Open standard for verifiable proofs of the exchanges between AI agents and the APIs they call.
A deterministic proof format that binds a request, a response, the parties, a billing reference and a timestamp into a single SHA-256 chain hash. Anyone can verify a proof without ArkForge's code or infrastructure.
For a legacy proof (spec_version "1.1", "2.0" or absent), the chain hash is a single concatenation:
printf '%s' "${REQUEST_HASH}${RESPONSE_HASH}${PAYMENT_ID}${TIMESTAMP}${BUYER}${SELLER}${UPSTREAM}${RECEIPT_HASH}" \
| sha256sum | cut -d' ' -f1UPSTREAM and RECEIPT_HASH are empty strings when absent from the proof.
Current proofs (spec_version "3.0" and above) use a Merkle root of per-field commitments instead: see section 5 of the spec. Recomputing the chain hash only shows internal consistency; the independent evidence is the RFC 3161 timestamp and the Sigstore Rekor entry.
If the result matches proof.hashes.chain, the proof is intact.
| Implementation | Language | Status |
|---|---|---|
| ArkForge Trust Layer | Python | Reference implementation |
Want to add yours? Open a PR.
test-vectors.json contains 14 test cases (7 legacy string-concatenation vectors, 2 canonical-JSON vectors for spec_version 1.2/2.1, 2 per-field commitment vectors for spec_version 3.0, 1 batch-anchor Merkle vector, and 2 spec_version 3.1 vectors covering the committed and publicly opened identity triple). Any conformant implementation MUST pass all vectors.
The proof-spec is the cryptographic foundation for the Compliance Receipts v0.1 spec drafted by the qntm Working Group.
Field mapping:
| proof-spec field | Compliance Receipts v0.1 field | Notes |
|---|---|---|
proof_id |
receipt_id |
Same role: unique receipt identifier |
hashes.request |
input_hash |
SHA-256 of canonical JSON (identical algorithm) |
hashes.response |
output_hash |
SHA-256 of canonical JSON (identical algorithm) |
timestamp |
step.timestamp |
ISO 8601 UTC |
parties.agent_identity + parties.agent_identity_verified + DID endpoint |
step.agent_did |
agent_identity carries the verified DID when agent_identity_verified: true; did:web:trust.arkforge.tech resolves to the Ed25519 signing key |
arkforge_signature |
signature |
Ed25519 — signs the chain hash (proof-spec) vs. canonical receipt (CR v0.1) |
hashes.chain |
no equivalent | Additional witness: binds payment + identity + request + response into one sealed hash |
Fields in Compliance Receipts v0.1 with no proof-spec equivalent (pipeline_id, step.index, step.role, previous_receipt_hash, policy) are pipeline context provided by the calling agent, not derived by the proxy.
OM World's per-step Execution Proof composes with proof-spec and CR v0.1 via the chained prev_hash mechanism: previous_receipt_hash (CR v0.1) is structurally equivalent to OM World's prev_hash, and step.timestamp maps directly. See OM-WORLD-COMPOSABILITY.md for the full field mapping, the canonical step_hash formula, and the JSON examples for the stateless vs. stateful context_hash edge case.
The proof format will evolve to support third-party provider attestations and multi-PSP payment verification. See the Trust Layer roadmap for the full architecture.