Receipt schema reference

scopebond:receipt evidence contract v1 — A countersigned receipt whose signature covers the complete canonical payload. It attests the gateway's recorded decision and adapter assertion; it does not independently prove an external effect or compliance.

Schema id: https://scopebond.com/schema/receipt-v1.json. Package: @scopebond/policy-schema 0.6.0 (newer published versions may add fields). A receipt has two top-level members, payload (everything that is signed, canonicalized with RFC 8785) and signature. What a receipt proves, and does not, is explained in Receipts and verification.

receipt

A countersigned receipt whose signature covers the complete canonical payload. It attests the gateway's recorded decision and adapter assertion; it does not independently prove an external effect or compliance.

FieldRequiredShapeDescription
payloadyesobject
signatureyesobject

receipt.payload

FieldRequiredShapeDescription
typeyesconst "scopebond:receipt"
evidence_versionyesconst "1.0"
canonicalizationyesconst "RFC8785"
intentyesobjectThe action the agent signed (the ACTA payload_digest source).
intent_hashyesstring, pattern ^[0-9a-f]{64}$Compatibility alias of action_ref.authorized_intent_hash.
action_refyesobject
policy_hashyesstringACTA policy_digest = the registered policy hash.
policy_versionyesinteger, min 1
policy_refyesobject
verifier_versionyesstring
realtime_resultyes"allow" · "deny" · "approved" · "timeout" · "not_evaluated"
executedyesboolean
execution_refyesstring \| nullCompatibility alias of execution.reference.
executionyesobject
redactionyesobject
authorizationyesobject or object or object or object
attesteryesobject
timestampyesstring, format date-time
evidence_classno"signed_intent" · "pep_authorized" · "boundary"Evidence class (§15). Absent = legacy, inferred at read time. Never upgraded.
principalnoobjectRequired for pep_authorized: the validated identity subject and issuer.
boundarynoobjectRequired for boundary: the gate that decided a consequence and the attributed actor.
overridenoobject or objectA person at the computer allowed an action a rule blocked (agent_dialog, with a reason whose SHA-256 is reason_digest), or the coding agent's own permission prompt was offered for it (harness_prompt). Present only with realtime_result "approved".

receipt.payload.intent

The action the agent signed (the ACTA payload_digest source).

FieldRequiredShapeDescription
action_typeyesstring
assetnostring
amountnointeger, min 0
paramsnoobject

receipt.payload.action_ref

FieldRequiredShapeDescription
action_idnostring, length 16–200
authorized_intent_hashyesstring, pattern ^[0-9a-f]{64}$
evidence_intent_hashyesstring, pattern ^[0-9a-f]{64}$

receipt.payload.policy_ref

FieldRequiredShapeDescription
idyesstring \| null
versionyesinteger, min 1
digestyesstring, pattern ^[0-9a-f]{64}$

receipt.payload.execution

FieldRequiredShapeDescription
stateyes"simulated" · "observed_not_evaluated" · "denied" · "allowed_pending" · "cooperative_allow" · "executed" · "failed" · "outcome_unknown"
assertionyes"none" · "gateway_simulation" · "adapter_reported_success" · "adapter_reported_failure" · "adapter_outcome_unknown"
referenceyesstring \| null
external_effectyesconst "not_independently_verified"

receipt.payload.redaction

FieldRequiredShapeDescription
profileyesconst "scopebond:minimized-intent/v1"
pathsyesarray, items: string

receipt.payload.authorization — form 1 (mode authenticated)

FieldRequiredShapeDescription
modeyesconst "authenticated"
agentyessee intentAuthorization
approvalyessee approval or null

receipt.payload.authorization — form 2 (mode insecure_development)

FieldRequiredShapeDescription
modeyesconst "insecure_development"
agentyesnull
approvalyesnull

receipt.payload.authorization — form 3 (mode boundary)

No agent authorization — a gate attested a consequence (boundary-class receipts). Identity is the receipt's boundary attribution.

FieldRequiredShapeDescription
modeyesconst "boundary"
agentyesnull
approvalyesnull

receipt.payload.authorization — form 4 (mode pep)

No agent signature — a proxy/PEP decided a request carrying the caller's own identity (pep_authorized receipts). Identity is the receipt's principal.

FieldRequiredShapeDescription
modeyesconst "pep"
agentyesnull
approvalyesnull

receipt.payload.attester

FieldRequiredShapeDescription
kindyes"gateway" · "module" · "resource"
kidyesstring

receipt.payload.principal

Required for pep_authorized: the validated identity subject and issuer.

FieldRequiredShapeDescription
subjectyesstring, length 1+
issueryesstring, length 1+

receipt.payload.boundary

Required for boundary: the gate that decided a consequence and the attributed actor.

FieldRequiredShapeDescription
gateyes"merge" · "deploy" · "egress" · "platform_event"
outcome_refyesstring, length 1+
attributionyesobject

receipt.payload.boundary.attribution

FieldRequiredShapeDescription
kindyes"asserted" · "inferred"
actoryesstring, length 1+

receipt.payload.override

A person at the computer allowed an action a rule blocked (agent_dialog, with a reason whose SHA-256 is reason_digest), or the coding agent's own permission prompt was offered for it (harness_prompt). Present only with realtime_result "approved".

FieldRequiredShapeDescription
versionyesconst 1
ruleyesstring, pattern ^[a-z0-9-]{1,64}$
methodyes"agent_dialog" · "harness_prompt"
stateyes"allowed" · "offered"
repeat_ofyesnull or string, length 16–200
reason_digestyesnull or string, pattern ^[0-9a-f]{64}$
reason_lengthyesnull or integer, min 1
os_user_digestyesnull or string, pattern ^[0-9a-f]{64}$
decided_atyesstring, format date-time

receipt.signature

FieldRequiredShapeDescription
algyes"Ed25519" · "ES256" · "secp256k1" · "EIP-712"
sigyesstring

Consistency rules

The schema enforces these if/then relations inside payload:

  • if ` = ? then realtime_result = "approved"`
  • if evidence_class = "boundary" then ` = ?, otherwise = ?`
  • if evidence_class = "pep_authorized" then ` = ?, otherwise = ?`
  • if execution.state = "executed" then executed = true, otherwise executed = false
  • if execution.state = "simulated" then execution.assertion = "gateway_simulation"
  • if execution.state = "observed_not_evaluated" then realtime_result = "not_evaluated", otherwise realtime_result ≠ "not_evaluated"

Definitions ($defs)

identity

FieldRequiredShapeDescription
kidyesstring, pattern ^key:[0-9a-f]{16}$
algyesconst "Ed25519"

intentAuthorization

FieldRequiredShapeDescription
versionyesconst "1.0"
request_idyesstring, pattern ^[A-Za-z0-9._:-]+$, length 16–200
issued_atyesstring, format date-time
expires_atyesstring, format date-time
signeryessee identity
intent_hashyesstring, pattern ^[0-9a-f]{64}$
signatureyesstring, length 40+

approval

FieldRequiredShapeDescription
versionyesconst "1.0"
approval_idyesstring, pattern ^[A-Za-z0-9._:-]+$, length 16–200
issued_atyesstring, format date-time
expires_atyesstring, format date-time
approveryessee identity
intent_hashyesstring, pattern ^[0-9a-f]{64}$
policy_refyesobject
decisionyesconst "approve"
signatureyesstring, length 40+