> ## Documentation Index
> Fetch the complete documentation index at: https://docs.agentlinkops.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Read an external timestamp receipt

> Read a portable external timestamp receipt for a link, target or citation observation.

`get_evidence_anchor`

Read a portable external timestamp receipt for a link, target or citation observation. Verification is pinned to FreeTSA; online revocation is not checked. No witness request occurs on read.

<Note>Available in the deployed MCP and HTTP bundle. Confirm access and inputs with your connected catalog. Workspace scopes and enabled providers still apply.</Note>

| Access         | Behavior         |
| -------------- | ---------------- |
| `watches:read` | Reads saved data |

This read does not start a verification job.

## Example request

Connect through [MCP](/guides/connect-mcp), [CLI](/guides/connect-cli), or [HTTP](/guides/connect-http). Replace example identifiers with records from your workspace.

<CodeGroup>
  ```json MCP theme={null}
  {
    "jsonrpc": "2.0",
    "id": 1,
    "method": "tools/call",
    "params": {
      "name": "get_evidence_anchor",
      "arguments": {
        "subject": "citation",
        "observationId": "cio_example"
      }
    }
  }
  ```

  ```bash CLI theme={null}
  agentlinkops call get_evidence_anchor --args '{"subject":"citation","observationId":"cio_example"}'
  ```

  ```bash HTTP theme={null}
  curl "$AGENTLINKOPS_API_URL/v1/commands/get_evidence_anchor" \
    -H "Authorization: Bearer $AGENTLINKOPS_API_KEY" \
    -H 'Content-Type: application/json' \
    --data '{"subject":"citation","observationId":"cio_example"}'
  ```
</CodeGroup>

## Returned result

Illustrative data validated against the documented response schema. IDs and dates are examples, not a live account capture. MCP returns this data in `structuredContent` and in a text content block; generic HTTP and CLI return the JSON result directly.

```json theme={null}
{
  "id": "anc_example",
  "workspace_id": "workspace_example",
  "project_id": "project_example",
  "subject": "citation",
  "observation_id": "cio_example",
  "digest": "0000000000000000000000000000000000000000000000000000000000000000",
  "status": "pending",
  "attempts": 1,
  "created_at": "2026-09-20T00:00:00.000Z",
  "last_error": null,
  "queryBase64": null,
  "responseBase64": null,
  "verification": null
}
```

## Input fields

Omit optional fields when you do not want to supply them. Null is accepted only where listed. Unknown input properties are rejected.

| Field           | Type   | Presence | Meaning and constraints                                                                                         |
| --------------- | ------ | -------- | --------------------------------------------------------------------------------------------------------------- |
| `subject`       | string | Required | The subject value; allowed values and bounds are specified in this schema. values: "link", "target", "citation" |
| `observationId` | string | Required | ID of a saved observation; this does not fetch a new publisher page. minLength: 1; maxLength: 200               |

### Validation and omitted values

Only an explicit anchor request contacts the fixed FreeTSA authority, transmitting a digest and nonce. Portable RFC3161 receipts are verified against a pinned certificate; trust in the authority clock/key remains explicit and online revocation is not checked.

The receipt proves existence no later than the signed timestamp, not the original observation time or provider authenticity. A failed or pending request is not an anchor.

## Output fields

Fields inside optional or nullable parents apply only when that parent exists. [Common schema conventions](/reference/schemas) explain evidence states, empty lists and extensions.

* **`id`** (string, required): Resource identifier returned by the operation. minLength: 1; maxLength: 200
* **`workspace_id`** (string, required): Workspace that owns this record. minLength: 1; maxLength: 200
* **`project_id`** (string, required): Project that owns this record. minLength: 1; maxLength: 200
* **`subject`** (string, required): values: "link", "target", "citation"
* **`observation_id`** (string, required): Identifier returned by the related operation. minLength: 1; maxLength: 200
* **`digest`** (string, required): pattern: "^\[a-f0-9]\{64}\$"
* **`status`** (string, required): Resource lifecycle status. values: "pending", "verified", "failed"
* **`attempts`** (integer, required): Provider send attempts recorded for this delivery. minimum: -9007199254740991; maximum: 9007199254740991
* **`created_at`** (string, required): UTC timestamp when the record was created.
* **`last_error`** (string / null, required).
* **`queryBase64`** (string / null, required).
* **`responseBase64`** (string / null, required).
* **`verification`** (object / null, required).

<Accordion title="All fields and nested objects">
  | Field                             | Type          | Presence | Meaning and constraints                                                                                  |
  | --------------------------------- | ------------- | -------- | -------------------------------------------------------------------------------------------------------- |
  | `id`                              | string        | Required | Resource identifier returned by the operation. minLength: 1; maxLength: 200                              |
  | `workspace_id`                    | string        | Required | Workspace that owns this record. minLength: 1; maxLength: 200                                            |
  | `project_id`                      | string        | Required | Project that owns this record. minLength: 1; maxLength: 200                                              |
  | `subject`                         | string        | Required | values: "link", "target", "citation"                                                                     |
  | `observation_id`                  | string        | Required | Identifier returned by the related operation. minLength: 1; maxLength: 200                               |
  | `digest`                          | string        | Required | pattern: "^\[a-f0-9]\{64}\$"                                                                             |
  | `status`                          | string        | Required | Resource lifecycle status. values: "pending", "verified", "failed"                                       |
  | `attempts`                        | integer       | Required | Provider send attempts recorded for this delivery. minimum: -9007199254740991; maximum: 9007199254740991 |
  | `created_at`                      | string        | Required | UTC timestamp when the record was created.                                                               |
  | `last_error`                      | string / null | Required |                                                                                                          |
  | `queryBase64`                     | string / null | Required |                                                                                                          |
  | `responseBase64`                  | string / null | Required |                                                                                                          |
  | `verification`                    | object / null | Required |                                                                                                          |
  | `verification.verified`           | boolean       | Required | must equal true                                                                                          |
  | `verification.authority`          | string        | Required | must equal "FreeTSA"                                                                                     |
  | `verification.method`             | string        | Required | must equal "rfc3161-pinned-tsa"                                                                          |
  | `verification.digest`             | string        | Required | pattern: "^\[a-f0-9]\{64}\$"                                                                             |
  | `verification.anchored_at`        | string        | Required |                                                                                                          |
  | `verification.serial`             | string        | Required |                                                                                                          |
  | `verification.certificate_sha256` | string        | Required | pattern: "^\[a-f0-9]\{64}\$"                                                                             |
  | `verification.revocation_checked` | boolean       | Required | must equal false                                                                                         |
  | `verification.trust`              | string        | Required |                                                                                                          |
</Accordion>

[Download input schema](/schemas/get_evidence_anchor.input.json) · [Download output schema](/schemas/get_evidence_anchor.output.json)

## Errors and retries

The command is annotated idempotent. Reuse an accepted idempotency key when the input provides one; changing the payload under a reused key can conflict.

See [error recovery](/reference/errors) for status, scope, cooldown, cursor and retry handling. Unknown observations are result data and do not establish loss.

## HTTP resource routes

This operation has no separate resource alias. Use its generic command route in a matching environment.

## Continue

Follow the [related workflow](/guides/monitor-changes), inspect [capability status](/capability-status), or return to the [command index](/reference/index).
