Skip to main content
GET
Signed current Merkle root for the canonical-card transparency log.

Response

Signed root, or an empty-state payload when the log has no entries.

typ
string
required

Domain separator distinguishing a signed root from a per-card attestation.

Allowed value: "AAP-TransparencyRoot/v1"
tree_size
integer
required
Required range: x >= 0
root_hash
string
required
Pattern: ^[0-9a-f]{64}$
published_at
string<date-time>
required
signing_key_id
string
required
signature
string
required

Base64url Ed25519 signature over canonical_json(commitment), where commitment is this object MINUS signature — i.e. {typ, tree_size, root_hash, published_at, signing_key_id}. Verify by dropping signature, canonicalising the rest (sorted keys, no whitespace), and checking against the JWKS key for signing_key_id.