Skip to main content

receipt

Verifiable custody of agent-produced records.

Status

Shipped so far: the release-chain verifier, the append gate, ECMAScript-compatible canonical JSON, standalone Ed25519 signing with consumer-pinned threshold keyrings, RFC 3161 dual-witness verification, and workflow-provenance verification. The machinery arrives by extraction from three production systems that each built it independently (pre-registered forecast records, an observation-ledger release chain, a signed statute corpus), behind a byte-equivalence gate: the extracted verifier must reproduce the source verifier's verdict, pass and fail alike, on the live production chain at a pinned commit before any system consumes the package. That gate has held end to end — the observation ledger consumes the package in production, with the differential harnesses re-proving equivalence on every package change.

What it provides (shipped rows) and what is still arriving

  • receipt.chain — append-only hash-chained manifests over record sets: enumerated genesis, content-addressed links, immutable-prefix verification
  • receipt.tsa — RFC 3161 dual-witness verification against consumer-committed trust bundles and signer identities, with explicit unavailable-witness outcomes
  • receipt.sign — Ed25519 producer signatures verified against fingerprints pinned in the consumer's own committed code (shipped: ported ledger primitives, sign-side helpers, N-of-M keyrings with legacy verification generations — retired keys verify immutable history only; rotation by reviewed spec change)
  • receipt.attest — workflow-provenance verification with self-anchoring enforcement epochs and a full-history sweep over every protected-tree commit
  • receipt.ratchet — shrink-only exception registries recomputed from live state; an excused failure that starts passing is an error until removed
  • receipt.chronology — record-vs-event ordering tiers: does witnessed time prove the record existed ante quem — before the event it predicts or observes?
  • receipt verify — the outside auditor's command: a clone, commodity tools, one offline fail-closed verdict

Design principle

Trust anchors live in the consumer's committed code, never in runtime configuration a producer could swap. The package ships machinery; consumers pin roots.

The name

A receipt is the record you keep so anyone can check it later. Software already uses the word in exactly this sense: an app-store receipt is a signed proof validated offline, without trusting the store that issued it. This package writes receipts for agent-produced records; receipt verify is what happens when someone asks to see them.

Releases through 0.1.2 shipped as vidimus; those remain on PyPI under the old name.

License

Apache-2.0.

Release files for receipt 0.4.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for receipt 0.4.0
File Size Uploaded
receipt-0.4.0.tar.gz 104.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for receipt 0.4.0
File Interpreter ABI Platform
receipt-0.4.0-py3-none-any.whl Python 3 none any Details

Total release size: 152.8 kB

Release files / receipt-0.4.0.tar.gz

Download URL receipt-0.4.0.tar.gz
Size 104.4 kB
Tags Source
SHA-256 checksum
How to use checksums
0baf7a1323c045a46d03cdb1def6d2935b439e01712561cb764b745519606dcc
BLAKE2b-256 checksum
How to use checksums
f7bc0a5dfa24747243db1fc40a2022c3956e9c6020be4af1cc605a767ef01816
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jul 22, 2026.

Transparency log

Release files / receipt-0.4.0-py3-none-any.whl

Download URL receipt-0.4.0-py3-none-any.whl
Size 48.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
f91477f6ec871fff8b7878ab42dafaeabb92617355be2719b1f46d2822535823
BLAKE2b-256 checksum
How to use checksums
decc1cfa0585d03c00d221807ff0d4b3217becf5acd80f170c73b692c1348812
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jul 22, 2026.

Transparency log

Release history Release notifications | RSS feed

0.6.1

2 release files

0.6.0

2 release files

0.5.2

2 release files

0.5.1

2 release files

0.5.0

2 release files

This release

0.4.0 This release

2 release files

0.3.0

2 release files

0.2.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page