SourceScore

VERITAS API docs

Curated AI/ML claim records and candidate evidence retrieval for LLM developers. A match is not a truth verdict. The public API is free and requires no auth or signup. OpenAPI 3.1 spec at /api/v1/openapi.json.

Quick start (5 min)

Every claim has a stable 16-hex-char id and cited primary evidence. Of the current 384 claims, 368 have two or more sources and 16 have one primary source. Records include SourceScore-issued HMAC integrity metadata and a JSON envelope at /api/v1/claims/<id>.json. No auth needed for v0 read endpoints.

curl

# Browse the full catalog
curl https://sourcescore.org/api/v1/claims.json | jq '.count, .claims[0]'

# Fetch a specific claim (e.g. GPT-4 release date)
curl https://sourcescore.org/api/v1/claims/09eea8fb1a8ccebf.json

# Search for claims about a topic
curl "https://sourcescore.org/api/v1/search?q=llama&limit=5"

# Match a natural-language claim against the catalog
curl -X POST https://sourcescore.org/api/v1/verify \
  -H 'Content-Type: application/json' \
  -d '{"claim": "Llama 3.1 was released in July 2024"}'

JavaScript (fetch)

// Browse catalog
const catalog = await fetch('https://sourcescore.org/api/v1/claims.json')
  .then(r => r.json());
console.log(`${catalog.count} verified claims`);

// Fetch by id
const claim = await fetch(
  'https://sourcescore.org/api/v1/claims/09eea8fb1a8ccebf.json'
).then(r => r.json());
console.log(claim.citedAs);

// Verify a natural-language claim
const verification = await fetch(
  'https://sourcescore.org/api/v1/verify',
  {
    method: 'POST',
    headers: { 'Content-Type': 'application/json' },
    body: JSON.stringify({
      claim: 'Llama 3.1 was released in July 2024',
    }),
  },
).then(r => r.json());

if (verification.bestMatch) {
  console.log('Candidate record:', verification.bestMatch.statement);
} else {
  console.log('No candidate record cleared the retrieval gates.');
}

Python (requests)

import requests

# Browse catalog
catalog = requests.get(
    'https://sourcescore.org/api/v1/claims.json'
).json()
print(f'{catalog["count"]} verified claims')

# Fetch by id
claim = requests.get(
    'https://sourcescore.org/api/v1/claims/09eea8fb1a8ccebf.json'
).json()
print(claim['citedAs'])

# Match a natural-language claim against the catalog
verification = requests.post(
    'https://sourcescore.org/api/v1/verify',
    json={'claim': 'Llama 3.1 was released in July 2024'},
).json()

if verification.get('bestMatch'):
    print('Candidate record:', verification['bestMatch']['statement'])
else:
    print('No candidate record cleared the retrieval gates.')

GET /api/v1/claims.json — catalog

Full list of every verified claim (light per-claim summary).

Example response

{
  "apiVersion": "v1",
  "methodology": "https://sourcescore.org/methodology/",
  "generated": "2026-05-16T11:07:02.574Z",
  "count": 384,
  "claims": [
    {
      "id": "ad17e76a8baad7a1",
      "vertical": "ai-ml",
      "subject": "Transformer architecture",
      "predicate": "introduced_in_paper",
      "object": "Attention Is All You Need (Vaswani et al., 2017)",
      "statement": "Transformer architecture introduced in paper: Attention Is All You Need (Vaswani et al., 2017).",
      "confidence": 1,
      "signatureShort": "a1b2c3d4",
      "detailUrl": "https://sourcescore.org/api/v1/claims/ad17e76a8baad7a1.json"
    }
  ]
}

Signature prefixes in documentation examples are illustrative; refetch the canonical record for the current value.

GET /api/v1/claims/{id}.json — per-claim envelope

Full claim record with sources, excerpts, integrity metadata, and a ready-to-paste citation. The HMAC tag is not publicly independently verifiable; refetch the canonical HTTPS record and inspect its cited evidence.

Example response

{
  "apiVersion": "v1",
  "methodology": "https://sourcescore.org/methodology/",
  "canonical": "https://sourcescore.org/claims/09eea8fb1a8ccebf/",
  "claim": {
    "vertical": "ai-ml",
    "subject": "GPT-4",
    "predicate": "released_on",
    "object": "2023-03-14",
    "statement": "GPT-4 released on: 2023-03-14.",
    "confidence": 1,
    "sources": [
      {
        "url": "https://openai.com/index/gpt-4-research/",
        "title": "GPT-4",
        "publisher": "OpenAI",
        "publishedDate": "2023-03-14",
        "accessedDate": "2026-05-16",
        "type": "official-blog",
        "excerpt": "We've created GPT-4, the latest milestone..."
      }
    ],
    "publishedAt": "2026-05-16T00:00:00Z",
    "lastVerified": "2026-05-16",
    "methodologyVersion": "veritas-v0.1",
    "tags": ["gpt-4", "openai", "release", "2023"],
    "id": "09eea8fb1a8ccebf"
  },
  "signature": {
    "algorithm": "HMAC-SHA256",
    "signedBy": "did:web:sourcescore.org",
    "signedAt": "2026-05-16T00:00:00.000Z",
    "signature": "fa4e121cda0e5dfd24b70fbf3ebaab85f65b116141c2a15335a9297f2328b729"
  },
  "citedAs": "GPT-4 released on: 2023-03-14. — SourceScore Claim 09eea8fb1a8ccebf (verified 2026-05-16, signed fa4e121c…). https://sourcescore.org/claims/09eea8fb1a8ccebf/"
}

POST /api/v1/verify — match a natural-language claim

Submit a claim in plain English; receive the best matching catalog record or notVerified: true. The legacy record-confidence gate is configurable via minConfidence (default 0.85). The response includes candidate records and canonical URLs. Treat it as retrieval, not entailment or a truth verdict.

Request

POST /api/v1/verify
Content-Type: application/json

{
  "claim": "Llama 3.1 was released in July 2024",
  "vertical": "ai-ml",
  "minConfidence": 0.85
}

Illustrative response shape (candidate found)

{
  "apiVersion": "v1",
  "methodology": "https://sourcescore.org/methodology/",
  "query": "Llama 3.1 was released in July 2024",
  "minConfidence": 0.85,
  "method": "keyword",
  "note": "matchScore is similarity, not a truth verdict.",
  "matches": [
    {
      "claim": {
        "id": "a55484ab8b4bdf4e",
        "subject": "Llama 3.1",
        "predicate": "released_on",
        "object": "2024-07-23",
        "statement": "Llama 3.1 released on: 2024-07-23.",
        "confidence": 1,
        "signatureShort": "<current prefix>",
        "detailUrl": "https://sourcescore.org/api/v1/claims/a55484ab8b4bdf4e.json"
      },
      "matchScore": 0.42,
      "rationale": "Keyword overlap on: llama, released, 2024."
    }
  ],
  "bestMatch": { "id": "a55484ab8b4bdf4e", ... },
  "signature": {
    "algorithm": "HMAC-SHA256",
    "signedBy": "did:web:sourcescore.org",
    "signedAt": "<response time>",
    "signature": "..."
  }
}

Illustrative response shape (no candidate cleared the gates)

{
  "apiVersion": "v1",
  "methodology": "https://sourcescore.org/methodology/",
  "query": "GPT-5 reaches AGI in 2025",
  "minConfidence": 0.85,
  "method": "keyword",
  "note": "matchScore is similarity, not a truth verdict.",
  "matches": [],
  "notVerified": true,
  "signature": { "algorithm": "HMAC-SHA256", ... }
}

GET /api/v1/methodology.json — methodology metadata

Returns the published methodology metadata, source-type rules, and endpoint index. It documents the current public API; proposed higher-volume pricing is separately explained on /pricing/ .

Authentication

v0 — no authentication. All read endpoints (catalog, per-claim, search, verify) are public and rate-limited only by Cloudflare network-level DDoS protection. CORS is permissive (Access-Control-Allow-Origin: *); browser, server, and LLM-agent callers all work.

Higher-volume access is only being evaluated. There are no public API keys, accounts, dashboard, checkout, billing, or SLA today.

Rate limits

v0: there is no account-level meter or public API-key quota. Standard Cloudflare network abuse protection may throttle abusive traffic; no fixed requests-per-minute threshold is promised.

Clients should use timeouts, cache stable claim records, and handle HTTP 429 or transient 5xx responses with bounded backoff. The API does not currently promise per-client rate-limit headers or an SLA.

Record integrity metadata (HMAC-SHA256)

Every per-claim envelope contains a SourceScore-issued HMAC tag over a canonical projection of the claim. The shared secret is not public, so public users cannot recompute or independently verify the tag.

Check a record by refetching its canonical HTTPS URL and comparing the claim content and cited evidence your application uses. The tag is not a public-key signature or a third-party identity proof.

Error format

All errors return a JSON envelope:

{
  "error": "Body must be JSON.",
  "detail": "Unexpected token } at position 17."  // optional
}

Common status codes:400 bad input; 404 claim id not found; 405 wrong method; 429 rate-limited; 503 catalog index temporarily unavailable.

Framework integrations

Integration guides for retrieving candidate records and carrying their evidence into an explicit review step:

Support

Questions, bug reports, and SDK feedback: hello@caslonmedia.com. The source repository is private, so there is no public issue tracker — email is the single support channel.

Proposed higher-volume access can be requested via the API access page.