{"id":"merkle-proof-verify","version":"1.0.0","description":"Recompute a Merkle root (RFC 9162 or Bitcoin) from one leaf and its audit path, and compare it to a claimed root.","supported_operations":["verify a merkle inclusion proof","check this leaf is really in the tree with this root","validate a ct log audit path","bitcoin merkle branch verification","spv proof check","check a partial merkle branch from a merkleblock message"],"unsupported_operations":["building the audit path from a full leaf list (see merkle-root-compute)","RFC 9162 consistency proofs between two tree sizes"],"semantics":["scheme 'rfc9162': leaf is raw leaf DATA as hex (the tool applies the 0x00 leaf-hash prefix itself). The verifier walks node=leaf_index, last_node=tree_size-1; while last_node>0: if node is odd, hash=H(0x01||next_path_entry||hash); else if node<last_node, hash=H(0x01||hash||next_path_entry); else (an even, rightmost node) consumes no path entry; then node//=2, last_node//=2. audit_path is consumed in that exact left-to-right order; reason 'path_length_wrong' (valid:false, computed_root null) when the path runs out early or has leftover entries.","scheme 'bitcoin': leaf is a 64-hex-char txid in display order; audit_path is the Bitcoin merkle branch, sibling hashes bottom-up in display order. The verifier reverses leaf and each sibling to internal order, pairs (current, sibling) by leaf_index's bit at each level (even index -> current is left), double-SHA-256s, halves the index. audit_path.length must equal ceil(log2(tree_size)) exactly, else 'path_length_wrong'.","leaf_index must be < tree_size in both schemes; otherwise the tool returns {valid: false, reason: 'index_out_of_range', computed_root: null} (RFC 9162 2.1.3.2: 'fail the proof verification'; well-typed input that does not verify is valid:false, not an error). A wrong audit_path length likewise returns {valid: false, reason: 'path_length_wrong', computed_root: null}. Order: every field is type- and shape-checked and every limit enforced first (invalid_input or limit_exceeded); then index_out_of_range, then path_length_wrong, then the root comparison. leaf_index and tree_size must be safe integers (at most 9007199254740991), else invalid_input.","computed_root is the recomputed root whenever the audit path length is consistent (valid true, or valid false with reason 'root_mismatch'), and null exactly when reason is 'path_length_wrong' or 'index_out_of_range'.","valid is true iff computed_root (canonical lowercase hex) equals root.","Limits: audit_path has at most 53 entries (max_audit_path_entries) and leaf decodes to at most 65536 bytes (max_leaf_bytes, 131072 hex characters); both fail with limit_exceeded, checked before any hashing."],"limits":{"max_audit_path_entries":53,"max_leaf_bytes":65536},"pricing":{"status":"unpriced","charge_usd":null},"input_schema":{"type":"object","additionalProperties":false,"required":["scheme","leaf","leaf_index","tree_size","audit_path","root"],"properties":{"scheme":{"type":"string","enum":["rfc9162","bitcoin"]},"leaf":{"type":"string","maxLength":131072,"pattern":"^([0-9a-f]{2})*$"},"leaf_index":{"type":"integer","minimum":0,"maximum":9007199254740991},"tree_size":{"type":"integer","minimum":1,"maximum":9007199254740991},"audit_path":{"type":"array","maxItems":53,"items":{"type":"string","pattern":"^[0-9a-f]{64}$"}},"root":{"type":"string","pattern":"^[0-9a-f]{64}$"}}},"output_schema":{"type":"object","additionalProperties":false,"required":["valid","reason","computed_root"],"properties":{"valid":{"type":"boolean"},"reason":{"type":["string","null"],"enum":["root_mismatch","path_length_wrong","index_out_of_range",null]},"computed_root":{"type":["string","null"],"pattern":"^[0-9a-f]{64}$"}}},"examples":[{"input":{"scheme":"rfc9162","leaf":"101112131415161718191a1b1c1d1e1f","leaf_index":0,"tree_size":1,"audit_path":[],"root":"3bfb960453ebaebf33727da7a1f4db38acc051d381b6da20d6d4e88f0eabfd7a"},"output":{"valid":true,"reason":null,"computed_root":"3bfb960453ebaebf33727da7a1f4db38acc051d381b6da20d6d4e88f0eabfd7a"}},{"input":{"scheme":"bitcoin","leaf":"4a5e1e4baab89f3a32518a88c31bc87f618f76673e2cc77ab2127b7afdeda33b","leaf_index":0,"tree_size":1,"audit_path":[],"root":"4a5e1e4baab89f3a32518a88c31bc87f618f76673e2cc77ab2127b7afdeda33b"},"output":{"valid":true,"reason":null,"computed_root":"4a5e1e4baab89f3a32518a88c31bc87f618f76673e2cc77ab2127b7afdeda33b"}}],"execute_url":"/v1/tools/merkle-proof-verify/versions/1.0.0/execute"}