Skip to main content

Verifiable custody of agent-produced records: chained manifests, dual RFC 3161 witnesses, pinned Ed25519 signatures, push attestation, chronology tiers, shrink-only waivers — one offline verification command

Project description

receipt

Verifiable custody of agent-produced records.

Status

Shipped so far: the release-chain verifier, the append gate, ECMAScript-compatible canonical JSON, and standalone Ed25519 signing with consumer-pinned threshold keyrings. The machinery arrives by extraction from three production systems that each built it independently (pre-registered forecast records, an observation-ledger release chain, a signed statute corpus), behind a byte-equivalence gate: the extracted verifier must reproduce the source verifier's verdict, pass and fail alike, on the live production chain at a pinned commit before any system consumes the package. That gate has held end to end — the observation ledger consumes the package in production, with the differential harnesses re-proving equivalence on every package change.

What it provides (shipped rows) and what is still arriving

  • receipt.chain — append-only hash-chained manifests over record sets: enumerated genesis, content-addressed links, immutable-prefix verification
  • receipt.tsa — RFC 3161 timestamps from independent authorities, two per record, with per-witness honest degradation (an unavailable witness is recorded with a reason, never silently skipped)
  • receipt.sign — Ed25519 producer signatures verified against fingerprints pinned in the consumer's own committed code (shipped: ported ledger primitives, sign-side helpers, N-of-M keyrings, rotation by reviewed spec change)
  • receipt.attest — CI push attestation with self-anchoring enforcement epochs and a completeness sweep over every record-touching commit
  • receipt.ratchet — shrink-only exception registries recomputed from live state; an excused failure that starts passing is an error until removed
  • receipt.chronology — record-vs-event ordering tiers: does witnessed time prove the record existed ante quem — before the event it predicts or observes?
  • receipt verify — the outside auditor's command: a clone, commodity tools, one offline fail-closed verdict

Design principle

Trust anchors live in the consumer's committed code, never in runtime configuration a producer could swap. The package ships machinery; consumers pin roots.

The name

A receipt is the record you keep so anyone can check it later. Software already uses the word in exactly this sense: an app-store receipt is a signed proof validated offline, without trusting the store that issued it. This package writes receipts for agent-produced records; receipt verify is what happens when someone asks to see them.

Releases through 0.1.2 shipped as vidimus; those remain on PyPI under the old name.

License

Apache-2.0.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

receipt-0.2.0.tar.gz (65.9 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

receipt-0.2.0-py3-none-any.whl (32.6 kB view details)

Uploaded Python 3

File details

Details for the file receipt-0.2.0.tar.gz.

File metadata

  • Download URL: receipt-0.2.0.tar.gz
  • Upload date:
  • Size: 65.9 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.14

File hashes

Hashes for receipt-0.2.0.tar.gz
Algorithm Hash digest
SHA256 41ef973355cf0cc18fdb1f5f78e116a3b95b5b7b27f67f48cb4fcbdd1561448d
MD5 38501a86188a499a0e5c8bf31ad9ae2a
BLAKE2b-256 9ed5ee2efdb0903a37ecd389d344e4822e0ff03b0fda79bc3a801a83dd84d777

See more details on using hashes here.

Provenance

The following attestation bundles were made for receipt-0.2.0.tar.gz:

Publisher: publish.yml on TheAxiomFoundation/receipt

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file receipt-0.2.0-py3-none-any.whl.

File metadata

  • Download URL: receipt-0.2.0-py3-none-any.whl
  • Upload date:
  • Size: 32.6 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.14

File hashes

Hashes for receipt-0.2.0-py3-none-any.whl
Algorithm Hash digest
SHA256 365b680ebec7e27de108cf990c807f8f45a8e9ccb40801a570c451afdd4aaf7a
MD5 c807de71dd4266a923679f8047b943db
BLAKE2b-256 53719efb03a89f382e5bdf33588bfe38ce04ce992d9c08c46c9c02ac4fc3b9d9

See more details on using hashes here.

Provenance

The following attestation bundles were made for receipt-0.2.0-py3-none-any.whl:

Publisher: publish.yml on TheAxiomFoundation/receipt

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page