# Public proof and Liquidity Passports

Klineo lets an issuer disclose selected liquidity evidence outside its private workspace. A public outcome proof records a completed reporting period. A Liquidity Passport presents an issuer-signed, time-limited disclosure with explicit source bindings. Both help a reader inspect what was published, which evidence it references, and what remains unavailable.

Publication integrity is separate from financial performance. A matching hash, valid signature, or finalized transaction does not guarantee liquidity, solvency, investment returns, future execution, or the completeness of everything an issuer chose to disclose.

## Choose the right publication

| Publication | Purpose | Identity and evidence | Time scope |
| --- | --- | --- | --- |
| Public outcome proof | Share historical vault outcomes and benchmark results | Report content hash, source bundle hash, public bundle hash, publication hash, and finalized issuer-Safe results commitment | A daily or weekly UTC reporting period |
| Liquidity Passport | Share a signed view of market quality, depth, reliability, reconciliation, and disclosed policy or ownership evidence | Canonical content hash, Ed25519 issuer signature, exact provider key version, source record bindings, and optional signed results-registry receipt | `generatedAt` through `validUntil` |

An outcome proof is historical. Its endpoint does not supply a current supersession or expiry check. A Passport has an expiry and a current public-serving eligibility check. Do not treat the two formats as interchangeable credentials.

## Review proof in the app

Open `/app/prove` and search or filter the proof and Passport inventory. Use **Load proof index** for additional stored records and registered-artifact evidence, then **Inspect** the intended Passport generation. The selection retains its exact record ID and resource version; review its stored disclosure and source bindings before resolving public evidence.

For a stored `ACTIVE` Passport, select **Resolve current public preview**. The service response and verification bundle must match that exact generation, artifact/content hashes, vault and signer. Stored `ACTIVE` status alone does not establish current public eligibility: expiry, provider authority, revocation, supersession or disclosure checks can make resolution unavailable. An inactive or unavailable generation remains historical evidence to inspect.

After successful resolution, inspect the disclosed metrics, validity, source period, disclosure flags and registered format manifest. Select the verification bundle or an available document format, then use **Download selected publication**. JSON, PDF and CSV bytes are checked against their registered hashes; **Open registered HTML** opens the server document. Stored object keys are provenance, not download links. Refresh and resolve again if the generation changes or the preview expires.

The disclosure controls in this workspace are read-only review controls. They do not publish, sign, revoke or change disclosure. The preview displays service verification; it does not independently establish signer identity or chain state.

## Read an outcome proof

The application opens published outcome proofs at `/proof/{slug}`. Public API reads do not require workspace membership:

| Method | Path | Result |
| --- | --- | --- |
| GET | `/api/liquidity-studio/v1/public/proofs/{slug}` | Response envelope containing the redacted proof in `data` |
| GET | `/api/liquidity-studio/v1/public/proofs/{slug}/bundle` | Downloadable proof JSON, without the `data` wrapper |
| GET | `/api/liquidity-studio/v1/public/proofs/{slug}/artifacts` | Public artifact references, source observations, actions, and Outcome Ledger |

Use the API origin supplied for your environment and a real issuer-published slug. Demo publications and design samples are synthetic and provide no chain verification.

```javascript
const apiOrigin = "https://YOUR_KLINEO_API_ORIGIN";
const slug = "YOUR_PUBLISHED_SLUG";
const url = new URL(
  `/api/liquidity-studio/v1/public/proofs/${encodeURIComponent(slug)}`,
  apiOrigin,
);
const response = await fetch(url, { headers: { accept: "application/json" } });
if (!response.ok) throw new Error(`Proof unavailable: ${response.status}`);
const { data: proof } = await response.json();
console.log(proof.periodStart, proof.periodEnd, proof.publicationHash);
```

A proof includes its exact vault reference, reporting period, source coverage, benchmark definitions, finalized actions, failed executions, evidence hashes, limitations, and disclosure policy. Depth may be `UNAVAILABLE`; missing performance values must remain unavailable rather than becoming zero.

Depth distinguishes the quote input required to buy token0 from the quote output obtained by selling token0 at the measured two-percent boundary. Amounts are quote-token atomic units. This public projection does not provide token decimals or a fiat conversion, so a consumer must not label those raw amounts as dollars. Pips use a scale of `1_000_000 = 100%`; divide by `10_000` to display a percentage.

## Understand outcome proof integrity

The public service checks the underlying report's canonical content and evidence hashes and validates the complete publication commitment before producing a proof. The public envelope identifies:

- `sourceContentHash`: the immutable private report artifact.
- `sourceBundleHash`: the report artifact plus its evidence references.
- `publicationHash`: the report identity, period, source coverage, slug, and issuer disclosure choice.
- `publicBundleHash`: the disclosure-filtered public envelope, excluding the hash field itself.
- `onchainCommitment`: the results contract, vault, commitment ID, finalized transaction and block, source block range, disclosure policy hash, and prior commitment superseded by this publication.

The server's `verification` fields are a service statement. The public browser page does not independently verify chain state or cryptographic signatures. A downloaded public bundle contains a redacted projection, so it cannot reconstruct undisclosed private report material solely from its source hashes.

For independent review, retain the exact JSON and hashes, establish the correct chain and trusted results-contract deployment from an independent source, and compare the referenced finalized commitment and disclosure material. A transaction link alone is insufficient evidence that it belongs to the expected contract, vault, chain, or reporting period.

## Read a Liquidity Passport

The application opens public Passports at `/passport/{slug}`. These public API reads do not require workspace membership:

| Method | Path | Result |
| --- | --- | --- |
| GET | `/api/liquidity-studio/v2/public/passports/{slug}` | `data.passport`, publication metadata, and service verification statement |
| GET | `/api/liquidity-studio/v2/public/passports/{slug}/formats/{format}` | Registered artifact bytes; format is `json`, `html`, `pdf`, or `csv` |
| GET | `/api/liquidity-studio/v2/public/passports/{slug}/verification-bundle` | Passport, publication metadata, signer evidence, artifact hashes, source report hashes, and optional registry receipt evidence |

The public service checks expiry, canonical payload integrity, the registered issuer key version, and the Ed25519 signature. It refuses serving a Passport whose signing provider has been disabled. If a registry receipt is present, its provider must remain healthy and the receipt must validate. A response may mark the signer trust anchor `ROTATED`: the original registered key remains the key for that signature, while the provider now has a later generation.

Artifact downloads are tied to the exact published Passport version and registered content hash. Passport creation first queues artifact persistence; a successful creation response can still show `PENDING_IMMUTABLE_OBJECT_REGISTRATION` and no ready formats. Wait for registration rather than assuming a PDF exists immediately.

## Passport publication eligibility

Publication requires an authority role and recent authentication. The backend grounds the signed disclosure in records from the issuer organization and rejects a mismatched vault, source value, record generation, hash, or evidence cut. Required evidence includes the newest eligible, issuer-reviewed market-quality score, bound depth rows, position reconciliation, policy evidence, incident evidence, and report artifacts.

The current publication checks allow a five-minute signing grace, up to one-hour-old score and snapshot evidence, and up to one-day-old simulation depth evidence, with a thirty-second future-time tolerance at the signed evidence cut. These are admission rules for the disclosure; they are not a promise that markets remain unchanged during the Passport's validity window. Inspect `generatedAt`, `validUntil`, `dataFreshnessSeconds`, source timestamps, and the type of each depth source.

Superseding a Passport requires the exact prior `contentHash` and a later generation time. Revocation creates a later record generation. Branded Passports also require current [partner configuration and bilateral issuer consent](/guides/partners); changing or revoking either can make a previously published branded Passport unavailable from the public service.

## Disclosure and interpretation

Outcome proofs let the issuer disclose treasury amounts, policy limits, and incidents independently. Passport disclosure separately controls treasury ownership, external manager names, incident details, and policy limits. Hidden fields remain hidden; an absent incident list does not establish that no incidents occurred.

A Passport's market-quality score is a measured and reviewed disclosure, not a credit rating or a guarantee of execution at a quoted size. Simulation-backed depth remains a simulation. Historical reliability and policy compliance describe their evidence scope. `null` compliance means a value was not supplied; it does not mean perfect compliance.

An optional Passport results-registry receipt is a registered provider's signed receipt. Do not infer an onchain commitment from that receipt unless its evidence independently establishes one. Outcome proofs, by contrast, explicitly include finalized issuer-Safe chain commitment material.

See [reports and exports](/guides/reports) for the private evidence ledger and the publication workflow.
