Receipts and verification

A receipt is the signed record of one decision about one agent action. You can prove it later to an auditor, a customer or your own team, offline, without trusting Scopebond.

What a receipt holds

PartWhat it records
ActionWhat the agent tried. Secrets are replaced by [REDACTED] before signing, and file contents are never stored
DecisionAllowed, denied, held or observed, and the policy version used
Outcomeexecuted, denied, simulated, failed, allowed_pending, observed_not_evaluated or outcome_unknown
SignaturesThe agent's (when there is one) and the deciding hook's or gateway's
Evidence classHow strong the proof is (below)

Evidence classes

ClassProduced byProvesDoes not prove
signed_intentGateway, hook, framework pluginThe agent signed this action, and it was checked before it ranThat an outside system did exactly what it reported
pep_authorizedMCP proxyThe proxy approved this action for this callerWhich agent sent it
boundaryGitHub checkA merge was allowed or blocked at that gateThat the underlying work was prevented

The workspace and exports show the class on every row and never add classes together.

Verify receipts

Coding-agent hook. Checks every local receipt. No network, no account. It exits with an error if any receipt fails.

npx @scopebond/hook@latest verify

Gateway. Export the gateway's public key once, then check a saved receipt offline.

npx @scopebond/gateway@latest keygen ./scopebond-attester.key --out ./gateway.pub.pem
npx @scopebond/gateway@latest verify ./receipt.json --key ./gateway.pub.pem

In code or the browser. Use verifyReceipt from @scopebond/gateway, or paste a receipt into the workspace's Verify a receipt page. Both run the same check as the command line.

Tamper evidence

The gateway regularly seals its log into a chained fingerprint, so a removed or changed receipt shows. It can prove one receipt is in the log without revealing the others. [PLANNED] Publishing these seals to an external public log.

When the workspace refuses a receipt

CaseResult
Signature does not match the enrolled keysRefused
Timestamp more than 5 minutes in the futureRefused. Check the machine's clock
Old receipt sent after time offlineAccepted. There is no age limit
Signed by a revoked key, before the revocationAccepted only if it arrives within 24 hours of the revocation

Offline verify has no arrival time, so it still accepts receipts signed before a key was revoked.

What a valid receipt does not prove

  • That the action was wise or compliant. It proves what was decided and recorded.
  • A breach. Whether an action broke a policy is worked out from receipts plus the policy, and only actions that ran can break one.
  • Anything, if it is marked insecure_development. That is an unsigned local test.