# Proof, vaults, receipts and passports

Paths on this page are relative to <code>/api/liquidity-studio/v2</code>. Authentication and required headers vary by operation.

[API reference overview](/api-reference/overview/) · [OpenAPI download](/openapi/liquidity-operating-system-v2.openapi.json)

## Operations on this page

| Method | Path | Operation |
| --- | --- | --- |
| <code>GET</code> | <code>/passports</code> | [listPassports](#listPassports) |
| <code>POST</code> | <code>/passports</code> | [publishLiquidityPassport](#publishLiquidityPassport) |
| <code>GET</code> | <code>/passports/{id}</code> | [getPassports](#getPassports) |
| <code>GET</code> | <code>/vaults</code> | [listQualifiedVaultsV2](#listQualifiedVaultsV2) |
| <code>GET</code> | <code>/vaults/{id}</code> | [getQualifiedVaultV2](#getQualifiedVaultV2) |
| <code>GET</code> | <code>/receipts</code> | [listExecutionReceiptsV2](#listExecutionReceiptsV2) |
| <code>GET</code> | <code>/receipts/{id}</code> | [getExecutionReceiptV2](#getExecutionReceiptV2) |
| <code>GET</code> | <code>/proof</code> | [listProofV2](#listProofV2) |
| <code>POST</code> | <code>/passports/{id}/revoke</code> | [revokeLiquidityPassport](#revokeLiquidityPassport) |
| <code>GET</code> | <code>/public/passports/{slug}</code> | [getPublicLiquidityPassport](#getPublicLiquidityPassport) |
| <code>GET</code> | <code>/public/passports/{slug}/formats/{format}</code> | [downloadPublicLiquidityPassport](#downloadPublicLiquidityPassport) |
| <code>GET</code> | <code>/public/passports/{slug}/verification-bundle</code> | [downloadLiquidityPassportVerificationBundle](#downloadLiquidityPassportVerificationBundle) |
| <code>GET</code> | <code>/public/studies/{slug}</code> | [getSharedSimulationStudy](#getSharedSimulationStudy) |

<a id="listPassports"></a>

## List liquidity passports

`GET /passports`

Operation ID: <code>listPassports</code>

**Authentication:** <code>&#95;&#95;Host-klineo&#95;session</code> cookie (<code>sessionCookie</code>) **OR** OAuth bearer token with <code>proof:read</code> (<code>serviceCredential</code>)

**Service scope:** <code>proof:read</code>. Session access and workspace roles are evaluated separately.

### Parameters

| Name | Location | Required | Type | Description and constraints |
| --- | --- | --- | --- | --- |
| <code>x-klineo-organization-id</code> | header | Yes | <code>string</code> | — |
| <code>cursor</code> | query | No | <code>string</code> | Opaque cursor returned in the previous response metadata. |
| <code>limit</code> | query | No | <code>integer</code> | Default: <code>50</code>; Minimum: <code>1</code>; Maximum: <code>100</code> |

### Responses

| Status | Description | Content type and schema |
| --- | --- | --- |
| <code>200</code> | Latest tenant-isolated aggregate versions | <code>application/json</code>: <code>object</code> |

**<code>200</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>data</code> | Yes | Array of All of: [RecordEnvelope](/api-reference/schemas/record-envelope/); <code>object</code> | — |
| <code>data&#91;&#93;.allOf&#91;2&#93;.payload</code> | Yes | [LiquidityPassport](/api-reference/schemas/liquidity-passport/) | — |
| <code>meta</code> | Yes | <code>object</code> | Additional properties rejected |
| <code>meta.count</code> | Yes | <code>integer</code> | Minimum: <code>0</code> |
| <code>meta.hasMore</code> | Yes | <code>boolean</code> | — |
| <code>meta.nextCursor</code> | No | <code>string</code> | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

<a id="publishLiquidityPassport"></a>

## Publish issuer-signed claims recomputed from exact current server evidence

`POST /passports`

Operation ID: <code>publishLiquidityPassport</code>

**Authentication:** <code>&#95;&#95;Host-klineo&#95;session</code> cookie (<code>sessionCookie</code>)

**Conditional version precondition:** <code>A passport already exists for payload.slug.</code>

### Parameters

| Name | Location | Required | Type | Description and constraints |
| --- | --- | --- | --- | --- |
| <code>Idempotency-Key</code> | header | Yes | <code>string</code> | Min length: <code>8</code>; Max length: <code>160</code> |
| <code>x-klineo-organization-id</code> | header | Yes | <code>string</code> | — |
| <code>If-Match</code> | header | No | <code>string</code> | Pattern: <code>^"&#91;^"&#92;&#92; &#93;+"$</code> |

### Request body

Required: **yes**.

**<code>application/json</code>**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>payload</code> | Yes | <code>object</code> | Additional properties rejected |
| <code>payload.passportVersion</code> | Yes | Constant <code>liquidity-passport-v1</code> | — |
| <code>payload.artifactRendererVersion</code> | Yes | <code>string</code> | Allowed: <code>liquidity-passport-artifacts-v1</code>, <code>liquidity-passport-artifacts-v2</code> |
| <code>payload.signatureAlgorithm</code> | Yes | Constant <code>Ed25519</code> | — |
| <code>payload.signerProviderId</code> | Yes | <code>string</code> | — |
| <code>payload.signerKeyResourceVersion</code> | Yes | [Hash](/api-reference/schemas/hash/) | — |
| <code>payload.slug</code> | Yes | <code>string</code> | — |
| <code>payload.vaultId</code> | Yes | <code>string</code> | — |
| <code>payload.issuerName</code> | Yes | <code>string</code> | — |
| <code>payload.reportBrand</code> | No | <code>object</code> | Additional properties rejected |
| <code>payload.reportBrand.partnerId</code> | Yes | <code>string</code> | — |
| <code>payload.reportBrand.name</code> | Yes | <code>string</code> | — |
| <code>payload.reportBrand.accentColor</code> | Yes | <code>string</code> | Pattern: <code>^#&#91;0-9a-fA-F&#93;{6}$</code> |
| <code>payload.reportBrand.logoContentHash</code> | No | [Hash](/api-reference/schemas/hash/) | — |
| <code>payload.reportBrand.sourceBinding</code> | Yes | <code>object</code> | Additional properties rejected |
| <code>payload.reportBrand.sourceBinding.partnerOrganizationId</code> | Yes | <code>string</code> | — |
| <code>payload.reportBrand.sourceBinding.partnerConfigurationResourceVersion</code> | Yes | [Hash](/api-reference/schemas/hash/) | — |
| <code>payload.reportBrand.sourceBinding.partnerConfigurationArtifactHash</code> | Yes | [Hash](/api-reference/schemas/hash/) | — |
| <code>payload.reportBrand.sourceBinding.consentId</code> | Yes | <code>string</code> | — |
| <code>payload.reportBrand.sourceBinding.consentResourceVersion</code> | Yes | [Hash](/api-reference/schemas/hash/) | — |
| <code>payload.reportBrand.sourceBinding.consentArtifactHash</code> | Yes | [Hash](/api-reference/schemas/hash/) | — |
| <code>payload.generatedAt</code> | Yes | <code>string</code> | Format: <code>date-time</code> |
| <code>payload.validUntil</code> | Yes | <code>string</code> | Format: <code>date-time</code> |
| <code>payload.usableDepthByTradeSize</code> | Yes | Array of <code>object</code> | Min items: <code>1</code> |
| <code>payload.usableDepthByTradeSize&#91;&#93;.tradeSizeQuote</code> | Yes | [AtomicAmount](/api-reference/schemas/atomic-amount/) | — |
| <code>payload.usableDepthByTradeSize&#91;&#93;.buySlippagePips</code> | Yes | [Pips](/api-reference/schemas/pips/) | — |
| <code>payload.usableDepthByTradeSize&#91;&#93;.sellSlippagePips</code> | Yes | [Pips](/api-reference/schemas/pips/) | — |
| <code>payload.historicalReliabilityPips</code> | Yes | [Pips](/api-reference/schemas/pips/) | — |
| <code>payload.policyCompliancePips</code> | Yes | At least one of: [Pips](/api-reference/schemas/pips/); <code>null</code> | — |
| <code>payload.policyLimits</code> | No | <code>object</code> | Additional properties rejected |
| <code>payload.policyLimits.level</code> | Yes | <code>integer</code> | Allowed: <code>0</code>, <code>1</code>, <code>2</code>, <code>3</code>, <code>4</code> |
| <code>payload.policyLimits.maximumAmountPerTransaction</code> | Yes | [AtomicAmount](/api-reference/schemas/atomic-amount/) | — |
| <code>payload.policyLimits.maximumDailyTurnover</code> | Yes | [AtomicAmount](/api-reference/schemas/atomic-amount/) | — |
| <code>payload.policyLimits.maximumSlippagePips</code> | Yes | [Pips](/api-reference/schemas/pips/) | — |
| <code>payload.policyLimits.approvedContracts</code> | Yes | Array of [Address](/api-reference/schemas/address/) | Max items: <code>256</code> |
| <code>payload.policyLimits.approvedAssets</code> | Yes | Array of [Address](/api-reference/schemas/address/) | Max items: <code>256</code> |
| <code>payload.policyLimits.approvedAdapterIds</code> | Yes | Array of <code>string</code> | Max items: <code>256</code> |
| <code>payload.policyLimits.minimumSecondsBetweenActions</code> | Yes | <code>integer</code> | Minimum: <code>0</code>; Maximum: <code>31536000</code> |
| <code>payload.policyLimits.minimumPriceX18</code> | No | [AtomicAmount](/api-reference/schemas/atomic-amount/) | — |
| <code>payload.policyLimits.maximumPriceX18</code> | No | [AtomicAmount](/api-reference/schemas/atomic-amount/) | — |
| <code>payload.policyLimits.oracleMaximumAgeSeconds</code> | Yes | <code>integer</code> | Minimum: <code>1</code>; Maximum: <code>86400</code> |
| <code>payload.policyLimits.expiresAt</code> | Yes | <code>string</code> | Format: <code>date-time</code> |
| <code>payload.policyLimits.controlEpoch</code> | Yes | [AtomicAmount](/api-reference/schemas/atomic-amount/) | — |
| <code>payload.policyLimits.publicMempoolFallbackAllowed</code> | Yes | <code>boolean</code> | — |
| <code>payload.reconciledPositionCount</code> | Yes | <code>integer</code> | Minimum: <code>0</code> |
| <code>payload.majorIncidentCount</code> | Yes | <code>integer</code> | Minimum: <code>0</code> |
| <code>payload.treasuryOwnedLiquidityQuote</code> | No | [AtomicAmount](/api-reference/schemas/atomic-amount/) | — |
| <code>payload.rentedLiquidityQuote</code> | No | [AtomicAmount](/api-reference/schemas/atomic-amount/) | — |
| <code>payload.incidentDetails</code> | No | <code>object</code> | Additional properties rejected |
| <code>payload.incidentDetails.v1IncidentEvidenceHashes</code> | Yes | Array of [Hash](/api-reference/schemas/hash/) | Max items: <code>256</code> |
| <code>payload.incidentDetails.anomalies</code> | Yes | Array of <code>object</code> | Max items: <code>256</code> |
| <code>payload.incidentDetails.anomalies&#91;&#93;.detectorVersion</code> | Yes | Constant <code>robust-mad-v1</code> | — |
| <code>payload.incidentDetails.anomalies&#91;&#93;.kind</code> | Yes | <code>string</code> | Allowed: <code>LIQUIDITY&#95;DISAPPEARANCE</code>, <code>ONE&#95;SIDED&#95;FLOW</code>, <code>INACTIVE&#95;RANGE</code>, <code>STABLECOIN&#95;DEPEG</code>, <code>ORACLE&#95;DISAGREEMENT</code>, <code>INVENTORY&#95;ACCUMULATION</code>, <code>EXCESSIVE&#95;TURNOVER</code>, <code>MANIPULATION&#95;INDICATOR</code>, <code>SIMULATED&#95;REALIZED&#95;DIVERGENCE</code> |
| <code>payload.incidentDetails.anomalies&#91;&#93;.severity</code> | Yes | <code>string</code> | Allowed: <code>INFO</code>, <code>WARNING</code>, <code>CRITICAL</code> |
| <code>payload.incidentDetails.anomalies&#91;&#93;.artifactHash</code> | Yes | [Hash](/api-reference/schemas/hash/) | — |
| <code>payload.externalManagerExposureQuote</code> | No | [AtomicAmount](/api-reference/schemas/atomic-amount/) | — |
| <code>payload.externalManagerNames</code> | No | Array of <code>string</code> | — |
| <code>payload.dataFreshnessSeconds</code> | Yes | <code>integer</code> | Minimum: <code>0</code> |
| <code>payload.disclosure</code> | Yes | <code>object</code> | Additional properties rejected |
| <code>payload.disclosure.showTreasuryOwnership</code> | Yes | <code>boolean</code> | — |
| <code>payload.disclosure.showExternalManagerNames</code> | Yes | <code>boolean</code> | — |
| <code>payload.disclosure.showIncidentDetails</code> | Yes | <code>boolean</code> | — |
| <code>payload.disclosure.showPolicyLimits</code> | Yes | <code>boolean</code> | — |
| <code>payload.reportHashes</code> | Yes | Array of [Hash](/api-reference/schemas/hash/) | Min items: <code>1</code>; Max items: <code>128</code> |
| <code>payload.sourceBindings</code> | Yes | [LiquidityPassportSourceBindings](/api-reference/schemas/liquidity-passport-source-bindings/) | — |
| <code>payload.resultsRegistryProviderId</code> | No | <code>string</code> | — |
| <code>payload.resultsRegistryProviderResourceVersion</code> | No | [Hash](/api-reference/schemas/hash/) | — |
| <code>payload.resultsRegistryProviderAttestationHash</code> | No | [Hash](/api-reference/schemas/hash/) | — |
| <code>payload.resultsRegistryCommitmentHash</code> | No | [Hash](/api-reference/schemas/hash/) | — |
| <code>payload.resultsRegistryReceipt</code> | No | <code>object</code> | Additional properties rejected |
| <code>payload.resultsRegistryReceipt.receiptVersion</code> | Yes | Constant <code>liquidity-passport-results-registry-receipt-v1</code> | — |
| <code>payload.resultsRegistryReceipt.providerId</code> | Yes | <code>string</code> | — |
| <code>payload.resultsRegistryReceipt.providerResourceVersion</code> | Yes | [Hash](/api-reference/schemas/hash/) | — |
| <code>payload.resultsRegistryReceipt.providerAttestationHash</code> | Yes | [Hash](/api-reference/schemas/hash/) | — |
| <code>payload.resultsRegistryReceipt.passportSubjectHash</code> | Yes | [Hash](/api-reference/schemas/hash/) | — |
| <code>payload.resultsRegistryReceipt.commitmentHash</code> | Yes | [Hash](/api-reference/schemas/hash/) | — |
| <code>payload.resultsRegistryReceipt.issuedAt</code> | Yes | <code>string</code> | Format: <code>date-time</code> |
| <code>payload.resultsRegistryReceipt.signature</code> | Yes | <code>string</code> | Content encoding: <code>base64</code> |
| <code>payload.supersedesPassportHash</code> | No | [Hash](/api-reference/schemas/hash/) | — |
| <code>payload.contentHash</code> | Yes | [Hash](/api-reference/schemas/hash/) | — |
| <code>payload.signature</code> | Yes | <code>string</code> | Content encoding: <code>base64</code> |
| <code>payload.marketQualityScoreId</code> | Yes | <code>string</code> | Min length: <code>3</code>; Max length: <code>160</code> |
| <code>reason</code> | Yes | <code>string</code> | Min length: <code>3</code>; Max length: <code>500</code> |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

### Responses

| Status | Description | Content type and schema |
| --- | --- | --- |
| <code>201</code> | Source-grounded canonical passport and immutable report job | <code>application/json</code>: <code>object</code> |
| <code>409</code> | A numeric claim, freshness window, provider generation, or source binding differs | No response body declared |
| <code>412</code> | Superseded passport generation changed | No response body declared |

**<code>201</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>data</code> | Yes | <code>object</code> | Additional properties rejected |
| <code>data.passport</code> | Yes | All of: [RecordEnvelope](/api-reference/schemas/record-envelope/); <code>object</code> | — |
| <code>data.passport.allOf&#91;2&#93;.payload</code> | Yes | [LiquidityPassport](/api-reference/schemas/liquidity-passport/) | — |
| <code>data.reportJob</code> | Yes | [OperatingSystemJob](/api-reference/schemas/operating-system-job/) | — |
| <code>data.signedFormatsReady</code> | Yes | Array of <code>string</code> | — |
| <code>data.artifactState</code> | Yes | Constant <code>PENDING&#95;IMMUTABLE&#95;OBJECT&#95;REGISTRATION</code> | — |
| <code>data.executionAuthorityGranted</code> | Yes | Constant <code>false</code> | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

<a id="getPassports"></a>

## Get one liquidity passports aggregate

`GET /passports/{id}`

Operation ID: <code>getPassports</code>

**Authentication:** <code>&#95;&#95;Host-klineo&#95;session</code> cookie (<code>sessionCookie</code>) **OR** OAuth bearer token with <code>proof:read</code> (<code>serviceCredential</code>)

**Service scope:** <code>proof:read</code>. Session access and workspace roles are evaluated separately.

### Parameters

| Name | Location | Required | Type | Description and constraints |
| --- | --- | --- | --- | --- |
| <code>x-klineo-organization-id</code> | header | Yes | <code>string</code> | — |
| <code>id</code> | path | Yes | <code>string</code> | — |

### Responses

| Status | Description | Content type and schema |
| --- | --- | --- |
| <code>200</code> | Current immutable aggregate version | <code>application/json</code>: <code>object</code> |
| <code>404</code> | Not found | No response body declared |

**<code>200</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>ETag</code> | Yes | <code>string</code> | — |

**<code>200</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>data</code> | Yes | All of: [RecordEnvelope](/api-reference/schemas/record-envelope/); <code>object</code> | — |
| <code>data.allOf&#91;2&#93;.payload</code> | Yes | [LiquidityPassport](/api-reference/schemas/liquidity-passport/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

<a id="listQualifiedVaultsV2"></a>

## List tenant-isolated qualified vault metadata projected from authoritative v1 custody records

`GET /vaults`

Operation ID: <code>listQualifiedVaultsV2</code>

**Authentication:** <code>&#95;&#95;Host-klineo&#95;session</code> cookie (<code>sessionCookie</code>) **OR** OAuth bearer token with <code>vaults:read</code> (<code>serviceCredential</code>)

**Service scope:** <code>vaults:read</code>. Session access and workspace roles are evaluated separately.

### Parameters

| Name | Location | Required | Type | Description and constraints |
| --- | --- | --- | --- | --- |
| <code>x-klineo-organization-id</code> | header | Yes | <code>string</code> | — |
| <code>cursor</code> | query | No | <code>string</code> | Opaque cursor returned in the previous response metadata. |
| <code>limit</code> | query | No | <code>integer</code> | Default: <code>50</code>; Minimum: <code>1</code>; Maximum: <code>100</code> |

### Responses

| Status | Description | Content type and schema |
| --- | --- | --- |
| <code>200</code> | Cursor-paginated vault projections | <code>application/json</code>: <code>object</code> |

**<code>200</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>data</code> | Yes | Array of [QualifiedVaultV2](/api-reference/schemas/qualified-vault-v2/) | — |
| <code>meta</code> | Yes | <code>object</code> | Additional properties rejected |
| <code>meta.count</code> | Yes | <code>integer</code> | Minimum: <code>0</code> |
| <code>meta.hasMore</code> | Yes | <code>boolean</code> | — |
| <code>meta.nextCursor</code> | No | <code>string</code> | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

<a id="getQualifiedVaultV2"></a>

## Read one qualified vault and immutable deployment/control evidence

`GET /vaults/{id}`

Operation ID: <code>getQualifiedVaultV2</code>

**Authentication:** <code>&#95;&#95;Host-klineo&#95;session</code> cookie (<code>sessionCookie</code>) **OR** OAuth bearer token with <code>vaults:read</code> (<code>serviceCredential</code>)

**Service scope:** <code>vaults:read</code>. Session access and workspace roles are evaluated separately.

### Parameters

| Name | Location | Required | Type | Description and constraints |
| --- | --- | --- | --- | --- |
| <code>x-klineo-organization-id</code> | header | Yes | <code>string</code> | — |
| <code>id</code> | path | Yes | <code>string</code> | — |

### Responses

| Status | Description | Content type and schema |
| --- | --- | --- |
| <code>200</code> | Vault projection | <code>application/json</code>: <code>object</code> |
| <code>404</code> | Not found | No response body declared |

**<code>200</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>ETag</code> | Yes | <code>string</code> | — |

**<code>200</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>data</code> | Yes | [QualifiedVaultV2](/api-reference/schemas/qualified-vault-v2/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

<a id="listExecutionReceiptsV2"></a>

## List canonical inclusion, finality, reconciliation, and attribution receipts

`GET /receipts`

Operation ID: <code>listExecutionReceiptsV2</code>

**Authentication:** <code>&#95;&#95;Host-klineo&#95;session</code> cookie (<code>sessionCookie</code>) **OR** OAuth bearer token with <code>receipts:read</code> (<code>serviceCredential</code>)

**Service scope:** <code>receipts:read</code>. Session access and workspace roles are evaluated separately.

### Parameters

| Name | Location | Required | Type | Description and constraints |
| --- | --- | --- | --- | --- |
| <code>x-klineo-organization-id</code> | header | Yes | <code>string</code> | — |
| <code>cursor</code> | query | No | <code>string</code> | Opaque cursor returned in the previous response metadata. |
| <code>limit</code> | query | No | <code>integer</code> | Default: <code>50</code>; Minimum: <code>1</code>; Maximum: <code>100</code> |

### Responses

| Status | Description | Content type and schema |
| --- | --- | --- |
| <code>200</code> | Cursor-paginated receipt projections | <code>application/json</code>: <code>object</code> |

**<code>200</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>data</code> | Yes | Array of [ExecutionReceiptV2](/api-reference/schemas/execution-receipt-v2/) | — |
| <code>meta</code> | Yes | <code>object</code> | Additional properties rejected |
| <code>meta.count</code> | Yes | <code>integer</code> | Minimum: <code>0</code> |
| <code>meta.hasMore</code> | Yes | <code>boolean</code> | — |
| <code>meta.nextCursor</code> | No | <code>string</code> | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

<a id="getExecutionReceiptV2"></a>

## Read one canonical execution receipt projection

`GET /receipts/{id}`

Operation ID: <code>getExecutionReceiptV2</code>

**Authentication:** <code>&#95;&#95;Host-klineo&#95;session</code> cookie (<code>sessionCookie</code>) **OR** OAuth bearer token with <code>receipts:read</code> (<code>serviceCredential</code>)

**Service scope:** <code>receipts:read</code>. Session access and workspace roles are evaluated separately.

### Parameters

| Name | Location | Required | Type | Description and constraints |
| --- | --- | --- | --- | --- |
| <code>x-klineo-organization-id</code> | header | Yes | <code>string</code> | — |
| <code>id</code> | path | Yes | <code>string</code> | — |

### Responses

| Status | Description | Content type and schema |
| --- | --- | --- |
| <code>200</code> | Receipt projection | <code>application/json</code>: <code>object</code> |
| <code>404</code> | Not found or not yet included | No response body declared |

**<code>200</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>ETag</code> | Yes | <code>string</code> | — |

**<code>200</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>data</code> | Yes | [ExecutionReceiptV2](/api-reference/schemas/execution-receipt-v2/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

<a id="listProofV2"></a>

## List signed passports and content-addressed proof artifacts

`GET /proof`

Operation ID: <code>listProofV2</code>

**Authentication:** <code>&#95;&#95;Host-klineo&#95;session</code> cookie (<code>sessionCookie</code>) **OR** OAuth bearer token with <code>proof:read</code> (<code>serviceCredential</code>)

**Service scope:** <code>proof:read</code>. Session access and workspace roles are evaluated separately.

### Parameters

| Name | Location | Required | Type | Description and constraints |
| --- | --- | --- | --- | --- |
| <code>x-klineo-organization-id</code> | header | Yes | <code>string</code> | — |
| <code>cursor</code> | query | No | <code>string</code> | Opaque cursor returned in the previous response metadata. |
| <code>limit</code> | query | No | <code>integer</code> | Default: <code>50</code>; Minimum: <code>1</code>; Maximum: <code>100</code> |

### Responses

| Status | Description | Content type and schema |
| --- | --- | --- |
| <code>200</code> | Cursor-paginated proof resources | <code>application/json</code>: <code>object</code> |

**<code>200</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>data</code> | Yes | Array of [ProofResource](/api-reference/schemas/proof-resource/) | — |
| <code>meta</code> | Yes | <code>object</code> | Additional properties rejected |
| <code>meta.count</code> | Yes | <code>integer</code> | Minimum: <code>0</code> |
| <code>meta.hasMore</code> | Yes | <code>boolean</code> | — |
| <code>meta.nextCursor</code> | No | <code>string</code> | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

<a id="revokeLiquidityPassport"></a>

## Immediately revoke a published passport without deleting signed evidence

`POST /passports/{id}/revoke`

Operation ID: <code>revokeLiquidityPassport</code>

**Authentication:** <code>&#95;&#95;Host-klineo&#95;session</code> cookie (<code>sessionCookie</code>)

### Parameters

| Name | Location | Required | Type | Description and constraints |
| --- | --- | --- | --- | --- |
| <code>Idempotency-Key</code> | header | Yes | <code>string</code> | Min length: <code>8</code>; Max length: <code>160</code> |
| <code>x-klineo-organization-id</code> | header | Yes | <code>string</code> | — |
| <code>id</code> | path | Yes | <code>string</code> | — |
| <code>If-Match</code> | header | Yes | <code>string</code> | Pattern: <code>^"&#91;^"&#92;&#92; &#93;+"$</code> |

### Request body

Required: **yes**.

**<code>application/json</code>**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>reason</code> | Yes | <code>string</code> | Min length: <code>3</code>; Max length: <code>500</code> |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

### Responses

| Status | Description | Content type and schema |
| --- | --- | --- |
| <code>200</code> | Append-only revoked passport generation | <code>application/json</code>: <code>object</code> |
| <code>409</code> | Passport is not active | No response body declared |
| <code>412</code> | Strong precondition failed | No response body declared |

**<code>200</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>data</code> | Yes | All of: [RecordEnvelope](/api-reference/schemas/record-envelope/); <code>object</code> | — |
| <code>data.allOf&#91;2&#93;.payload</code> | Yes | [LiquidityPassport](/api-reference/schemas/liquidity-passport/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

<a id="getPublicLiquidityPassport"></a>

## Verify an issuer-disclosed signed Liquidity Passport

`GET /public/passports/{slug}`

Operation ID: <code>getPublicLiquidityPassport</code>

**Authentication:** No authentication requirement is declared in this OpenAPI operation. Consult the access guide and deployed service configuration.

### Parameters

| Name | Location | Required | Type | Description and constraints |
| --- | --- | --- | --- | --- |
| <code>slug</code> | path | Yes | <code>string</code> | — |

### Responses

| Status | Description | Content type and schema |
| --- | --- | --- |
| <code>200</code> | Canonical public passport | <code>application/json</code>: <code>object</code> |
| <code>404</code> | Not published, revoked, or expired | No response body declared |

**<code>200</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>ETag</code> | Yes | <code>string</code> | — |

**<code>200</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>data</code> | Yes | [PublicPassportResult](/api-reference/schemas/public-passport-result/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.

<a id="downloadPublicLiquidityPassport"></a>

## Download deterministic signed JSON, HTML, PDF, or CSV

`GET /public/passports/{slug}/formats/{format}`

Operation ID: <code>downloadPublicLiquidityPassport</code>

**Authentication:** No authentication requirement is declared in this OpenAPI operation. Consult the access guide and deployed service configuration.

### Parameters

| Name | Location | Required | Type | Description and constraints |
| --- | --- | --- | --- | --- |
| <code>slug</code> | path | Yes | <code>string</code> | — |
| <code>format</code> | path | Yes | <code>string</code> | Allowed: <code>json</code>, <code>html</code>, <code>pdf</code>, <code>csv</code> |

### Responses

| Status | Description | Content type and schema |
| --- | --- | --- |
| <code>200</code> | Content-addressed passport artifact | <code>application/json</code>: [LiquidityPassport](/api-reference/schemas/liquidity-passport/); <code>text/html</code>: <code>string</code>; <code>application/pdf</code>: <code>string</code>; <code>text/csv</code>: <code>string</code> |
| <code>404</code> | Not published, revoked, expired, or trust anchor disabled | No response body declared |

**<code>200</code> response headers**

| Header | Required | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>Content-Disposition</code> | Yes | <code>string</code> | — |
| <code>X-KlineO-Passport-Hash</code> | Yes | [Hash](/api-reference/schemas/hash/) | — |
| <code>X-KlineO-Artifact-Hash</code> | Yes | [Hash](/api-reference/schemas/hash/) | — |
| <code>X-KlineO-Signature-Algorithm</code> | Yes | Constant <code>Ed25519</code> | — |
| <code>X-KlineO-Signer-Key-Version</code> | Yes | [Hash](/api-reference/schemas/hash/) | — |

**<code>200</code> <code>text/html</code> body**

<code>string</code> — Format: <code>binary</code>

**<code>200</code> <code>application/pdf</code> body**

<code>string</code> — Format: <code>binary</code>

**<code>200</code> <code>text/csv</code> body**

<code>string</code> — Format: <code>binary</code>

<a id="downloadLiquidityPassportVerificationBundle"></a>

## Download canonical passport, trust anchor, artifact hashes, and registry commitment

`GET /public/passports/{slug}/verification-bundle`

Operation ID: <code>downloadLiquidityPassportVerificationBundle</code>

**Authentication:** No authentication requirement is declared in this OpenAPI operation. Consult the access guide and deployed service configuration.

### Parameters

| Name | Location | Required | Type | Description and constraints |
| --- | --- | --- | --- | --- |
| <code>slug</code> | path | Yes | <code>string</code> | — |

### Responses

| Status | Description | Content type and schema |
| --- | --- | --- |
| <code>200</code> | Verification bundle | <code>application/json</code>: [LiquidityPassportVerificationBundle](/api-reference/schemas/liquidity-passport-verification-bundle/) |
| <code>404</code> | Passport unavailable | No response body declared |

<a id="getSharedSimulationStudy"></a>

## Read a non-revoked study share

`GET /public/studies/{slug}`

Operation ID: <code>getSharedSimulationStudy</code>

**Authentication:** No authentication requirement is declared in this OpenAPI operation. Consult the access guide and deployed service configuration.

### Parameters

| Name | Location | Required | Type | Description and constraints |
| --- | --- | --- | --- | --- |
| <code>slug</code> | path | Yes | <code>string</code> | — |

### Responses

| Status | Description | Content type and schema |
| --- | --- | --- |
| <code>200</code> | Disclosed study artifact | <code>application/json</code>: <code>object</code> |
| <code>404</code> | Not published, revoked, or expired | No response body declared |

**<code>200</code> <code>application/json</code> body**

<code>object</code> — Additional properties rejected

| Field | Required at this level | Type | Description and constraints |
| --- | --- | --- | --- |
| <code>data</code> | Yes | [SharedSimulationStudy](/api-reference/schemas/shared-simulation-study/) | — |

Nested required fields apply when their parent object or matching union branch is present. Named types link to their complete schema.
