ProofCore / Docs
01 — Architecture

Protocol Overview & Axioms

ProofCore is a decentralized cryptographic evidence layer. It transforms ephemeral digital artifacts (AI outputs, audit reports, server logs, code releases) into mathematically indisputable proof records anchored to the TON Blockchain.

Strict Zero-Storage by Design

Raw payloads and confidential prompts are hashed in volatile RAM and immediately discarded. ProofCore never writes sensitive customer data to disk or public blockchains.

Zero Vendor Lock-in

Proof verification does not depend on our API or continued corporate existence. Proof packages are 100% self-contained and verifiable offline against public TON nodes.

02 — Machine-to-Machine Interface

M2M REST API v0.1

Base Gateway: https://api.proofcore.org (Anonymous Zero-Auth access).

⚡ Rate Limits & High-Throughput M2M

The Free Zero-Auth Tier is capped at 100 requests / hour / IP via a Redis sliding-window filter to mitigate DDoS attacks.

Autonomous Agents & High-Frequency Pipelines: For continuous CI/CD or multi-agent loops requiring higher throughput, x402 Micropayments (USDC/TON) and Enterprise Dedicated API Keys are Coming Soon (Q4 2026).

POST /api/v0.1/seal

Polymorphic endpoint that ephemerally ingests, canonicalizes, and hashes an artifact in RAM. Creates an Ed25519 notary signature and queues the commitment for TON Merkle batching.

Request 1/3: Simple Text Mode cURL
curl -X POST https://api.proofcore.org/api/v0.1/seal \ -H "Content-Type: application/json" \ -d '{ "payload": { "mode": "text", "content": "Any raw string, markdown, or custom stringified JSON envelope." }, "title": "My Custom Proof", "agent_id": "Agent-Smith" }'
Request 2/3: AI Inference Mode cURL
curl -X POST https://api.proofcore.org/api/v0.1/seal \ -H "Content-Type: application/json" \ -d '{ "payload": { "mode": "inference", "prompt": "Audit Vault.sol for reentrancy vulnerabilities", "output": "Audit complete. Severity: 0 High. Safe for deployment.", "model_id": "claude-3-5-sonnet" }, "title": "Smart Contract Audit" }'
Request 3/3: Multi-Artifacts Bundle cURL
curl -X POST https://api.proofcore.org/api/v0.1/seal \ -H "Content-Type: application/json" \ -d '{ "payload": { "mode": "artifacts", "files": [ {"filename": "contract.sol", "content": "pragma solidity ^0.8.0; ..."}, {"filename": "deploy.js", "content": "console.log(\"deploying\");"} ] }, "title": "Release v1.2.0" }'
Response (Status: 200 OK) Queued for TON
{ "status": "queued", "deal_id": "96051ff8-facb-4df6-b086-205a52c4842d", "sha256_hash": "6001835047a8bc5f1eb969fcbd07ea5048ece4bfb1e232daa50d62bd713ed645", "signature": "R2VuaXVz...==", "signer_pubkey": "oH96uLjPgb+M9hKBNtFqbN9zzIDWdcs79dKbMXnVIcg=", "verification_url": "https://proofcore.org/app/96051ff8-facb-4df6-b086-205a52c4842d", "citation_markdown": "\n\n---\n🛡️ **ProofCore Cryptographic Evidence:** [Verified on TON Blockchain](https://proofcore.org/app/96051ff8-facb-4df6-b086-205a52c4842d)\n\n---", "badge_url": "https://api.proofcore.org/api/badge/96051ff8-facb-4df6-b086-205a52c4842d", "badge_markdown": "[![ProofCore](https://api.proofcore.org/api/badge/96051ff8-facb-4df6-b086-205a52c4842d)](https://proofcore.org/app/96051ff8-facb-4df6-b086-205a52c4842d)" }
GET /api/v0.1/proof/{deal_id}

Polls blockchain status and retrieves the full cryptographic manifest, including explicit Merkle tree traversal paths and public TON transaction hashes.

Response (Once Anchored: status = 'anchored_onchain') TON Confirmed
{ "deal_id": "96051ff8-facb-4df6-b086-205a52c4842d", "status": "anchored_onchain", "network": "mainnet", "merkle_root": "07ab51479c5f9148e1cc397ed2084cb8f211b025ca59263b24dd2c39b3e09904", "merkle_path": [ { "direction": "right", "hash": "d1c2...f8" }, { "direction": "left", "hash": "a4b3...c2" } ], "ton_tx_hash": "6ecea8b15a7aa5a60be9d914d367baf63e64df239d46aadcfa31bef74f87d067", "ton_time": 1789367854, "ton_explorer_url": "https://tonviewer.com/transaction/6ecea8b15a7aa5a60be9d914d367baf63e64df239d46aadcfa31bef74f87d067", "zip_url": "https://api.proofcore.org/api/download/96051ff8-facb-4df6-b086-205a52c4842d" }
POST /api/v0.1/verify

Autonomous inter-agent verification. Recalculates the SHA-256 digest, checks the Ed25519 notary signature, and confirms blockchain state. If you pass content containing the citation badge, the deal UUID is extracted automatically.

Request Payload Autonomous Marker Parsing
{ "content": "Audit complete. Severity: 0 High... \n\n" }
Verification Verdict valid: true
{ "valid": true, "checks": { "hash_match": true, "signature_valid": true }, "anchor": { "status": "anchored_onchain", "merkle_root": "07ab51479c5f9148e1cc397ed2084cb8f211b025ca59263b24dd2c39b3e09904", "ton_tx_hash": "6ecea8b15a7aa5a60be9d914d367baf63e64df239d46aadcfa31bef74f87d067", "network": "mainnet" } }
GET /api/v0.1/pubkey

Retrieves the official Base64-encoded Ed25519 public key of the ProofCore notary service. Use this key to verify notary signatures offline on local air-gapped systems without querying our database.

Response Ed25519 Raw PubKey
{ "algorithm": "Ed25519", "public_key": "oH96uLjPgb+M9hKBNtFqbN9zzIDWdcs79dKbMXnVIcg=" }

HTTP Status Codes & Error Reference

Status Code Reason Client Handling Strategy
400 Bad Request Malformed JSON syntax or missing required payload fields. Validate payload schema against mode specifications.
404 Not Found Invalid deal UUID or deal does not exist in registry. Ensure the UUID is 36 characters and correctly formatted.
413 Payload Too Large Raw payload exceeds server limit (10MB). Compute SHA-256 locally on client and submit digest envelope.
429 Too Many Requests Rate limit exceeded (100 req/hr/IP on Free Tier). Back off and retry after the hour window expires.
500 Server Error Transient gateway timeout or blockchain network halt. Retry request with exponential backoff (1s, 2s, 4s).

🐍 End-to-End Pipeline in Python

Copy-paste this complete script to see how data flows from initial sealing, through blockchain polling, to autonomous verification:

pipeline_demo.py
import requests import time BASE_URL = "https://api.proofcore.org" # ===================================================================== # STEP 1: SEAL THE ARTIFACT # ===================================================================== payload = { "payload": { "mode": "inference", "prompt": "Audit Vault.sol for reentrancy vulnerabilities", "output": "Audit complete. Severity: 0 High. Safe for deployment.", "model_id": "claude-3-5-sonnet" }, "title": "Automated Security Audit" } print("[1/4] Sealing output via ProofCore API...") seal_res = requests.post(f"{BASE_URL}/api/v0.1/seal", json=payload).json() deal_id = seal_res["deal_id"] print(f" ✓ Sealed! Deal ID: {deal_id}") print(f" ✓ Notary Signature: {seal_res['signature'][:32]}...") # ===================================================================== # STEP 2: POLL BLOCKCHAIN MANIFEST (TON BATCHING) # ===================================================================== print("\n[2/4] Polling for TON Blockchain Anchor...") for attempt in range(10): proof_res = requests.get(f"{BASE_URL}/api/v0.1/proof/{deal_id}").json() status = proof_res.get("status") if status == "anchored_onchain": print(f" ✓ ANCHORED IN TON!") print(f" ✓ Merkle Root: {proof_res['merkle_root']}") print(f" ✓ TON TX: {proof_res['ton_tx_hash']}") break print(f" • Status is '{status}' (Queued)... waiting 5s") time.sleep(5) # ===================================================================== # STEP 3: DOWNSTREAM AGENT VERIFICATION # ===================================================================== print("\n[3/4] Verifying content as a downstream consumer...") # Append the returned citation marker exactly as downstream systems receive it received_text = payload["payload"]["output"] + seal_res["citation_markdown"] verify_res = requests.post(f"{BASE_URL}/api/v0.1/verify", json={ "content": received_text # deal_id is extracted automatically from marker! }).json() print(f" ✓ Verification Verdict: {verify_res['valid']}") print(f" ✓ Hash Match: {verify_res['checks']['hash_match']}") print(f" ✓ Notary Signature Valid: {verify_res['checks']['signature_valid']}") # ===================================================================== # STEP 4: RETRIEVE NOTARY PUBLIC KEY & DOWNLOAD ZIP # ===================================================================== print("\n[4/4] Fetching notary public key & standalone evidence archive...") pubkey_res = requests.get(f"{BASE_URL}/api/v0.1/pubkey").json() print(f" ✓ Server Ed25519 PubKey: {pubkey_res['public_key']}") print(f" ✓ Standalone Evidence ZIP: {BASE_URL}/api/download/{deal_id}")
03 — Agent Economy

Model Context Protocol (MCP)

ProofCore provides a native, publicly hosted MCP endpoint compatible with Claude Desktop, Cursor IDE, Windsurf, and Claude Code.

Endpoint Configuration
.cursor/mcp.json or claude_desktop_config.json
{ "mcpServers": { "proofcore": { "url": "https://mcp.proofcore.org" } } }
Claude Code One-Liner: claude mcp add proofcore https://mcp.proofcore.org
seal_content

Seals output in RAM, returns deal UUID and invariant citation badge for responses.

verify_content

Parses incoming text with citation markers and validates hash + notary signature.

get_proof_status

Polls deal UUID lifecycle ('queued' ➔ 'anchored_onchain') and returns Merkle root + TON tx.

get_public_key

Fetches Ed25519 public key for local air-gapped signature verification.

04 — CI/CD Supply Chain

GitHub Action & OIDC Notarization

Mitigate supply chain poisoning (SLSA Level 3). The ProofCore Action computes checksums of compiled binaries directly on the runner and binds them to cryptographically signed GitHub OIDC tokens.

.github/workflows/release.yml YAML
name: Release & Cryptographic Notarization on: release: types: [published] jobs: build-and-seal: runs-on: ubuntu-latest permissions: id-token: write # Required: GitHub signs an OIDC JWT proving build provenance contents: write steps: - uses: actions/checkout@v4 - name: Build Binaries run: cargo build --release - name: Notarize on TON Blockchain uses: ProofCore-Protocol/proofcore-action@v1 with: files: "target/release/*" append_badge_to_release: true
05 — Offline Architecture

Standalone Evidence Package (ZIP)

Every transaction generates an autonomous ZIP package. Download via GET /api/download/{deal_id}. Contains everything required to reconstruct the proof completely disconnected from the internet.

proof_package_{id}.zip Directory Structure
proofcore_{deal_id}.zip ├── 📁 1_ORIGINAL_ASSET/ │ └── artifact.bin ← Exact unmodified raw file (or purged_notice.txt under zero-storage) ├── 📁 2_PROOF_DATA/ │ ├── proof.json ← Canonical manifest with RFC 6962 Merkle tree paths │ └── forensic_metadata.json ← Captured headers, agent ID, DNS snapshots, and Ed25519 signature ├── 📁 3_VERIFIERS/ │ ├── verify.py ← Zero-dependency Python CLI verifier │ └── verify.html ← 100% Client-Side WebCrypto HTML verifier (Open in browser) ├── 📁 4_LEGAL_CERTIFICATE/ │ └── Certificate.pdf ← Official Forensic PDF with dual Web & TON QR codes └── 📁 5_README/ └── README_EN.txt ← Mathematical formulas and verification instructions

Offline Verification Execution:

1. verify.py recalculates the SHA-256 hash of the local file in 1_ORIGINAL_ASSET/.
2. It combines the asset hash with forensic_metadata.json to derive the Canonical Deal Hash.
3. It climbs the Merkle tree path defined in proof.json to recompute the local Merkle Root.
4. The calculated root is compared against the raw TON Blockchain block transaction comment (MR: <root>).

Zero-Storage Mode Notice: Under strict zero-storage mode, raw files are omitted from the cloud archive. To execute full 3-way verification, drop your original local file into 1_ORIGINAL_ASSET/ before running the script, or verify the manifest inclusion and notary signature directly.
06 — Mathematical Invariants

Cryptographic Specification (RFC 6962)

The proofcore-merkle-v1 scheme strictly follows RFC 6962 domain separation to prevent length-extension and second-preimage attacks:

RFC 6962 Hashing Invariants
1. Canonical Deal Hash: H_deal = SHA256( canonicalize_json(assets, forensics) ) 2. Leaf Node Hashing (Domain Prefix 0x00): H_leaf = SHA256( 0x00 || bytes.fromhex(H_deal) ) 3. Internal Tree Traversal (Domain Prefix 0x01): If Sibling is on LEFT: H_parent = SHA256( 0x01 || bytes.fromhex(sibling_hash) || bytes.fromhex(current_hash) ) If Sibling is on RIGHT: H_parent = SHA256( 0x01 || bytes.fromhex(current_hash) || bytes.fromhex(sibling_hash) ) 4. On-Chain Ledger Anchor: The calculated H_root is written as a 64-character hex comment to the TON smart contract: Contract Address: EQCSNotK-MOtTfh4_1KBK-0SmIz06zEmniaT8YT1vw3OKlsE Opcode: 0, Payload: "MR: " + H_root
07 — Legal Engineering

Evidentiary & Statutory Alignment

ProofCore primitives are designed to support digital evidence authentication under international legal frameworks:

🇺🇸 US Federal Rules of Evidence (FRE 902)

Structured to support self-authenticating electronic records through verifiable digital identification processes (SHA-256 hash values) under Rule 902(13) and Rule 902(14).

🇪🇺 EU eIDAS 2.0 & e-Evidence

Designed to align with Regulation (EU) 2024/1183 electronic ledgers and timestamping frameworks for establishing data integrity in legal proceedings.

🇪🇺 EU AI Act (Article 50)

Structured to provide machine-readable provenance and transparency metadata for generative AI outputs and algorithmic decisions.

🌐 UNCITRAL MLETR

Supports functional equivalence and data integrity standards recognized under the Model Law on Electronic Transferable Records.

Evidentiary Disclaimer: ProofCore provides technical cryptographic primitives (cryptographic digests, Merkle inclusion paths, Ed25519 signatures, and decentralized timestamps). ProofCore does not evaluate factual truthfulness, and final legal admissibility is determined solely by the presiding court under applicable procedural law.