Export a ledger subject as STIX 2.1
Requires a workspace-bound API key with ledger:read. Projects the subject's fold to a STIX 2.1 bundle: identity objects for subjects, cyber-observable objects for email, handle, domain, hostname, URL, and ASN designators, and relationship objects for claims with confidence, start_time, stop_time, and the cited observations as external references. Verification state and the claim key travel in a property extension. An unconfirmed same-as exports as related-to; duplicate-of and attributed-to are never emitted. history=true adds retracted heads as revoked relationships. STIX ids carry the SHA-256 digest of a per-workspace key in UUID form, so they are stable and do not reveal the workspace. An explicit validAt cursor scopes object IDs to that valid-time snapshot. A reassertion after revocation starts a new relationship ID. If the bounded subject neighborhood is incomplete, returns HTTP 400 VALIDATION_ERROR; export the paginated ledger records and project the complete log offline instead.