Skip to main content

Verifiable custody of agent-produced records: chained manifests, dual RFC 3161 witnesses, pinned Ed25519 signatures, push attestation, chronology tiers, shrink-only waivers — one offline verification command

Project description

receipt

Verifiable custody of agent-produced records.

Status

Shipped so far: the release-chain verifier, the append gate, ECMAScript-compatible canonical JSON, and standalone Ed25519 signing with consumer-pinned threshold keyrings. The machinery arrives by extraction from three production systems that each built it independently (pre-registered forecast records, an observation-ledger release chain, a signed statute corpus), behind a byte-equivalence gate: the extracted verifier must reproduce the source verifier's verdict, pass and fail alike, on the live production chain at a pinned commit before any system consumes the package. That gate has held end to end — the observation ledger consumes the package in production, with the differential harnesses re-proving equivalence on every package change.

What it provides (shipped rows) and what is still arriving

  • receipt.chain — append-only hash-chained manifests over record sets: enumerated genesis, content-addressed links, immutable-prefix verification
  • receipt.tsa — RFC 3161 timestamps from independent authorities, two per record, with per-witness honest degradation (an unavailable witness is recorded with a reason, never silently skipped)
  • receipt.sign — Ed25519 producer signatures verified against fingerprints pinned in the consumer's own committed code (shipped: ported ledger primitives, sign-side helpers, N-of-M keyrings with legacy verification generations — retired keys verify immutable history only; rotation by reviewed spec change)
  • receipt.attest — CI push attestation with self-anchoring enforcement epochs and a completeness sweep over every record-touching commit
  • receipt.ratchet — shrink-only exception registries recomputed from live state; an excused failure that starts passing is an error until removed
  • receipt.chronology — record-vs-event ordering tiers: does witnessed time prove the record existed ante quem — before the event it predicts or observes?
  • receipt verify — the outside auditor's command: a clone, commodity tools, one offline fail-closed verdict

Design principle

Trust anchors live in the consumer's committed code, never in runtime configuration a producer could swap. The package ships machinery; consumers pin roots.

The name

A receipt is the record you keep so anyone can check it later. Software already uses the word in exactly this sense: an app-store receipt is a signed proof validated offline, without trusting the store that issued it. This package writes receipts for agent-produced records; receipt verify is what happens when someone asks to see them.

Releases through 0.1.2 shipped as vidimus; those remain on PyPI under the old name.

License

Apache-2.0.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

receipt-0.3.0.tar.gz (70.5 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

receipt-0.3.0-py3-none-any.whl (34.1 kB view details)

Uploaded Python 3

File details

Details for the file receipt-0.3.0.tar.gz.

File metadata

  • Download URL: receipt-0.3.0.tar.gz
  • Upload date:
  • Size: 70.5 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.14

File hashes

Hashes for receipt-0.3.0.tar.gz
Algorithm Hash digest
SHA256 31085b3c299eb0688a78a5c4162568cbe1ed2edb5fd4fdc56e1e672eef2d9f4f
MD5 2fdb4329e3bc7abcb6cdfba929641b01
BLAKE2b-256 d107d093b29386e68be6b195efbc02ee0b5fb8ce41e6b2efa8cba8eba4f19603

See more details on using hashes here.

Provenance

The following attestation bundles were made for receipt-0.3.0.tar.gz:

Publisher: publish.yml on TheAxiomFoundation/receipt

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file receipt-0.3.0-py3-none-any.whl.

File metadata

  • Download URL: receipt-0.3.0-py3-none-any.whl
  • Upload date:
  • Size: 34.1 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.14

File hashes

Hashes for receipt-0.3.0-py3-none-any.whl
Algorithm Hash digest
SHA256 89414893651cb611d7b2740507a0c61cadca666829e9df598c590636a6fdcd49
MD5 8dcdfe122dff1dc6293258fce95c5527
BLAKE2b-256 fae1e47249df9226688a64bf6563db8fdf06bfe96b0e6eee8ae69166a2f1c865

See more details on using hashes here.

Provenance

The following attestation bundles were made for receipt-0.3.0-py3-none-any.whl:

Publisher: publish.yml on TheAxiomFoundation/receipt

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page