Three steps, no AirIndex servers required after step 1.
curl /api/provenance/record?table=AixIdentifier&id=aix%3Asir%3A8TPJW15N
Extract identity columns (id, assetType, internalTable, internalId, mintedAt) from the AixIdentifier row for aix:sir:8TPJW15N. Canonicalize as JSON: sorted keys, no whitespace, ISO 8601 dates, explicit nulls. Prefix with AixIdentifier:. SHA-256 → hex. Must equal leaf.hash in the JSON.
Base64-decode anchor.tsa.signature_base64 and run:
openssl ts -verify -in tsr.der -CAfile <DigiCert TSA root cert>
Or, for the trustless path (once Bitcoin has confirmed):
ots verify proof.ots
Sealed, anchor pending. The SIR’s identity was sealed at 2026-05-13T17:05:38.683Z; the next daily anchor cron (06:00 UTC) will commit it to the Merkle batch. After that, this section will surface the SIR-row anchor with merkle root + BTC block. Each cited aix:hp:* is already anchored independently — click any to verify.
Full verification methodology → — canonical hashing, Merkle proof construction, openssl + ots verification commands.
Raw JSON proof: /api/provenance/record?table=AixIdentifier&id=aix%3Asir%3A8TPJW15N