{"schema_version":"tickertrac-record-anchor/v1","anchors":[{"id":2,"anchored_at":"2026-09-26T01:11:06.259464Z","digest":"be56970df1a5cc2ae3984141d77156ceb51f72ce995f50ba195e76b24a86e0d2","head_count":1,"tsa_url":"http://timestamp.digicert.com","token_time":"2026-09-26T01:11:06Z","timestamped":true},{"id":1,"anchored_at":"2026-09-23T19:23:18.717236Z","digest":"c0d95f49c4e3a9d78eafe0b2e47025774dd87af1be4c6588633e6a0ab387c029","head_count":0,"tsa_url":"http://timestamp.digicert.com","token_time":"2026-09-23T19:23:18Z","timestamped":true}],"canonicalization":"JSON with keys sorted, separators ',' and ':', no ASCII escaping, UTF-8 bytes, SHA-256 hex. Timestamps are UTC with six fractional digits and a Z suffix. The signature is Ed25519 over the ASCII bytes of the entry hash, base64 encoded.","how_to_verify":"Recompute the digest: SHA-256 of the canonical JSON object {\"heads\": [...], \"schema_version\": \"tickertrac-record-anchor/v1\"} with keys sorted, separators \",\" and \":\", UTF-8. Decode token_base64 to anchor.tsr and run `openssl ts -verify -digest <digest> -in anchor.tsr -token_in -CAfile <the authority's root>` (DigiCert's root: https://cacerts.digicert.com/DigiCertTrustedRootG4.crt.pem); `openssl ts -reply -in anchor.tsr -token_in -text` prints the authority's time. Or run tickertrac.com/record/verify.py on any entry: it checks the covering anchor too. Every head in the list, and every earlier entry in that record's chain, existed by that time."}