Y2 Elite workspaces are rolling out for teams
Y2Y2Docs
Ontology & Fusion

Export STIX and Verify the Seal

Share ledger claims as STIX 2.1, export the sealed log, and prove offline that no line was edited

Export a subject as STIX 2.1

In the app, choose Export STIX 2.1 in the ledger panel. It downloads a bundle for the subject at the Valid on date you set.

Through the API, with ledger:read:

curl --get "https://api.y2.dev/api/v2/ledger/subjects/sbj_0123456789abcdef01234567/stix" \
  --header "Authorization: Bearer $Y2_API_KEY" \
  --data-urlencode "history=true" > northwind.stix.json

history=true adds retracted claims as relationships with revoked: true. Without it, the bundle holds only live claims. See STIX 2.1 export for the mapping.

An incomplete subject neighborhood returns 400 VALIDATION_ERROR instead of a partial bundle. Export the complete sealed log below, then run bun packages/ontology/src/cli.ts stix ledger.ndjson to project it offline.

Export the sealed log

Page through the log with afterSeq. The log is append-only, so continuing from meta.nextAfterSeq never skips or repeats a line:

after=0
: > ledger.ndjson
while :; do
  page=$(curl --silent --get "https://api.y2.dev/api/v2/ledger/records" \
    --header "Authorization: Bearer $Y2_API_KEY" \
    --data-urlencode "afterSeq=$after" --data-urlencode "limit=200")
  echo "$page" | jq -r '.data[].line' >> ledger.ndjson
  after=$(echo "$page" | jq '.meta.nextAfterSeq')
  [ "$(echo "$page" | jq '.meta.hasMore')" = "true" ] || break
done

Each line is the exact canonical text that was sealed. Write it byte for byte; do not reformat it.

Check the export offline

The reference checker ships in the portable @y2/ontology package. From the root of the Y2 repository:

bun packages/ontology/src/cli.ts check ledger.ndjson

It verifies canonical JSON, each line's SHA-256, the prev chain, strictly increasing record time, and every rule in the record format. It prints ok or one line per problem with its rule code. fold and stix subcommands read the same file with --recorded-at and --valid-at cursors.

Verify the seal in place

To check the stored log without exporting it, verify windows of the seal:

curl --get "https://api.y2.dev/api/v2/ledger/verify" \
  --header "Authorization: Bearer $Y2_API_KEY" \
  --data-urlencode "afterSeq=0" --data-urlencode "limit=200"

The response reports ok, the number of lines checked, and any problems by seq. Continue from meta.nextAfterSeq until hasMore is false. Seal verification recomputes hashes and links; rules that look up earlier records are enforced at append time and by the offline checker.