curl --request GET \
--url "https://cache.example.com/cache/chunks/did%3Aopenpayload%3A1111111111111111111111/e93e6c49-d280-4078-81bd-16f09be99e7e" \
--header "X-Device-Id: mobile-01" \
--header "X-Service-Id: did:openpayload:1111111111111111111111#cache" \
--header "X-Cache-Endpoint: https://cache.example.com" \
--header "X-Key-Id: did:openpayload:1111111111111111111111#signing" \
--header "X-Timestamp: <current-RFC3339-timestamp>" \
--header "X-Nonce: <unique-random-nonce>" \
--header "X-Signature: <base64-signature>"
Cache API
Get message chunks
Retrieve the encrypted chunks belonging to one message group
curl --request GET \
--url "https://cache.example.com/cache/chunks/did%3Aopenpayload%3A1111111111111111111111/e93e6c49-d280-4078-81bd-16f09be99e7e" \
--header "X-Device-Id: mobile-01" \
--header "X-Service-Id: did:openpayload:1111111111111111111111#cache" \
--header "X-Cache-Endpoint: https://cache.example.com" \
--header "X-Key-Id: did:openpayload:1111111111111111111111#signing" \
--header "X-Timestamp: <current-RFC3339-timestamp>" \
--header "X-Nonce: <unique-random-nonce>" \
--header "X-Signature: <base64-signature>"
Large encrypted messages can be divided into chunks. Each chunk has its own
Also send the standard Cache proof headers.
message_id, while every chunk in the set shares one UUID message_group_id.
This endpoint returns a complete currently cached chunk set for one recipient and group. An assured set remains hidden while incomplete. Your client remains responsible for validating ordering and reassembling the encrypted content.
The network accepts at most 2 MiB of decoded data per chunk. OpenPayload does not define a network-wide maximum chunk count or aggregate message size. Cache retrieval returns the chunks that were actually stored; the recipient still validates the declared set before reassembly.
Signed proof
Use operationchunks and set subject to the exact messageGroupId:
openpayload:cache:retrieval-proof:v1
operation=chunks
did=did:openpayload:1111111111111111111111
device_id=mobile-01
service_id=did:openpayload:1111111111111111111111#cache
cache_endpoint=https://cache.example.com
key_id=did:openpayload:1111111111111111111111#signing
timestamp=<current-RFC3339-timestamp>
nonce=<unique-random-nonce>
subject=e93e6c49-d280-4078-81bd-16f09be99e7e
Request
string
required
Recipient DID.
string
required
UUID shared by the requested chunks.
string
Device to bind into the proof, when retrieving for one device.
curl --request GET \
--url "https://cache.example.com/cache/chunks/did%3Aopenpayload%3A1111111111111111111111/e93e6c49-d280-4078-81bd-16f09be99e7e" \
--header "X-Device-Id: mobile-01" \
--header "X-Service-Id: did:openpayload:1111111111111111111111#cache" \
--header "X-Cache-Endpoint: https://cache.example.com" \
--header "X-Key-Id: did:openpayload:1111111111111111111111#signing" \
--header "X-Timestamp: <current-RFC3339-timestamp>" \
--header "X-Nonce: <unique-random-nonce>" \
--header "X-Signature: <base64-signature>"
Response
200 Response
{
"count": 2,
"complete": true,
"chunks": [
{
"message_id": "<chunk-message-uuid>",
"recipient": "did:openpayload:1111111111111111111111",
"chunked": true,
"chunk": {
"messageGroupId": "e93e6c49-d280-4078-81bd-16f09be99e7e",
"sequenceNumber": 0,
"totalChunks": 2
},
"envelope": {},
"proof": {}
}
]
}
Straight to the point
GET /cache/chunks/{did}/{messageGroupId}
- Proof operation:
chunks - Proof subject: exact group UUID
- Sort returned chunks by response field
sequenceNumber complete: falsewith an emptychunksarray means the assured set is absent or still incomplete- Validate ordering, completeness, and the declared group before reassembly

