary": {}, "entries": [ { "seq": 1, "id": "example", "at": "2026-04-15T12:00:00Z", "kind": "example", "process_id": "example", "counterparty_did": "example", "summary": "example", "payload": "example", "payload_sha256": "example", "counterparty_signature": "example", "meta": {}, "content_hash": "example", "prev_hash": "example", "entry_hash": "example", "signature": "example" } ], "leaves": [ { "leaf": { "id": "example", "at": "2026-04-15T12:00:00Z", "kind": "example", "process_id": "example", "counterparty_did": "example", "content": {}, "window_seq": 1, "leaf_index": 1 }, "tree_size": 1, "proof": [ "example" ] } ], "chain": [ { "seq": 1, "prev_hash": "example", "content_hash": "example", "entry_hash": "example" } ], "anchors": [ { "id": "example", "seq": 1, "head": "example", "anchored_at": "2026-04-15T12:00:00Z", "receipt": "example", "qualified": "example" } ], "authority_did": "example", "did_documents": [ {} ], "did_histories": [ {} ], "consent": "example", "signature": "example"}Responses
Section titled “Responses”OK.
The outcome of verifying a bundle: ok when every check passed.
object
One check of [check].
object
discovery, issuer, keys or client.
ok, warning (could not be checked fully; saving is allowed),
failed (saving is refused) or skipped (an earlier check failed).
What was found, for people.
Example generated
{ "ok": true, "checks": [ { "id": "example", "status": "example", "detail": "example" } ]}No valid session, DPoP-bound token or API key.
The body of every failed call to a management API.
object
object
Stable, machine-readable: invalid_request, unauthenticated,
forbidden, not_found, conflict, upstream_unavailable,
unavailable, internal, or a more specific code of the operation.
For people; may change between versions.
Example
{ "error": { "code": "not_found", "message": "unknown negotiation" }}The caller lacks the role this operation needs; or a change with the session cookie came from a page of another site (cross_site_request, decisions #83).
The body of every failed call to a management API.
object
object
Stable, machine-readable: invalid_request, unauthenticated,
forbidden, not_found, conflict, upstream_unavailable,
unavailable, internal, or a more specific code of the operation.
For people; may change between versions.
Example
{ "error": { "code": "not_found", "message": "unknown negotiation" }}