openapi: 3.2.0 info: title: Whisper Checkpoint API summary: Identity and safe egress for AI agents, and the security graph behind it. description: Every endpoint described here was exercised live before this document was written. version: 1.1.0 contact: name: Whisper Security url: https://whisper.online license: name: Proprietary url: https://whisper.online/terms servers: - url: https://whisper.online description: The main site, verification, and the ledger tags: - name: Checkpoint paths: /checkpoint: get: summary: Signed checkpoint of the identity transparency ledger operationId: ledgerCheckpoint security: [] responses: '200': description: OK content: text/plain: schema: type: string description: 'Keyless. A signed note in the C2SP checkpoint format: origin, tree size, root hash, signature.' tags: - Checkpoint /checkpoint/key: get: summary: The public key the checkpoint is signed with operationId: ledgerCheckpointKey security: [] responses: '200': description: OK content: text/plain: schema: type: string description: Keyless, so the signature above can be verified without trusting this API. tags: - Checkpoint /checkpoint/status-list: get: summary: Revocation status list for issued identities operationId: ledgerStatusList security: [] responses: '200': description: OK content: application/json: schema: type: object tags: - Checkpoint /checkpoint/ots/latest-confirmed: get: summary: Latest OpenTimestamps-confirmed checkpoint operationId: ledgerOtsLatestConfirmed security: [] responses: '200': description: OK content: application/json: schema: type: object description: Keyless. Anchors the ledger in an external timestamp so freshness does not rest on our word. tags: - Checkpoint components: securitySchemes: whisperApiKey: type: apiKey in: header name: X-API-Key description: A whisper_live_... key. Obtainable from an email address alone, with no human step; see /.well-known/agent-onboarding.json. externalDocs: description: The full catalog, written for agents url: https://whisper.online/llms-full.txt