ChainVerdict Pulse archive reference format — 2 October 2026 Purpose: verify this publisher's existing exported record format. Not a new protocol, safety certification, independent observer or novel moat. A daily export contains day, endpoints, merkleRoot and records (strings). Each record is the exact UTF-8 encoding of a JSON.stringify output, with keys: url,d,p,a,x,v,l and optionally self:1, in that order. d is a UTC date. p = probes; a = alive probes; x = x402 responses; v = valid x402 offers; l = rounded mean latency in milliseconds, or null. self:1 marks the operator's own endpoints. Alive and valid-offer counts do not prove paid fulfilment. The publisher sorts the complete strings using JavaScript UTF-16 ordering. Do NOT parse and reserialize strings before hashing: whitespace/escaping matters. SHA256 each string. Hash adjacent raw 32-byte hashes together at each level; promote an odd last node unchanged. A single leaf is its own root. The endpoints count and resulting root must match the original anchor. The full anchors response carries a compact Ed25519 JWS checkpoint authenticating its list of day, merkleRoot, chained, prevChained and records. The checker pins the existing production public key (kid b0bd6062bb630141). A key in a downloaded bundle cannot replace that pin. Key rotation requires a reviewed checker update. This authenticates the publisher, not the truth of the observations. It does not prevent the publisher from issuing conflicting signed histories; preserve copies. A chain link is SHA256(raw prevChained || raw merkleRoot). Genesis prev = 32 zero bytes. The proof message is chained, NOT merkleRoot. Proofs are serialized OpenTimestamps Timestamp trees, base64 encoded, NOT detached .ots files. The verifier parses official OTS proofs offline. The supplied 80-byte Bitcoin header is checked against its supplied hash and the timestamp attestation. It checks the header's declared proof of work against Bitcoin's mainnet maximum target; a minimum-difficulty mined header can pass. An untrusted supplied header is not an independent time source. It does NOT establish the best chain or difficulty history, or run a node. Capture fetches headers independently from Blockstream. For stronger assurance obtain headers from your validated node; never accept headers chosen by an untrusted bundle author as independent proof. An operator could still record false observations before committing them. As-of is an explicit UTC DATE, not a real-time clock attestation. Completed-day and age checks depend on an honest caller-supplied date. A default window spans supplied days; callers should pin --from/--to to avoid silent scope reduction. Current policy refuses all dates before 2026-10-04, including the repair-transition and collector-incident days. A requested endpoint is matched exactly, with no URL normalization or redirects. Missing days, missing endpoint, unclosed days and pending proofs are refused. The complete_recent window label describes coverage/age, NOT verified content; inspect every day's usableEvidence and recordStatus, or the CLI exit code. Exit 0 = all requested days pass the limited checks; 2 = insufficient evidence; 1 = input/operational error. No exit code authorizes payment or says service safe. Capture contacts only public Pulse exports and Blockstream's public API. Verify makes no network calls. No wallet, signing keys or paid request is used. Save captures under unique directories. Keep independent copies of roots and exports over time; this tool cannot recover records missing from a commitment. The public 2 October sample is a REAL refusal, not a positive verification. canonical-vector.json is SYNTHETIC and tests only hashing interoperability. Python tests use a synthetic Bitcoin header as a trust input, not a real block. x401 draft 0.2.0 uses PROOF-REQUEST/PROOF-RESPONSE/PROOF-RESULT independently of payment. Ordinary 401 responses do not establish x401 support. These daily records contain no credential evidence. Refer to github.com/proof/x401 and the existing x401-node SDK; this checker cannot satisfy or certify proof-gated access. Client policy also refuses commitments more than 72 hours after UTC day-end. That conservative bound is a product choice, not an OpenTimestamps guarantee. All days in a bundle are refused if its commitment chain is broken. Refused days never return endpointObservation. Capture before the signed-checkpoint release has no authenticated issuer and is correctly refused by newer checkers.