API Reference
Events
इस पन्ने पर
Every event across the four contracts, what its fields carry, and when it fires. Indexed parameters are marked.
MoolamRegistry
PasskeyBound
event PasskeyBound(address indexed wallet, bytes32 qx, bytes32 qy, uint256 nonce)Fires on every successful bindPasskey, both the first bind and a rotation.
| Field | Meaning |
|---|---|
wallet | The wallet the key now belongs to |
qx, qy | The passkey public key coordinates |
nonce | The bind nonce this signature consumed |
PassportRegistered
event PassportRegistered(
bytes32 indexed passportId,
address indexed creator,
uint256 indexed generatorAgentId,
bytes32 parentId,
uint64 phash,
bytes32 blockhash256,
bytes32 manifestHash,
uint8 kind,
uint8 fingerprintVersion,
string metadataURI
)Fires on register and on appendEdit. Indexers build the whole provenance graph from this one
event. It is also the trigger for the Chainlink CRE workflow.
| Field | Meaning |
|---|---|
passportId | The sha256 of the exact image bytes, and the token id |
creator | The wallet that owns the token |
generatorAgentId | The ERC-8004 agent that generated the image, zero if none |
parentId | The passport this one was edited from, zero for an original |
phash | The 64 bit perceptual hash |
blockhash256 | The 256 bit block hash recorded with the image |
manifestHash | The sha256 of the C2PA manifest store, zero when there is none |
kind | 0 Generated, 1 Captured, 2 Edited |
fingerprintVersion | Which fingerprint algorithm produced phash |
metadataURI | Where the image, manifest and thumbnail live |
The ERC-721 Transfer from the zero address fires in the same transaction.
VerificationAttested
event VerificationAttested(
bytes32 indexed passportId, address indexed receiver,
bool matched, uint16 distance, bytes32 recomputed
)Fires when a listed receiver rechecks a passport and records the result, which in practice means a
Chainlink CRE report landed through one of three receivers: MoolamReceiver, the door for Chainlink's
network, listed again since 2026-10-02, or one of the two SimulationReceiver contracts the policy has
listed since 2026-09-27 for runs in Chainlink's simulator. Rows from before 2026-09-26 name
MoolamReceiver or its sealed twin.
| Field | Meaning |
|---|---|
passportId | The passport that was rechecked |
receiver | The listed receiver that wrote the result |
matched | Whether the recomputed fingerprint matched the recorded one |
distance | The perceptual hash distance measured |
recomputed | The fingerprint the verifier computed |
PassportFlagged
event PassportFlagged(
bytes32 indexed passportId, address indexed challenger,
uint256 bond, bytes32 evidenceHash, string evidenceURI
)Fires on flag, when someone challenges a passport and posts a bond.
| Field | Meaning |
|---|---|
passportId | The passport being challenged |
challenger | Who opened the dispute |
bond | The bond now held by the registry until the dispute is settled |
evidenceHash | The keccak256 of the evidence URI, stored so the URI cannot be swapped |
evidenceURI | Where the evidence lives |
DisputeResolved
event DisputeResolved(bytes32 indexed passportId, bool upheld, address indexed resolver)Fires on resolve. upheld true means the challenge stood and the passport is now marked disputed
for good.
Withdrawn and WithdrawnTo
event Withdrawn(address indexed who, uint256 amount)
event WithdrawnTo(address indexed who, address indexed to, uint256 amount)Fire when someone pulls what they are owed. WithdrawnTo also names where the money went. In both
the credit spent is who's own, zeroed before the transfer.
Rescued
event Rescued(address indexed token, address indexed to, uint256 amount)Fires on rescueERC20 and rescueNative. token is the zero address for native token. It never
covers a bond or an unclaimed credit.
Inherited
Transfer, Approval and ApprovalForAll from ERC-721. Paused and Unpaused from Pausable.
OwnershipTransferStarted and OwnershipTransferred from Ownable2Step. EIP712DomainChanged
from EIP712.
MoolamConsent
ConsentSet
event ConsentSet(
bytes32 indexed passportId,
address indexed writer,
uint256 indexed index,
Consent consent,
string constraintInfo,
uint64 at
)Fires once for every statement a passport's holder writes about AI use, from setConsent and once
per passport from setConsentBatch, in the order the batch names them. There is no event for a
statement being removed, because none ever is.
| Field | Meaning |
|---|---|
passportId | The passport the statement is about |
writer | The address that held the passport when the statement was written |
index | Where this statement sits in the passport's history, counting from zero |
consent | The four use values: 0 not stated, 1 allowed, 2 not allowed, 3 conditions apply |
constraintInfo | The conditions in free text, empty unless a use is Constrained |
at | The block timestamp the statement was written at |
The event carries exactly what was stored and nothing else, so an indexer reading the logs and a caller reading the storage cannot disagree. The full contract is in MoolamConsent.
VerifierPolicy
| Event | Fires when |
|---|---|
ChangeQueued(bytes32 indexed id, bytes32 indexed op, bytes data, uint64 executeAfter) | A change is put in the queue and its 24 hour clock starts |
ChangeExecuted(bytes32 indexed id) | A queued change runs, alongside the event for that specific change |
ChangeCancelled(bytes32 indexed id) | A queued change is dropped before it runs |
ReceiverAdded(address indexed receiver) | An address may now write attestations, from either bootstrapAddReceiver or an executed queueAddReceiver |
ReceiverRemoved(address indexed receiver) | An address may no longer write attestations. No delay |
ResolverSet(address indexed resolver) | The dispute resolver changed, and once in the constructor |
TreasurySet(address indexed treasury) | The treasury changed, and once in the constructor |
DisputeBondSet(uint256 bond) | The dispute bond changed, and once in the constructor |
BootstrapFinalized() | The setup window closed. From here on every widening of trust waits 24 hours |
Plus OwnershipTransferStarted and OwnershipTransferred.
MoolamReceiver and SimulationReceiver
Every one of these is an owner action, and each emits so the change is visible on chain.
| Event | Fires when |
|---|---|
ForwarderAddressUpdated(address indexed previousForwarder, address indexed newForwarder) | The forwarder allowed to call onReport is swapped |
ExpectedAuthorUpdated(address indexed previousAuthor, address indexed newAuthor) | The pinned workflow author changes |
ExpectedWorkflowNameUpdated(bytes10 indexed previousName, bytes10 indexed newName) | The pinned workflow name changes |
ExpectedWorkflowIdUpdated(bytes32 indexed previousId, bytes32 indexed newId) | The pinned workflow id changes |
SecurityWarning(string message) | Chainlink's template warns that the forwarder was set to the zero address, which it accepts rather than refuses |
Plus OwnershipTransferred.
A successful onReport emits nothing of its own. The VerificationAttested on the registry is the
record.
What the indexer consumes
The Envio indexer subscribes to six registry events, two policy events and one consent event:
MoolamRegistry:PasskeyBound,PassportRegistered,VerificationAttested,PassportFlagged,DisputeResolved,TransferVerifierPolicy:ReceiverAdded,ReceiverRemovedMoolamConsent:ConsentSet
Transfer is what keeps Passport.owner current on a sale while Passport.creator never moves.
The consent register was deployed ten days after the other three, so it carries its own start block in
config.yaml and the sync skips 2.7 million blocks of nothing. No screen reads a statement from the
index today: the passport page and the verify service both read the contract directly, because a
statement written a moment ago is exactly the one a reader must not miss.