Proof bundle
The self-contained JSON or CBOR file downloaded for a committed subject, carrying the subject data and its metadata, Merkle proofs, an Ed25519 signature, the witness detail that opens the submitted-after edge, and at least one public-blockchain commitment, every hash recomputed from carried bytes.
Overview
A proof bundle is the single self-contained file you download when you timestamp something
with Truestamp. It carries the subject’s data and its system-generated metadata, the Merkle
inclusion proofs, an Ed25519 signature, and the
public-blockchain commitment records needed for
offline verification without contacting any Truestamp
server. It serializes to two interchangeable encodings, human-readable JSON and compact
binary CBOR, and a top-level type key names the kind of subject it is about (item,
block, beacon, or one of the three entropy sources), with the matching frozen
t type code bound into the signed payload. A bundle must
contain at least one public-chain commitment, so one can only be generated once the
subject’s block has been committed.
Two properties are worth stating plainly, because they are what make a bundle stand alone.
- Nothing in a bundle is opaque. Every hash a verifier needs is recomputed from bytes the file carries, the subject and block metadata maps included. There is no field a reader has to accept on trust because it cannot be checked.
- A bundle may carry its witnesses. A downloaded file for an item names the head block and the entropy records the submission committed to, and carries each one in full, so the submitted-after edge can be confirmed from the file plus the public sources rather than from Truestamp. A compact variant leaves the witness detail out; the fingerprint, the signature, and every other check are unaffected.
The field-by-field reference is the proof bundle wire format; checking a bundle is covered in verify a proof, and the path from submission to a downloadable bundle is the proof lifecycle.
- Block hash
- CBOR
- Claims hash
- CLI (truestamp)
- Compact proof encoding
- Domain-Separated Hashing (SHA-256 Byte Prefixes)
- Ed25519 signature
- Entropy Verification Levels
- Epoch root
- Inclusion proof
- Item hash
- JCS (JSON Canonicalization Scheme)
- Merkle root
- Metadata hash
- Offline verification
- Signing-key ID (kid)
- t type code
- Truestamp CLI
- Witness