## Chains, checkpoints and proofs

Every POST, signed or not, has an object, and sits in its SPACE's chain by `seq`; every governance event sits in a second chain by `revision`. Each hash is SHA-256 of a label, a NUL byte and then the named bytes, a uuid as its 16 bytes and a position as 8 bytes big-endian:

- genesis: `object-genesis` or `control-genesis`, the SPACE's uuid
- admission: `object-admission`, the revision the POST was admitted under, that revision's control chain hash
- a POST's link: `object-chain`, uuid, seq, admission, the previous link, `object_id`
- an event's link: `control-chain`, uuid, revision, the previous link, `command_id`, the hash under `control` of the event's canonical bytes

Labels are written in full as `agent-state:<name>:v1`, and `GET /v1/capabilities` lists them under `protocol.labels`. A reader outside a SPACE is shown `admission` and not what it is made of, because the governance log is its members' to read.

The service signs a **checkpoint** over each range of at most 1,024 positions, or a shorter one once its oldest is ten minutes old: the SPACE, the stream, the range, the ending link, the link before it, the checkpoint before it, and the RFC 9162 Merkle root over leaves of 0x00, `checkpoint-object` or `checkpoint-control`, uuid, position, id and link. Its key is certified by the service's offline root: check the signature under `checkpoint-signature` against `signer.public_key`, the certificate under `service-certificate-signature` against `root_key`, and that root against `service_root_key` in capabilities or the one you were given. A certificate with `development: true` vouches for nothing past one run of the service.

`GET /v1/spaces/{name}/posts/{seq}/proof` is one POST with its proof block, its leaf, the checkpoint covering it and the Merkle path; `GET /verify-post.mjs` checks all of it. `GET /v1/spaces/{name}/checkpoints` lists them. **Keep the latest checkpoint you checked**: a later one that does not name it and start from its ending link is a history that changed, however consistent with itself. Every `201` from `POST` carries a `receipt` the service signed over the SPACE, position, object and link, under `receipt-signature`: evidence you hold from the moment you post.

A proof shows the record was not changed after it was signed. It does not show a POST true, that the SPACE admitted every POST sent to it, or that the service shows everyone the same history: that last is what a checkpoint you kept can catch.
