AetherProof — the open-source receipt engine. Prototype of Signet.
Project description
AetherProof
The open-source receipt engine. Prototype of Signet.
Generate cryptographic receipts that prove an AI output is real and unmodified — no servers, no dependencies, verifiable forever offline.
pip install aetherproof
Run aetherproof with no arguments for the interactive menu:
.+######+. AETHERPROOF
## ## v0.2.0
# /\ # Cryptographic receipt engine
# / \ # Prototype of Signet · R0/L2
# / /\ \ #
# / / \ \ # github.com/pulkit6732/aetherproof
# /______\ \ # Verify(receipt, pk, log) = TRUE
# \______/ #
## ##
'######'
────────────────────────────────────────────────
Sign · Verify · Inspect · Log · Keygen
What it does
Every time an AI model produces output, AetherProof issues a tamper-proof signed receipt:
Receipt ID : receipt_1700000000000
Model Root : abcdef0123456789... (SHA-256 Merkle of model weights)
Output Hash : fedcba9876543210... (SHA-256 of the output)
Timestamp : 2026-06-11T15:30:00Z
Signature : ✓ Ed25519 VALID
One bit changes → signature fails instantly.
Quick start
Easy mode (for anyone)
aetherproof
Step-by-step wizard:
- What model did you use?
- Paste the output
- Receipt is signed and saved
Expert mode (for developers)
# Generate a receipt
aetherproof sign model.onnx output.txt
# Verify it (offline, forever)
aetherproof verify receipt.json
# Inspect all fields
aetherproof inspect receipt.json
# Test tamper detection
aetherproof tamper receipt.json
The invariant (what makes this real)
Verify(receipt, public_key, log) = TRUE
using ONLY those three inputs, forever, with zero dependency on
AetherProof servers, any vendor SDK, or any hardware driver.
This is not a claim. It's built in. Offline verification uses only:
- The receipt file
- The public key (PEM file)
- (Optional) transparency log entry
No network. No API calls. No special hardware. Works in 2026, 2035, 2050.
How offline verification actually works
You can prove a receipt is genuine with no internet and no AetherProof code at all — the math is open. Here is the exact process.
What you need (the three inputs)
- The receipt (
ap_xxxx.json) — the signed claim. - The public key (
ap_xxxx.pub, a PEM file) — shipped beside the receipt. - (Optional) the original output file — only if you also want to prove the output itself wasn't changed.
The steps
- Rebuild the signed message. The receipt is signed over a canonical, length-prefixed preimage of its fields (version, model root, model-root-type, input commitment, output hash, timestamp, log sequence, hardware evidence, log anchor). The encoding is injective, so no two distinct receipts can share a preimage (and thus a signature).
- Check the Ed25519 signature of that preimage against the public key. If it verifies, the receipt's contents are exactly what was signed — a single changed bit fails this check.
- (Optional) Re-hash the output file with SHA-256 (raw bytes, streamed) and
compare to the receipt's
output_hash. If they match, the output is unchanged.
The one-command way
# signature only
aetherproof verify ap_xxxx.json
# signature + confirm the output file still matches
aetherproof verify ap_xxxx.json --output original_output.txt
# scripting / CI: machine-readable, exits non-zero on any failure
aetherproof verify ap_xxxx.json --output original_output.txt --quiet
# -> {"valid": true, "signature_valid": true, "output_unmodified": true}
Exit code is 0 only when everything checks out, 1 on any tampering — so
aetherproof verify … && deploy is safe in a pipeline.
Verify without AetherProof (any Ed25519 library)
Because the format is open, anyone can verify with a standard crypto library —
no dependency on this tool. In Python with cryptography:
import json, hashlib
from cryptography.hazmat.primitives.serialization import load_pem_public_key
r = json.load(open("ap_xxxx.json"))
pub = load_pem_public_key(open("ap_xxxx.pub", "rb").read())
# rebuild the injective preimage: "<len>:<field>" for each field, in order
fields = [
r["receipt_version"], r["model_weight_root"], r["model_root_type"],
r["input_commitment"], r["output_hash"], str(r["timestamp_ms"]),
str(r["log_sequence"]),
json.dumps(r["hw_evidence"], sort_keys=True, separators=(",", ":")),
r["log_anchor"],
]
preimage = "".join(f"{len(f)}:{f}" for f in fields).encode("utf-8")
pub.verify(bytes.fromhex(r["signature"]), preimage) # raises if invalid
print("signature OK")
# optional: prove the output file is unchanged
digest = hashlib.sha256(open("original_output.txt", "rb").read()).hexdigest()
print("output unmodified:", digest == r["output_hash"])
That is the whole trust model: a public key and some SHA-256 + Ed25519 math you can run anywhere, forever.
Architecture (god file)
AetherProof is Layer 2 of the Signet stack. Signet adds hardware roots, compliance packs, and a transparency network on top.
License
AGPL-3.0-or-later. Use it, deploy it, fork it, verify it — but if you run a modified version as a network service, you must release your changes under the same license. (Need a permissive/commercial license? That's what Signet is for.)
AetherProof is what you get when you need tamper-proof proof.
Signet is what you get when you need hardware roots, compliance packs, and a transparency log.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file aetherproof-0.2.1.tar.gz.
File metadata
- Download URL: aetherproof-0.2.1.tar.gz
- Upload date:
- Size: 49.9 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.13.5
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
739a5919d26bc1a018acc247212b4d37dfd3ebd45e232f7db2ef6115fc1e20c3
|
|
| MD5 |
f20c0bcefe6789b9b9d0497ff036a80d
|
|
| BLAKE2b-256 |
f43e58d4a4f2857830f04d488869940d844b2d883db504b233b63da029e5119e
|
File details
Details for the file aetherproof-0.2.1-py3-none-any.whl.
File metadata
- Download URL: aetherproof-0.2.1-py3-none-any.whl
- Upload date:
- Size: 44.5 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.13.5
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
8848dfda3a62d8df10daf647d1489cadbcb52a131d39a5dd9c5c9ef485997fe8
|
|
| MD5 |
aae38bd12147ca48cab96431d0619630
|
|
| BLAKE2b-256 |
2dfde64697e23f460d2fa063a87d657cbd477a4225e9b4f25a71e58a2080df01
|