ghostroute_ct_proofs
Returns GhostRoute's per-cert inclusion proofs: each is a cryptographic
demonstration that the exact certificate a host serves is included in an
append-only CT log whose root TunnelMind signature-verified — upgrading
"a monitor said this cert exists" to "proven in a log we witness". Failed
attempts are included with a reason; a cert that suddenly cannot be
proven is itself a signal.
Use this tool when:
You want to know whether a specific AI host's live cert is provably logged (pass
domain), orYou want the corpus-wide proof rollup across watched hosts (omit
domain).
Inputs:
domain(query, optional): a hostname to filter to; omit for corpus-wide.limit(query, optional): max recent rows, 1–200, default 50.
Returns:
domain(echo, null when corpus-wide).summary:total_attempts,proven,unproven,domains,last_observed_at.recent[]: recent attempts (log_operator,leaf_index,tree_size,sth_root_hash,inclusion_proven,reason, ...).by_domain[]: per-hostattempts/provenrollup.
Latency:
Typical <300ms (KV-cached 5m).
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| limit | No | ||
| domain | No |