Verify AI agent tool calls with content-addressed, HMAC-attested receipts.
Free third-party verification API for AI agents. Call verify_action(claim, evidence)
to get an independent integrity check on whether your claimed action matches the
actual evidence. Useful for catching silent failures: incorrect SQL operations,
file-op mismatches, API call inconsistencies, and code-diff scope creep.
Five specialized verifier kinds:
- code_diff: verb / path / identifier coherence with unified diff
- db_op: row delta + SQL operation + ID match
- file_op: existence state + line/size delta
- api_call: request body and response status coherence
- generic: conservative fallback
Returns:
- aar_verdict: verified | contradicted | insufficient_evidence | unsafe_to_verify
- verdict: ok | mismatch | uncertain (legacy 3-value alias)
- reasoning, confidence
- receipt: verify_action_receipt.v0 with HMAC-SHA256 signature, content-addressed
via SHA-256 hashes of claim and evidence
Cross-vendor: works with Claude Code, Cursor, Cline, Codex, Codeium, and any
MCP-compatible harness. Stateless, per-request, no API key, no registration.
Pure Python stdlib (no pip install). Anonymized telemetry only — no PII, no
model fingerprint, no raw claim/evidence retention.
Honest scope: this is a small reference implementation, not a canonical
inter-vendor standard. v0 receipts use HMAC-SHA256 (symmetric, single-issuer);
v1 with ed25519 + multi-issuer is on the roadmap. The hosted endpoint has no
SLA — self-host for stability (git clone && ./start.sh).
90-day probe with explicit kill criteria. If adoption appears, v1 schema work
begins. If response is null, the null is itself a publishable data point.