Trust Lists
The signed trust lists, the anchor log and the files they reference — static, public, no authentication.
- Real network
https://trust.tamga.network- Sandbox (test network; `environment` = `sandbox`)
https://trust.sandbox.tamga.network- Authentication
- None — public
- Definition
- OpenAPI 3.1 file · Guide
Every file is static and public (CORS *, cached for 5 minutes; archive files are immutable). The .jws files are compact JWS (alg: ES256, typ: tamga-tl+jwt, x5c = list signing certificate) — verify only the .jws; the .json copies are for people to read. Each list has a monotonic version, a previous_version_hash chain and a next_update date (at most 90 days); a change is published within 24 hours.
In code, do not read these files yourself: use TrustSource from @tamga-network/trust, which checks the signature against the pinned root fingerprints, the hash chain, the format version and freshness. The field-by-field format is in SPEC-TRUST-0001.
Endpoints
| Endpoint | Description |
|---|---|
GET /lotl.jws | Get the list of lists (signed) |
GET /lotl.json | Get the list of lists (readable copy) |
GET /tl-{cc}.jws | Get a national list (signed) |
GET /tl-{cc}.json | Get a national list (readable copy) |
GET /keys/root-fingerprints.json | Get the root fingerprints |
GET /keys/{name}.cert.pem | Get a certificate referenced by a list |
GET /wrprc/index.json | List the registration certificates |
GET /zk/{circuit_id}.zst | Download a ZK circuit |
GET /anchors.jsonl | Get the anchor log |
GET /archive/{file} | Get an archived version |
GET /CHANGELOG.md | Get the list change log |
Authentication
No authentication: every endpoint is public.
Lists
The list of lists and the national lists.
Get the list of lists (signed)
/lotl.jwsThe top-level list: national list slots and their signing keys, network-level schemas, wallet providers, credential categories, accepted ZK circuits, the catalogue address. Verify the x5c[0] fingerprint against keys/root-fingerprints.json (and the value you pinned in your configuration).
Authentication None — public
Responses
| Status | Description |
|---|---|
| 200 | Compact JWS; the payload is Lotl. |
Example
curl "https://trust.tamga.network/lotl.jws"eyJhbGciOiJFUzI1NiIsInR5cCI6InRhbWdhLXRsK2p3dCIsIng1YyI6WyLigKYiXX0.eyJsaXN0X3R5cGUiOiJsb3RsIn0.…Get the list of lists (readable copy)
/lotl.jsonThe same content as lotl.jws, unsigned. For people and debugging only.
Authentication None — public
Responses
| Status | Description |
|---|---|
| 200 | The list. Returns Lotl |
Example
curl "https://trust.tamga.network/lotl.json"{
"list_format_version": "1.0",
"list_type": "lotl",
"environment": "production",
"version": 69,
"issued_at": "2026-10-09T12:00:00Z",
"next_update": "2026-10-09T12:00:00Z",
"previous_version_hash": "sha256:5ec0…",
"operator": {
"name": "…",
"status": "provisional",
"on_behalf_of": "…",
"trust_framework": "https://example.org"
},
"catalogue": {
"url": "https://schemas.tamga.network/v1/catalogue.json"
},
"national_lists": [
{
"state_code": "TR",
"status": "ACTIVE",
"list_url": "https://example.org",
"signing_keys": [
{
"fingerprint_sha256": null,
"cert_ref": null,
"status": null
}
]
}
],
"schemas": [
{}
],
"wallet_providers": [
{}
],
"zk_circuits": [
{
"circuit_id": "…",
"system": "longfellow-libzk-v1",
"version": 0,
"sha256": "…",
"status": "…"
}
]
}Get a national list (signed)
/tl-{cc}.jwsA national list: root CAs, issuers (with their authorised credential types and status list base), relying parties (with their registered scopes), national schemas. Signed with a key listed in lotl.national_lists[].signing_keys. Today only tl-tr is published; the other member-state slots are reserved.
Authentication None — public
Parameters
| Name | In | Type | Description |
|---|---|---|---|
cc required | path | string | Lower-case country code. One of: tr |
Responses
| Status | Description |
|---|---|
| 200 | Compact JWS; the payload is NationalList. |
| 404 | No list is published for this country yet. |
Example
curl "https://trust.tamga.network/tl-tr.jws"…Get a national list (readable copy)
/tl-{cc}.jsonThe same content as tl-{cc}.jws, unsigned.
Authentication None — public
Parameters
| Name | In | Type | Description |
|---|---|---|---|
cc required | path | string | One of: tr |
Responses
| Status | Description |
|---|---|
| 200 | The list. Returns NationalList |
Example
curl "https://trust.tamga.network/tl-tr.json"{
"list_type": "trusted_list",
"state_code": "TR",
"version": 0,
"issued_at": "2026-10-09T12:00:00Z",
"next_update": "2026-10-09T12:00:00Z",
"root_cas": [
{}
],
"issuers": [
{
"issuer_id": "…",
"slug": "…",
"legal_name": "…",
"class": "PUB",
"issuer_url": "https://example.org",
"status_list_base": "https://example.org",
"status": "ACTIVE",
"schema_authorizations": [
{}
]
}
],
"relying_parties": [
{
"client_id": "…",
"dns_name": "…",
"legal_name": "…",
"status": "…",
"scopes": [
{}
]
}
],
"national_schemas": [
{}
]
}Get the list change log
/CHANGELOG.mdA human-readable log of what changed in each published version.
Authentication None — public
Responses
| Status | Description |
|---|---|
| 200 | Markdown. |
Example
curl "https://trust.tamga.network/CHANGELOG.md"Keys and certificates
Root fingerprints, certificates, registration certificates, ZK circuits.
Get the root fingerprints
/keys/root-fingerprints.jsonThe SHA-256 fingerprints of the list signing certificates and of the national root CAs — the top of the chain of trust. The same values are published at tamga.network/trust-anchor and in the Trust Framework; pin them in your configuration rather than trusting this file alone.
Authentication None — public
Responses
| Status | Description |
|---|---|
| 200 | Fingerprints. Returns RootFingerprints |
Example
curl "https://trust.tamga.network/keys/root-fingerprints.json"{
"note": "…",
"lotl_signing_keys": [
{
"fingerprint_sha256": "7fd176d58fd3fba3bdea137374d6ae3dc8ffc8dcb9b645c2b08566464764fdc1",
"cert_ref": "tl-signer-1",
"status": "ACTIVE"
}
],
"national_root_cas": [
{
"ca_id": "…",
"legal_name": "…",
"cert_fingerprint_sha256": "…"
}
]
}Get a certificate referenced by a list
/keys/{name}.cert.pemOnly certificates the lists reference (operator, root, registrar, relying party) are published here; name is the cert_ref value in the list.
Authentication None — public
Parameters
| Name | In | Type | Description |
|---|---|---|---|
name required | path | string |
Responses
| Status | Description |
|---|---|
| 200 | PEM certificate. |
| 404 | Unknown certificate. |
Example
curl "https://trust.tamga.network/keys/tl-signer-1.cert.pem"List the registration certificates
/wrprc/index.jsonIndex of the registration certificates (ETSI TS 119 475 rc-wrp+jwt) issued for every valid relying party use and every issuer (ADR-0026). Each item's path is the certificate file under this host. Signed with the registrar key listed in lotl.national_lists[].roles.registrar.signing_keys.
Authentication None — public
Responses
| Status | Description |
|---|---|
| 200 | Index. |
Example
curl "https://trust.tamga.network/wrprc/index.json"{
"generated_at": "2026-10-09T12:00:00Z",
"items": [
{
"path": "…",
"exp": "2026-10-09T12:00:00Z"
}
]
}Download a ZK circuit
/zk/{circuit_id}.zstThe zero-knowledge circuit files listed in lotl.zk_circuits (ADR-0032). Wallets download them and check zk_circuits[].sha256 before use.
Authentication None — public
Parameters
| Name | In | Type | Description |
|---|---|---|---|
circuit_id required | path | string |
Responses
| Status | Description |
|---|---|
| 200 | zstd-compressed circuit. |
Example
curl "https://trust.tamga.network/zk/{circuit_id}.zst"Anchor log and archive
The hourly anchor log and the immutable version archive.
Get the anchor log
/anchors.jsonlOne signed JWS per line, in time order: status list publications (kind: status_list), schema registrations (kind: schema), hourly heartbeats and archive checkpoints. Each line links to the previous one with previous_hash. Records only list identifiers and content digests — never personal data.
Authentication None — public
Responses
| Status | Description |
|---|---|
| 200 | Newline-delimited JWS; each payload is an AnchorEntry. Returns AnchorEntry |
Example
curl "https://trust.tamga.network/anchors.jsonl"{
"seq": 16902,
"previous_hash": "sha256:df9370353f7c4f1730a28affba41bce711b3a0335e3c402f8e11af30d5299679",
"ts": "2026-10-08T23:02:04.428Z",
"kind": "status_list",
"list_id": "0x00000000000000000000000000000000000000000000000088565603be702c85",
"issuer_id": "0xab180a99995cd80e330f38e470691dd1c39f7861bf3a76a0c04ed8deb7bb86e9",
"list_uri": "https://id.tamga.network/status/88565603be702c85",
"content_hash": "sha256:82d6ebd236d760b617f5f7840223ad5368e5394750d02d740502e9056dd7ccb4",
"list_version": 6901,
"published_at": "2026-10-08T23:02:04.422Z"
}Get an archived version
/archive/{file}Every published list version (lotl.v0068.jws, tl-tr.v0068.jws) and every archived slice of the anchor log (anchors-<from>-<to>.jsonl). Immutable; nothing is deleted. Used to replay the full history.
Authentication None — public
Parameters
| Name | In | Type | Description |
|---|---|---|---|
file required | path | string |
Responses
| Status | Description |
|---|---|
| 200 | The archived file. |
| 404 | No such version. |
Example
curl "https://trust.tamga.network/archive/lotl.v0068.jws"…Objects
Lotl
Main fields; the full format is in SPEC-TRUST-0001 §3.
| Field | Type | Description |
|---|---|---|
list_format_version | string | Unknown version → stop. |
list_type | string | Always lotl |
environment | string | Absent means production. One of: production · sandbox |
version | integer | |
issued_at | string (date-time) | |
next_update | string (date-time) | |
previous_version_hash | string | |
operator | object | |
operator.name | string | |
operator.status | string | |
operator.on_behalf_of | string | |
operator.trust_framework | string (uri) | |
catalogue | object | |
catalogue.url | string (uri) | |
national_lists | array<object> | |
national_lists[].state_code | string | |
national_lists[].status | string | One of: ACTIVE · RESERVED |
national_lists[].list_url | string (uri) | |
national_lists[].signing_keys | array<KeyRef> | |
schemas | array<object> | Network-level credential types. |
wallet_providers | array<object> | |
zk_circuits | array<object> | |
zk_circuits[].circuit_id | string | |
zk_circuits[].system | string | |
zk_circuits[].version | integer | |
zk_circuits[].sha256 | string | |
zk_circuits[].status | string |
NationalList
Main fields; the full format is in SPEC-TRUST-0001 §4.
| Field | Type | Description |
|---|---|---|
list_type | string | Always trusted_list |
state_code | string | |
version | integer | |
issued_at | string (date-time) | |
next_update | string (date-time) | |
root_cas | array<object> | |
issuers | array<object> | |
issuers[].issuer_id | string | |
issuers[].slug | string | |
issuers[].legal_name | string | |
issuers[].class | string | One of: PUB · QUALIFIED · EAA |
issuers[].issuer_url | string (uri) | |
issuers[].status_list_base | string (uri) | |
issuers[].status | string | One of: ACTIVE · SUSPENDED · REVOKED · RETIRED |
issuers[].schema_authorizations | array<object> | |
relying_parties | array<object> | |
relying_parties[].client_id | string | x509_hash:… |
relying_parties[].dns_name | string | |
relying_parties[].legal_name | string | |
relying_parties[].status | string | |
relying_parties[].scopes | array<object> | |
national_schemas | array<object> |
RootFingerprints
| Field | Type | Description |
|---|---|---|
note | string | |
lotl_signing_keys | array<KeyRef> | |
national_root_cas | array<object> | |
national_root_cas[].ca_id | string | |
national_root_cas[].legal_name | string | |
national_root_cas[].cert_fingerprint_sha256 | string |
KeyRef
| Field | Type | Description |
|---|---|---|
fingerprint_sha256 | string | |
cert_ref | string | |
status | string |
AnchorEntry
Payload of one anchor log line; the full format is in SPEC-TRUST-0001 §5.
| Field | Type | Description |
|---|---|---|
seq | integer | |
previous_hash | string | |
ts | string (date-time) | |
kind | string | One of: status_list · schema · heartbeat · checkpoint |
list_id | string | |
issuer_id | string | |
list_uri | string (uri) | |
content_hash | string | |
list_version | integer | |
published_at | string (date-time) |
Import the machine-readable definition into any OpenAPI tool to generate a client or send test requests: trust-lists.openapi.yaml.