Three steps, no AirIndex servers required after step 1.
curl /api/provenance/record?table=AixIdentifier&id=aix%3Ahp%3AHD67TBTA
Extract identity columns (id, assetType, internalTable, internalId, mintedAt) from the AixIdentifier row for aix:hp:HD67TBTA. Canonicalize as JSON: sorted keys, no whitespace, ISO 8601 dates, explicit nulls. Prefix with AixIdentifier:. SHA-256 → hex. Must equal leaf.hash in the JSON.
Base64-decode anchor.tsa.signature_base64 and run:
openssl ts -verify -in tsr.der -CAfile <DigiCert TSA root cert>
Or, for the trustless path (once Bitcoin has confirmed):
ots verify proof.ots
Full verification methodology → — canonical hashing, Merkle proof construction, openssl + ots verification commands.
Raw JSON proof: /api/provenance/record?table=AixIdentifier&id=aix%3Ahp%3AHD67TBTA