> ## Documentation Index
> Fetch the complete documentation index at: https://docs.truthlocks.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Get Proof Bundle

> Returns a complete proof bundle for offline verification. Includes:
- The attestation itself
- Issuer information
- Public key used for signing
- Transparency log inclusion proof
- Signed tree head


Returns a complete proof bundle for offline verification. Includes the attestation, issuer information, public key, transparency log inclusion proof, and signed tree head.

### Parameters

<ParamField path="id" type="uuid" required>
  Attestation ID
</ParamField>

### Responses


## OpenAPI

````yaml mint-openapi.yaml GET /v1/attestations/{id}/proof-bundle
openapi: 3.0.3
info:
  title: Truthlocks API
  description: >
    Truthlocks is a universal verification infrastructure for documents,
    credentials, and digital assets.

    This specification defines the canonical API for interacting with Truthlocks
    services.


    ## Base URLs

    - **Production**: `https://api.truthlocks.com`

    - **Sandbox**: `https://sandbox-api.truthlocks.com`


    ## Authentication

    - **API Keys**: Use `X-API-Key` header for machine-to-machine operations

    - **Bearer Tokens**: Use `Authorization: Bearer <jwt>` for user-initiated
    operations


    ## Tenant Identity

    In production, tenant identity is derived from the authenticated context
    (API key or JWT).

    The `X-Tenant-ID` header is ignored in production to prevent spoofing.
  version: 1.0.0
  contact:
    name: Truthlocks Support
    url: https://truthlocks.com/support
    email: support@truthlocks.com
servers:
  - url: https://api.truthlocks.com
    description: Production API
  - url: https://sandbox-api.truthlocks.com
    description: Sandbox Environment
security:
  - APIKey: []
tags:
  - name: Authentication
    description: API key and token management
  - name: Issuers
    description: Issuer registration and trust management
  - name: Keys
    description: Cryptographic key management for issuers
  - name: Attestations
    description: Attestation lifecycle (mint, revoke, supersede)
  - name: Verification
    description: Attestation verification and proof bundles
  - name: Governance
    description: Issuer governance workflows (admin only)
  - name: Identity
    description: Organization, user, and role management
  - name: Audit
    description: Audit event queries
  - name: Platform
    description: Platform administration (super admin only)
  - name: Platform Review
    description: Staff review workflows for issuer applications
  - name: Tenant Console
    description: Tenant profile and lifecycle endpoints
  - name: Health
    description: Service health and readiness endpoints
  - name: Risk
    description: Risk signal ingestion and fraud detection
  - name: Risk Enforcement
    description: Risk enforcement actions — block, challenge, quarantine, and configuration
  - name: Billing
    description: Billing, subscription, and addon management
  - name: Machine Identity
    description: >-
      Machine Agent Identity Protocol (MAIP) — agent registration, sessions,
      trust, witness, compliance, orchestration, and observability
externalDocs:
  description: Transparency read-only API (separate service spec)
  url: >-
    https://github.com/truthlocks/truthlock/blob/main/docs/transparency/openapi.yaml
paths:
  /v1/attestations/{id}/proof-bundle:
    get:
      tags:
        - Verification
      summary: Get Proof Bundle
      description: |
        Returns a complete proof bundle for offline verification. Includes:
        - The attestation itself
        - Issuer information
        - Public key used for signing
        - Transparency log inclusion proof
        - Signed tree head
      parameters:
        - name: id
          in: path
          required: true
          schema:
            type: string
            format: uuid
      responses:
        '200':
          description: Proof bundle
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ProofBundle'
        '404':
          description: Attestation not found
      security:
        - APIKey: []
components:
  schemas:
    ProofBundle:
      type: object
      properties:
        attestation:
          $ref: '#/components/schemas/Attestation'
        issuer:
          $ref: '#/components/schemas/Issuer'
        key:
          $ref: '#/components/schemas/Key'
        inclusion_proof:
          type: object
          properties:
            log_index:
              type: integer
            root_hash:
              type: string
            hashes:
              type: array
              items:
                type: string
        signed_tree_head:
          type: object
          properties:
            tree_size:
              type: integer
            root_hash:
              type: string
            signature:
              type: string
    Attestation:
      type: object
      properties:
        id:
          type: string
          format: uuid
        issuer_id:
          type: string
          format: uuid
        kid:
          type: string
        status:
          type: string
          enum:
            - VALID
            - REVOKED
            - SUPERSEDED
        payload:
          type: object
        signature:
          type: string
        log_index:
          type: integer
        created_at:
          type: string
          format: date-time
    Issuer:
      type: object
      properties:
        id:
          type: string
          format: uuid
        tenant_id:
          type: string
          format: uuid
        name:
          type: string
        domain:
          type: string
        status:
          type: string
          enum:
            - PENDING
            - APPROVED
            - SUSPENDED
            - REVOKED
        trust_level:
          type: string
          enum:
            - BASIC
            - VERIFIED
            - ENTERPRISE
        created_at:
          type: string
          format: date-time
        updated_at:
          type: string
          format: date-time
    Key:
      type: object
      properties:
        kid:
          type: string
          description: Key identifier
        issuer_id:
          type: string
          format: uuid
        algorithm:
          $ref: '#/components/schemas/SigningAlgorithm'
        public_key:
          type: string
          description: Base64-encoded public key
        status:
          type: string
          enum:
            - ACTIVE
            - DISABLED
            - EXPIRED
        not_before:
          type: string
          format: date-time
        expires_at:
          type: string
          format: date-time
    SigningAlgorithm:
      type: string
      enum:
        - Ed25519
        - ES256
        - ES384
        - ES512
        - RS256
        - RS384
        - RS512
        - PS256
        - PS384
        - PS512
      description: Signing algorithm for key generation
  securitySchemes:
    APIKey:
      type: apiKey
      in: header
      name: X-API-Key
      description: API key for machine-to-machine authentication

````