Skip to content

Trust Lists ​

The signed trust lists, the anchor log and the files they reference — static, public, no authentication.

Real network
https://trust.tamga.network
Sandbox (test network; `environment` = `sandbox`)
https://trust.sandbox.tamga.network
Authentication
None — public
Definition
OpenAPI 3.1 file · Guide

Every file is static and public (CORS *, cached for 5 minutes; archive files are immutable). The .jws files are compact JWS (alg: ES256, typ: tamga-tl+jwt, x5c = list signing certificate) — verify only the .jws; the .json copies are for people to read. Each list has a monotonic version, a previous_version_hash chain and a next_update date (at most 90 days); a change is published within 24 hours.

In code, do not read these files yourself: use TrustSource from @tamga-network/trust, which checks the signature against the pinned root fingerprints, the hash chain, the format version and freshness. The field-by-field format is in SPEC-TRUST-0001.

Endpoints ​

EndpointDescription
GET /lotl.jwsGet the list of lists (signed)
GET /lotl.jsonGet the list of lists (readable copy)
GET /tl-{cc}.jwsGet a national list (signed)
GET /tl-{cc}.jsonGet a national list (readable copy)
GET /keys/root-fingerprints.jsonGet the root fingerprints
GET /keys/{name}.cert.pemGet a certificate referenced by a list
GET /wrprc/index.jsonList the registration certificates
GET /zk/{circuit_id}.zstDownload a ZK circuit
GET /anchors.jsonlGet the anchor log
GET /archive/{file}Get an archived version
GET /CHANGELOG.mdGet the list change log

Authentication ​

No authentication: every endpoint is public.

Lists ​

The list of lists and the national lists.

Get the list of lists (signed) ​

GET/lotl.jws

The top-level list: national list slots and their signing keys, network-level schemas, wallet providers, credential categories, accepted ZK circuits, the catalogue address. Verify the x5c[0] fingerprint against keys/root-fingerprints.json (and the value you pinned in your configuration).

Authentication None — public

Responses ​

StatusDescription
200Compact JWS; the payload is Lotl.

Example ​

bash
curl "https://trust.tamga.network/lotl.jws"
text
eyJhbGciOiJFUzI1NiIsInR5cCI6InRhbWdhLXRsK2p3dCIsIng1YyI6WyLigKYiXX0.eyJsaXN0X3R5cGUiOiJsb3RsIn0.…

Get the list of lists (readable copy) ​

GET/lotl.json

The same content as lotl.jws, unsigned. For people and debugging only.

Authentication None — public

Responses ​

StatusDescription
200The list. Returns Lotl

Example ​

bash
curl "https://trust.tamga.network/lotl.json"
json
{
  "list_format_version": "1.0",
  "list_type": "lotl",
  "environment": "production",
  "version": 69,
  "issued_at": "2026-10-09T12:00:00Z",
  "next_update": "2026-10-09T12:00:00Z",
  "previous_version_hash": "sha256:5ec0…",
  "operator": {
    "name": "…",
    "status": "provisional",
    "on_behalf_of": "…",
    "trust_framework": "https://example.org"
  },
  "catalogue": {
    "url": "https://schemas.tamga.network/v1/catalogue.json"
  },
  "national_lists": [
    {
      "state_code": "TR",
      "status": "ACTIVE",
      "list_url": "https://example.org",
      "signing_keys": [
        {
          "fingerprint_sha256": null,
          "cert_ref": null,
          "status": null
        }
      ]
    }
  ],
  "schemas": [
    {}
  ],
  "wallet_providers": [
    {}
  ],
  "zk_circuits": [
    {
      "circuit_id": "…",
      "system": "longfellow-libzk-v1",
      "version": 0,
      "sha256": "…",
      "status": "…"
    }
  ]
}

Get a national list (signed) ​

GET/tl-{cc}.jws

A national list: root CAs, issuers (with their authorised credential types and status list base), relying parties (with their registered scopes), national schemas. Signed with a key listed in lotl.national_lists[].signing_keys. Today only tl-tr is published; the other member-state slots are reserved.

Authentication None — public

Parameters ​

NameInTypeDescription
cc requiredpathstringLower-case country code. One of: tr

Responses ​

StatusDescription
200Compact JWS; the payload is NationalList.
404No list is published for this country yet.

Example ​

bash
curl "https://trust.tamga.network/tl-tr.jws"
text
…

Get a national list (readable copy) ​

GET/tl-{cc}.json

The same content as tl-{cc}.jws, unsigned.

Authentication None — public

Parameters ​

NameInTypeDescription
cc requiredpathstringOne of: tr

Responses ​

StatusDescription
200The list. Returns NationalList

Example ​

bash
curl "https://trust.tamga.network/tl-tr.json"
json
{
  "list_type": "trusted_list",
  "state_code": "TR",
  "version": 0,
  "issued_at": "2026-10-09T12:00:00Z",
  "next_update": "2026-10-09T12:00:00Z",
  "root_cas": [
    {}
  ],
  "issuers": [
    {
      "issuer_id": "…",
      "slug": "…",
      "legal_name": "…",
      "class": "PUB",
      "issuer_url": "https://example.org",
      "status_list_base": "https://example.org",
      "status": "ACTIVE",
      "schema_authorizations": [
        {}
      ]
    }
  ],
  "relying_parties": [
    {
      "client_id": "…",
      "dns_name": "…",
      "legal_name": "…",
      "status": "…",
      "scopes": [
        {}
      ]
    }
  ],
  "national_schemas": [
    {}
  ]
}

Get the list change log ​

GET/CHANGELOG.md

A human-readable log of what changed in each published version.

Authentication None — public

Responses ​

StatusDescription
200Markdown.

Example ​

bash
curl "https://trust.tamga.network/CHANGELOG.md"

Keys and certificates ​

Root fingerprints, certificates, registration certificates, ZK circuits.

Get the root fingerprints ​

GET/keys/root-fingerprints.json

The SHA-256 fingerprints of the list signing certificates and of the national root CAs — the top of the chain of trust. The same values are published at tamga.network/trust-anchor and in the Trust Framework; pin them in your configuration rather than trusting this file alone.

Authentication None — public

Responses ​

StatusDescription
200Fingerprints. Returns RootFingerprints

Example ​

bash
curl "https://trust.tamga.network/keys/root-fingerprints.json"
json
{
  "note": "…",
  "lotl_signing_keys": [
    {
      "fingerprint_sha256": "7fd176d58fd3fba3bdea137374d6ae3dc8ffc8dcb9b645c2b08566464764fdc1",
      "cert_ref": "tl-signer-1",
      "status": "ACTIVE"
    }
  ],
  "national_root_cas": [
    {
      "ca_id": "…",
      "legal_name": "…",
      "cert_fingerprint_sha256": "…"
    }
  ]
}

Get a certificate referenced by a list ​

GET/keys/{name}.cert.pem

Only certificates the lists reference (operator, root, registrar, relying party) are published here; name is the cert_ref value in the list.

Authentication None — public

Parameters ​

NameInTypeDescription
name requiredpathstring

Responses ​

StatusDescription
200PEM certificate.
404Unknown certificate.

Example ​

bash
curl "https://trust.tamga.network/keys/tl-signer-1.cert.pem"

List the registration certificates ​

GET/wrprc/index.json

Index of the registration certificates (ETSI TS 119 475 rc-wrp+jwt) issued for every valid relying party use and every issuer (ADR-0026). Each item's path is the certificate file under this host. Signed with the registrar key listed in lotl.national_lists[].roles.registrar.signing_keys.

Authentication None — public

Responses ​

StatusDescription
200Index.

Example ​

bash
curl "https://trust.tamga.network/wrprc/index.json"
json
{
  "generated_at": "2026-10-09T12:00:00Z",
  "items": [
    {
      "path": "…",
      "exp": "2026-10-09T12:00:00Z"
    }
  ]
}

Download a ZK circuit ​

GET/zk/{circuit_id}.zst

The zero-knowledge circuit files listed in lotl.zk_circuits (ADR-0032). Wallets download them and check zk_circuits[].sha256 before use.

Authentication None — public

Parameters ​

NameInTypeDescription
circuit_id requiredpathstring

Responses ​

StatusDescription
200zstd-compressed circuit.

Example ​

bash
curl "https://trust.tamga.network/zk/{circuit_id}.zst"

Anchor log and archive ​

The hourly anchor log and the immutable version archive.

Get the anchor log ​

GET/anchors.jsonl

One signed JWS per line, in time order: status list publications (kind: status_list), schema registrations (kind: schema), hourly heartbeats and archive checkpoints. Each line links to the previous one with previous_hash. Records only list identifiers and content digests — never personal data.

Authentication None — public

Responses ​

StatusDescription
200Newline-delimited JWS; each payload is an AnchorEntry. Returns AnchorEntry

Example ​

bash
curl "https://trust.tamga.network/anchors.jsonl"
json
{
  "seq": 16902,
  "previous_hash": "sha256:df9370353f7c4f1730a28affba41bce711b3a0335e3c402f8e11af30d5299679",
  "ts": "2026-10-08T23:02:04.428Z",
  "kind": "status_list",
  "list_id": "0x00000000000000000000000000000000000000000000000088565603be702c85",
  "issuer_id": "0xab180a99995cd80e330f38e470691dd1c39f7861bf3a76a0c04ed8deb7bb86e9",
  "list_uri": "https://id.tamga.network/status/88565603be702c85",
  "content_hash": "sha256:82d6ebd236d760b617f5f7840223ad5368e5394750d02d740502e9056dd7ccb4",
  "list_version": 6901,
  "published_at": "2026-10-08T23:02:04.422Z"
}

Get an archived version ​

GET/archive/{file}

Every published list version (lotl.v0068.jws, tl-tr.v0068.jws) and every archived slice of the anchor log (anchors-<from>-<to>.jsonl). Immutable; nothing is deleted. Used to replay the full history.

Authentication None — public

Parameters ​

NameInTypeDescription
file requiredpathstring

Responses ​

StatusDescription
200The archived file.
404No such version.

Example ​

bash
curl "https://trust.tamga.network/archive/lotl.v0068.jws"
text
…

Objects ​

Lotl ​

Main fields; the full format is in SPEC-TRUST-0001 §3.

FieldTypeDescription
list_format_versionstringUnknown version → stop.
list_typestringAlways lotl
environmentstringAbsent means production. One of: production · sandbox
versioninteger
issued_atstring (date-time)
next_updatestring (date-time)
previous_version_hashstring
operatorobject
operator.namestring
operator.statusstring
operator.on_behalf_ofstring
operator.trust_frameworkstring (uri)
catalogueobject
catalogue.urlstring (uri)
national_listsarray<object>
national_lists[].state_codestring
national_lists[].statusstringOne of: ACTIVE · RESERVED
national_lists[].list_urlstring (uri)
national_lists[].signing_keysarray<KeyRef>
schemasarray<object>Network-level credential types.
wallet_providersarray<object>
zk_circuitsarray<object>
zk_circuits[].circuit_idstring
zk_circuits[].systemstring
zk_circuits[].versioninteger
zk_circuits[].sha256string
zk_circuits[].statusstring

NationalList ​

Main fields; the full format is in SPEC-TRUST-0001 §4.

FieldTypeDescription
list_typestringAlways trusted_list
state_codestring
versioninteger
issued_atstring (date-time)
next_updatestring (date-time)
root_casarray<object>
issuersarray<object>
issuers[].issuer_idstring
issuers[].slugstring
issuers[].legal_namestring
issuers[].classstringOne of: PUB · QUALIFIED · EAA
issuers[].issuer_urlstring (uri)
issuers[].status_list_basestring (uri)
issuers[].statusstringOne of: ACTIVE · SUSPENDED · REVOKED · RETIRED
issuers[].schema_authorizationsarray<object>
relying_partiesarray<object>
relying_parties[].client_idstringx509_hash:…
relying_parties[].dns_namestring
relying_parties[].legal_namestring
relying_parties[].statusstring
relying_parties[].scopesarray<object>
national_schemasarray<object>

RootFingerprints ​

FieldTypeDescription
notestring
lotl_signing_keysarray<KeyRef>
national_root_casarray<object>
national_root_cas[].ca_idstring
national_root_cas[].legal_namestring
national_root_cas[].cert_fingerprint_sha256string

KeyRef ​

FieldTypeDescription
fingerprint_sha256string
cert_refstring
statusstring

AnchorEntry ​

Payload of one anchor log line; the full format is in SPEC-TRUST-0001 §5.

FieldTypeDescription
seqinteger
previous_hashstring
tsstring (date-time)
kindstringOne of: status_list · schema · heartbeat · checkpoint
list_idstring
issuer_idstring
list_uristring (uri)
content_hashstring
list_versioninteger
published_atstring (date-time)

Import the machine-readable definition into any OpenAPI tool to generate a client or send test requests: trust-lists.openapi.yaml.