Receipts and verification
A receipt is the signed record of one decision about one agent action. You can prove it later to an auditor, a customer or your own team, offline, without trusting Scopebond.
What a receipt holds
| Part | What it records |
|---|---|
| Action | What the agent tried. Secrets are replaced by [REDACTED] before signing, and file contents are never stored |
| Decision | Allowed, denied, held or observed, and the policy version used |
| Outcome | executed, denied, simulated, failed, allowed_pending, observed_not_evaluated or outcome_unknown |
| Signatures | The agent's (when there is one) and the deciding hook's or gateway's |
| Evidence class | How strong the proof is (below) |
Evidence classes
| Class | Produced by | Proves | Does not prove |
|---|---|---|---|
signed_intent | Gateway, hook, framework plugin | The agent signed this action, and it was checked before it ran | That an outside system did exactly what it reported |
pep_authorized | MCP proxy | The proxy approved this action for this caller | Which agent sent it |
boundary | GitHub check | A merge was allowed or blocked at that gate | That the underlying work was prevented |
The workspace and exports show the class on every row and never add classes together.
Verify receipts
Coding-agent hook. Checks every local receipt. No network, no account. It exits with an error if any receipt fails.
npx @scopebond/hook@latest verify
Gateway. Export the gateway's public key once, then check a saved receipt offline.
npx @scopebond/gateway@latest keygen ./scopebond-attester.key --out ./gateway.pub.pem
npx @scopebond/gateway@latest verify ./receipt.json --key ./gateway.pub.pem
In code or the browser. Use verifyReceipt from @scopebond/gateway, or paste a receipt into the workspace's Verify a receipt page. Both run the same check as the command line.
Tamper evidence
The gateway regularly seals its log into a chained fingerprint, so a removed or changed receipt shows. It can prove one receipt is in the log without revealing the others. [PLANNED] Publishing these seals to an external public log.
When the workspace refuses a receipt
| Case | Result |
|---|---|
| Signature does not match the enrolled keys | Refused |
| Timestamp more than 5 minutes in the future | Refused. Check the machine's clock |
| Old receipt sent after time offline | Accepted. There is no age limit |
| Signed by a revoked key, before the revocation | Accepted only if it arrives within 24 hours of the revocation |
Offline verify has no arrival time, so it still accepts receipts signed before a key was revoked.
What a valid receipt does not prove
- That the action was wise or compliant. It proves what was decided and recorded.
- A breach. Whether an action broke a policy is worked out from receipts plus the policy, and only actions that ran can break one.
- Anything, if it is marked
insecure_development. That is an unsigned local test.