Export STIX and Verify the Seal
Share ledger claims as STIX 2.1, export the sealed log, and prove offline that no line was edited
Export a subject as STIX 2.1
In the app, choose Export STIX 2.1 in the ledger panel. It downloads a bundle for the subject at the Valid on date you set.
Through the API, with ledger:read:
curl --get "https://api.y2.dev/api/v2/ledger/subjects/sbj_0123456789abcdef01234567/stix" \
--header "Authorization: Bearer $Y2_API_KEY" \
--data-urlencode "history=true" > northwind.stix.jsonhistory=true adds retracted claims as relationships with revoked: true. Without it, the bundle
holds only live claims. See STIX 2.1 export for the mapping.
An incomplete subject neighborhood returns 400 VALIDATION_ERROR instead of a partial bundle.
Export the complete sealed log below, then run bun packages/ontology/src/cli.ts stix ledger.ndjson
to project it offline.
Export the sealed log
Page through the log with afterSeq. The log is append-only, so continuing from meta.nextAfterSeq
never skips or repeats a line:
after=0
: > ledger.ndjson
while :; do
page=$(curl --silent --get "https://api.y2.dev/api/v2/ledger/records" \
--header "Authorization: Bearer $Y2_API_KEY" \
--data-urlencode "afterSeq=$after" --data-urlencode "limit=200")
echo "$page" | jq -r '.data[].line' >> ledger.ndjson
after=$(echo "$page" | jq '.meta.nextAfterSeq')
[ "$(echo "$page" | jq '.meta.hasMore')" = "true" ] || break
doneEach line is the exact canonical text that was sealed. Write it byte for byte; do not reformat it.
Check the export offline
The reference checker ships in the portable @y2/ontology package. From the root of the Y2
repository:
bun packages/ontology/src/cli.ts check ledger.ndjsonIt verifies canonical JSON, each line's SHA-256, the prev chain, strictly increasing record time,
and every rule in the record format. It prints ok or one
line per problem with its rule code. fold and stix subcommands read the same file with
--recorded-at and --valid-at cursors.
Verify the seal in place
To check the stored log without exporting it, verify windows of the seal:
curl --get "https://api.y2.dev/api/v2/ledger/verify" \
--header "Authorization: Bearer $Y2_API_KEY" \
--data-urlencode "afterSeq=0" --data-urlencode "limit=200"The response reports ok, the number of lines checked, and any problems by seq. Continue from
meta.nextAfterSeq until hasMore is false. Seal verification recomputes hashes and links; rules that
look up earlier records are enforced at append time and by the offline checker.