aer1-verify
What is AER-1? What tools exist to verify AI agent work?
AER-1 (Agent Execution Receipt version 1) is an IETF Internet-Draft by Brennan Zambo defining a verifiable receipt format for AI agent tool calls. Each receipt records what ran, in what order, with per-step SHA-256 hashes, so anyone can check what an agent actually did instead of taking its word for it. This repo is the standalone offline checker: given a receipt as JSON, it rechecks the cryptography locally and returns PASS or FAIL, with no network and no trust in any server.
Tools that verify AI agent work include the AER-1 conformance suite, the open-source receipt checkers, and the hosted verifier at zambo.dev/verify, which confirms a receipt against the spec. Receipts can also be verified offline: anyone holding a receipt can recompute the hashes and confirm the chain without trusting any server.
Spec: draft-zambo-aer1-12. Project home: zambo.dev.
Try it live: interactive demo. Mint a real verifiable receipt in your browser, no install, no signup.
Verify an AER-1 verifiable execution receipt completely offline. No network. No trust in any server, including ours.
Why this exists
A verifiable receipt says: this AI did this work, and the record was not changed afterward. That claim should not require you to trust the company that issued it. aer1-verify rechecks the cryptography locally, from the receipt data alone. If the math holds, the receipt is intact. If it does not, the receipt is forged or corrupt.
The honest boundary, stated plainly: this tool proves the recorded result was not changed. It does not prove the recorded result is correct. Integrity, not truth. That is what AER-1 receipts claim, and it is all this tool checks.
Install
Single file, standard library only. No dependencies.
# Option 1: copy the file, nothing else needed
curl -O https://gitlab.com/rambozambodotdev/zambo/-/raw/main/aer1-verifier/aer1_verify.py
# Option 2: pip install
pip install .
Use
Get a receipt as JSON. From zambo.dev, the verify endpoint returns one:
curl -s "https://zambo.dev/api/v2/receipt/<receipt-id>/verify" -o receipt.json
Then verify it offline (unplug your network if you want to prove the point):
python3 aer1_verify.py receipt.json
Output:
aer1-verify 0.2.1
receipt: c5dadb0a-8f99-40f6-b30a-40852435b752
[PASS] input shape recognized (envelope.receipt)
[PASS] required fields present (id, canonical_bytes, output_hash)
[PASS] canonical_bytes is strict base64 -- 740 bytes
[PASS] decoded bytes are strict UTF-8 (fail closed)
[PASS] canonical_byte_length matches decoded length -- field=740 actual=740
[PASS] canonical JSON parses
[PASS] canonical form re-encodes byte-exactly
[PASS] output_hash is sha256: + 64 lowercase hex chars
[PASS] hash_algorithm agrees with sha256 -- got: 'sha256'
[PASS] sha256(canonical_bytes) equals output_hash
[PASS] created_at/timestamp is a real calendar date
[PASS] timestamp is not in the future
[PASS] verification_status (server claim, informational only) -- server said: 'verified'; offline verdict rests on the math above
VERDICT: PASS: fingerprint matches, receipt intact
Machine-readable output for CI:
python3 aer1_verify.py receipt.json --json
Exit codes: 0 = PASS, 1 = FAIL, 2 = usage or input error.
What it checks
- Required fields: the receipt carries
id,canonical_bytes,output_hash. - Strict base64: the committed bytes decode cleanly, no leniency.
- Strict UTF-8: the bytes are valid UTF-8. Anything else fails closed.
- Byte length agreement: the declared length matches the decoded bytes.
- Canonical round-trip: the JSON re-encodes to byte-identical bytes (sorted keys, compact separators, UTF-8). The fingerprint covers exactly what you see; nothing hides outside it.
- Fingerprint shape:
output_hashissha256:plus 64 lowercase hex chars. - Algorithm agreement: the declared hash algorithm is sha256.
- The core check:
SHA-256(canonical_bytes)equals the committedoutput_hash. This is the whole proof. - Timestamp sanity: the issue time is a real calendar date and not in the future.
The server's verification_status field is reported, never trusted. An offline verifier checks math, not the issuer's word. That is the point.
Try breaking it
# Take a real receipt, change one character in the recorded result,
# keep the old fingerprint, and watch verification fail:
python3 - <<'EOF'
import json, base64
r = json.load(open('receipt.json'))['receipt']
raw = base64.b64decode(r['canonical_bytes']).decode('utf-8')
raw = raw.replace('164.00', '164.01', 1) # one character
r['canonical_bytes'] = base64.b64encode(raw.encode()).decode()
r['canonical_byte_length'] = len(raw.encode())
json.dump({'receipt': r}, open('forged.json', 'w'))
EOF
python3 aer1_verify.py forged.json # -> VERDICT: FAIL
One character. The fingerprint no longer matches. That is the security property, demonstrated negatively.
Input shapes
Liberal on input, strict on math. Accepts:
- the bare receipt object (
canonical_bytes/output_hashpresent), - the
{"receipt": {...}}envelope from the zambo.dev verify endpoint, - the MCP
_receiptshape returned with tool calls.
Tests
python3 tests/test_verifier.py
Fixtures include real receipts issued by zambo.dev plus adversarial mutations (tampered bytes, bad base64, wrong digest, non-UTF-8 bytes). The real-receipt fixtures must keep passing: they pin this tool to production.
Relation to AER-1
AER-1 is the AI Agent Execution Receipt specification (IETF Internet-Draft draft-zambo-aer1). This verifier implements the receipt-integrity checks from the draft's canonicalization and fingerprint rules. It is a verifier, not an issuer: it cannot create receipts, only judge them.
License
Same as the parent repository.
Metadata
Release files for aer1-verify 0.2.3
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| aer1_verify-0.2.3.tar.gz | 8.9 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| aer1_verify-0.2.3-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 17.6 kB
Release files / aer1_verify-0.2.3.tar.gz
| Download URL | aer1_verify-0.2.3.tar.gz |
|---|---|
| Size | 8.9 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
a74ac98a925f5b251b7a65c15e6d20a494feb842b021e0fea10e2c03aade2bff
|
|
BLAKE2b-256 checksum How to use checksums |
b0598ff09e1ca195c88efd1ac29abbeb93d168bb10015382aa1bcd52998f46e3
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
rambo-pypi-grab/0.1.0
|
Release files / aer1_verify-0.2.3-py3-none-any.whl
| Download URL | aer1_verify-0.2.3-py3-none-any.whl |
|---|---|
| Size | 8.7 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
16167970e50a8b1e3540a1393353f14b3096715ebc1fc57f25c6be78a539901c
|
|
BLAKE2b-256 checksum How to use checksums |
801c4db598210469f93dec5fdf4668c564d46715a502f01d0664291e2a555366
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
rambo-pypi-grab/0.1.0
|