{
  "module": "register",
  "version": "1.2.0",
  "suite_version": "oaas-checks-1",
  "what_this_is": "A registry that publishes proofs about its own behaviour. Absence proofs show a domain was not listed on a date. RFC 6962 consistency proofs show no entry was inserted behind an earlier position. Revocations are sealed rather than deleted, so a removed listing stays readable.",
  "why_that_matters": "Every other registry is a mutable database whose operator can add, back-date or quietly delete entries. Trusting the list means trusting the registrar. This one is checkable against its own operator.",
  "what_this_is_not": [
    "Not a certification. Nobody has been certified by anyone.",
    "Not a statement that any law applies to a listed domain, or that a listed domain satisfies it. Whether a regulation applies to an organisation is a question for that organisation's own advisers.",
    "Not an audit. No third party has audited this registry or any domain on it.",
    "Not a claim about anything a domain did not seal. A check observes what is served at a URL at a moment in time."
  ],
  "status_vocabulary": {
    "unverified": "The domain proved control and is listed. The check suite has not been run against it yet.",
    "checks-passed": "Every check in suite oaas-checks-1 returned pass on the date shown. This describes what the checks observed on that date and nothing else.",
    "checks-failed": "At least one check did not pass. The failing check names are published.",
    "stale": "The last successful check is more than 90 days old. Nothing was withdrawn; the evidence simply aged.",
    "withdrawn": "The domain asked to be removed. The listing history remains readable.",
    "revoked": "The operator removed the listing. The reason is sealed alongside it and the history remains readable."
  },
  "how_to_get_listed": [
    "Simplest, nothing to edit: if your manifest already carries a `Domain: <yourdomain>` line matching the domain you are claiming, POST /x/register/claim and you are listed. A manifest served from your domain naming your domain could only have been published by you.",
    "If your manifest does not name itself, use the token route instead:",
    "1. POST /x/register/challenge with {\"domain\": \"example.com\"} \u2014 returns a one-time token.",
    "2. Serve that token at https://example.com/.well-known/aileash-register.txt, or add a `Register-Token: <token>` line to your manifest at /.well-known/ai.txt or /ai.txt",
    "Any token issued in the last 24 hours will verify \u2014 asking for a new one does not invalidate one you already published. See /x/register/tokens?domain=example.com",
    "3. POST /x/register/claim with {\"domain\": \"example.com\"} \u2014 we fetch, verify, run the checks and seal the result.",
    "Opt out at any time with a `Register: no` line in the manifest \u2014 the register refuses the claim and says so.",
    "Nobody is listed by the operator. A domain lists itself by proving it controls the domain."
  ],
  "manifest_paths_tried": [
    "/.well-known/ai.txt",
    "/ai.txt"
  ],
  "field_aliases": {
    "chain_tip_url": [
      "chain-tip-url",
      "chain-head",
      "witness-tip",
      "chain-anchor"
    ],
    "verifier": [
      "verifier",
      "verify-chain",
      "consistency-proof",
      "self-check"
    ],
    "contact": [
      "contact",
      "security-contact"
    ]
  },
  "checks_run": [
    "ai_txt_reachable",
    "ai_txt_declares_required_fields",
    "chain_tip_served",
    "chain_tip_is_sha256",
    "verifier_named"
  ],
  "trees": {
    "event_tree": "RFC 6962 ordered tree over every register event in write order. Answers append-only. Verifies with any standard Certificate Transparency verifier.",
    "domain_tree": "Sorted tree over the domains listed at a checkpoint, odd nodes promoted, domain-separated prefixes. Answers absence.",
    "note": "The two roots answer different questions and deliberately never match."
  },
  "proof_of_control": {
    "preferred": "manifest-self-declaration (a Domain: line naming itself)",
    "fallback": "one-time token served at a path we name",
    "opt_out": "a `Register: no` line in the manifest"
  },
  "stale_after_days": 90,
  "challenge_ttl_seconds": 86400,
  "routes": {
    "public": [
      "GET /x/register/absence",
      "GET /x/register/checkpoints",
      "GET /x/register/consistency",
      "GET /x/register/entry",
      "GET /x/register/history",
      "GET /x/register/inclusion",
      "GET /x/register/list",
      "GET /x/register/roots",
      "GET /x/register/sealcheck",
      "GET /x/register/spec",
      "GET /x/register/tokens",
      "GET /x/register/vocabulary",
      "POST /x/register/challenge",
      "POST /x/register/claim",
      "POST /x/register/recheck",
      "POST /x/register/withdraw"
    ],
    "keyed": [
      "POST /x/register/recheck-all",
      "POST /x/register/checkpoint",
      "POST /x/register/revoke"
    ]
  },
  "honest_limits": [
    "A check observes what a URL served at a moment in time. It cannot know what a domain did not seal.",
    "Domain control proves control of the domain, not the truth of anything the domain declares.",
    "Absence proofs are only as good as the checkpoint they are made against. A period with no checkpoint has nothing to prove absence from.",
    "Nobody can be forced to keep publishing. A listing goes stale when the evidence ages, and that is the honest outcome rather than a failure of the register."
  ]
}