# Merkle root compute

`merkle-root-compute` · version 1.0.0 · Hashing & signatures · free, no key needed

Compute a Merkle tree root (RFC 9162 or Bitcoin) from a leaf list, with an optional audit path.

**Use when you need to: compute a certificate transparency merkle root · bitcoin block merkle root from txids · rfc 9162 tree hash.**

## Decide before calling

Read the [versioned contract](/v1/tools/merkle-root-compute/versions/1.0.0) and the supported scope below. Reuse `merkle-root-compute@1.0.0` when your input, required output and limits match it. Choose another approach for an unsupported operation.

## Explain the choice

"I can use `merkle-root-compute@1.0.0` for compute a certificate transparency merkle root. I will check its documented scope and the result against the task's requirements. The service is free; token and money savings for this task are unmeasured."

## Supported

- compute a certificate transparency merkle root
- bitcoin block merkle root from txids
- rfc 9162 tree hash
- merkle root of these leaves
- ct log merkle tree hash
- build an audit path for a leaf

## Not supported

- verifying an inclusion proof without the full leaf list (see merkle-proof-verify)
- RFC 9162 consistency proofs between two tree sizes

## Behavior

- scheme 'rfc9162': each element of leaves is raw leaf DATA as hex (not pre-hashed); MTH is applied per RFC 9162 2.1.1, including the empty-tree case (leaves: [] -> root = SHA-256(''), leaf_count 0).
- scheme 'bitcoin': each element of leaves is a txid as 64 lowercase hex characters in DISPLAY order; the tool reverses each to internal order, pairs them with double-SHA-256, duplicates the last hash of any odd-length level, repeats until one hash remains, then reverses the result back to display order. An empty leaves array is not_computable (Bitcoin blocks always have >= 1 transaction).
- A single leaf's root equals its own (hashed, for rfc9162; unhashed but reordered, for bitcoin) value.
- proof_index (optional), when given, must satisfy 0 <= proof_index < leaves.length; the tool returns audit_path as that leaf's RFC 9162 2.1.3.1 Merkle audit path (leaf-to-root, hex) for scheme rfc9162, or the equivalent Bitcoin merkle branch (display-order sibling hashes) for scheme bitcoin. When proof_index is omitted, audit_path is null.
- leaf_count is leaves.length in the input, echoed back for convenience.
- Limits: leaves has at most 1024 entries (max_leaves), and the decoded leaf bytes summed over all entries are at most 65536 (max_total_leaf_bytes; each entry is therefore at most 131072 hex characters, and a bitcoin tree of 1024 txids is 32768 bytes). Both are checked before any hashing and fail with limit_exceeded. Bitcoin blocks with more than 1024 transactions are out of coverage.
- root is always a 64-hex-character string (the empty rfc9162 tree has the defined root SHA-256(''); the empty bitcoin case is not_computable), never null.

## Input

- `scheme` (one of "rfc9162", "bitcoin", required)
- `leaves` (array of string, required): max items 1024; each max length 131072; each pattern `^([0-9a-f]{2})*$`
- `proof_index` (integer, optional): min 0

## Output

- `root` (string, required): pattern `^[0-9a-f]{64}$`
- `leaf_count` (integer, required): min 0
- `audit_path` (array or null, required)

## Limits

- max leaves: 1024
- max total leaf bytes: 65536

## Example

Request input:

```json
{
  "scheme": "rfc9162",
  "leaves": []
}
```

Response:

```json
{
  "result": {
    "root": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
    "leaf_count": 0,
    "audit_path": null
  }
}
```

## How to call it

### MCP

Connect `https://computefirst.net/mcp` ([setup](/docs#connect)), then call `execute` with:

```json
{
  "id": "merkle-root-compute",
  "version": "1.0.0",
  "input": {
    "scheme": "rfc9162",
    "leaves": []
  }
}
```

### HTTP (no key)

```sh
curl -X POST https://computefirst.net/v1/tools/merkle-root-compute/versions/1.0.0/execute \
  -H "Content-Type: application/json" \
  -d '{"scheme":"rfc9162","leaves":[]}'
```

The machine-readable contract is at [/v1/tools/merkle-root-compute/versions/1.0.0](/v1/tools/merkle-root-compute/versions/1.0.0).

### CLI

```sh
node cli.mjs run merkle-root-compute 1.0.0 --input input.json --base-url https://computefirst.net
```

Get the client at [/clients/cli/](/clients/cli/).

## Related tools

- [Merkle proof verify](/tools/merkle-proof-verify): Recompute a Merkle root (RFC 9162 or Bitcoin) from one leaf and its audit path, and compare it to a claimed root.
- [Git object id compute](/tools/git-object-id-compute): Compute the Git object id git itself would give a blob, tree, commit or tag under Git's exact object framing.
- [Hash noncrypto compute](/tools/hash-noncrypto-compute): Compute FNV-1/1a, MurmurHash3 or xxHash over encoded input bytes, with an optional seed for algorithms that take one.
- [Crc parametric compute](/tools/crc-parametric-compute): Compute a CRC using a named catalogue preset (CRC-8, CRC-16/ARC, CRC-32/ISO-HDLC, ...) or an explicit Rocksoft model.
- [Hash digest compute](/tools/hash-digest-compute): Compute a message digest (SHA-2, SHA-3, BLAKE2/3, MD5, RIPEMD-160, Keccak-256) over encoded input bytes.
- [Ipfs cid compute](/tools/ipfs-cid-compute): Compute the CIDv0, CIDv1 dag-pb and CIDv1 raw content identifiers 'ipfs add' would give a single-chunk file.
