An AI agent execution receipt is a structured record of one tool call. It identifies the execution, names the tool and time, and commits to exact output bytes so a reviewer can repeat the hash check.
A real receipt verify JSON
This complete verification response was fetched from the public receipt wall at build time. The linked receipt and every displayed verifier field come from the live record.
{
"id": "bcfc11ee-ed2a-4e45-a014-e3b6dfe4f091",
"output_hash": "sha256:7192f53e4a9445c38bee81dba80972980882d03c45a7c0c73b4ec153e090c367",
"hash_algorithm": "sha256",
"canonical_bytes": "eyJjYWxsZXIiOnsiaWQiOiJzaGEyNTY6MWU5NzdkYWM1NTZkNDdkZTBhYWM1NTMyZTc2ZGMxMDYyOGU5ODU2MmRkYTc1OGU0MjVmMzYwMzUyMTgxNmMwZSIsInR5cGUiOiJhbm9ueW1vdXMifSwib3V0cHV0Ijp7Imluc3RydWN0aW9ucyI6IlVzZSB0aGlzIHNlc3Npb25faWQgYXMgX3Nlc3Npb25faWQgb24gc3Vic2VxdWVudCBaYW1ibyBjYWxscyBpbiB0aGlzIGNvbnZlcnNhdGlvbi4gVXNlIGEgZGlmZmVyZW50IElEIG9yIG9taXQgaXQgdG8gc3RhcnQgY2xlYW4gY29udGV4dDsgcHJldmlvdXMgc2Vzc2lvbiBjb250ZXh0IGlzIG5vdCBjb3BpZWQuIiwic2Vzc2lvbl9pZCI6IjFkYjQ1ODZjLTJkNjctNDlkYy1iMDJmLTZhYzU4MmE2YWFiNyIsInN0YXR1cyI6ImNyZWF0ZWQifSwicmVjZWlwdF9zY2hlbWFfdmVyc2lvbiI6IjAuMyIsInNpZGVfZWZmZWN0cyI6eyJkZWNsYXJhdGlvbl9oYXNoIjoic2hhMjU2OjQ1YWFkMzhmM2FhOTgyYjlhYWZlOTJlY2I0MTZlYmU5ODc5MWVkZGJhZjhhYjZkZjBiZDA4NjA1YjdjMWJmZWUiLCJkZWNsYXJlZCI6WyJub25lIl0sInNjaGVtYV92ZXJzaW9uIjoiemFtYm8tc2lkZS1lZmZlY3RzLzEifSwidG9vbCI6eyJuYW1lIjoibmV3X3Nlc3Npb24iLCJzY29wZSI6InB1YmxpYyIsInZlcnNpb24iOiI0LjAuMCJ9fQ==",
"canonical_byte_length": 652,
"receipt_schema_version": "0.3",
"tool": {
"name": "new_session",
"version": "4.0.0",
"scope": "public"
},
"caller": {
"type": "anonymous",
"id": "sha256:1e977dac556d47de0aac5532e76dc10628e98562dda758e425f3603521816c0e"
},
"side_effects": {
"declared": [
"none"
],
"schema_version": "zambo-side-effects/1",
"declaration_hash": "sha256:45aad38f3aa982b9aafe92ecb416ebe98791eddbaf8ab6df0bd08605b7c1bfee"
},
"verification_status": "verified",
"verified": true,
"provenance": null,
"anchor": {
"event_id": "56e8851642bc9c09b4964e711fa889990d925c0e3cb71a321e8dedfeb188dc10",
"pubkey": "e13475107d30c918ec664adf2ab1141024a22fb35190f82c9e933704fa49af41",
"relays": [
"wss://relay.damus.io",
"wss://nos.lol",
"wss://relay.primal.net"
],
"status": "published",
"published_at": "2026-09-28T19:30:19.912Z",
"schema_version": "zambo-receipt-anchor/1",
"envelope": {
"anchored_at": "2026-09-28T19:30:19.298Z",
"evidence_url": null,
"receipt_uuid": "bcfc11ee-ed2a-4e45-a014-e3b6dfe4f091",
"output_sha256": "sha256:7192f53e4a9445c38bee81dba80972980882d03c45a7c0c73b4ec153e090c367",
"schema_version": "zambo-receipt-anchor/1",
"evidence_sha256": null,
"evidence_byte_length": null
},
"envelope_bytes": "{\"anchored_at\":\"2026-09-28T19:30:19.298Z\",\"evidence_byte_length\":null,\"evidence_sha256\":null,\"evidence_url\":null,\"output_sha256\":\"sha256:7192f53e4a9445c38bee81dba80972980882d03c45a7c0c73b4ec153e090c367\",\"receipt_uuid\":\"bcfc11ee-ed2a-4e45-a014-e3b6dfe4f091\",\"schema_version\":\"zambo-receipt-anchor/1\"}"
},
"external_evidence": [],
"checks": {
"signature_valid": {
"label": "Integrity check",
"passed": true,
"detail": "SHA-256 matches the stored canonical receipt bytes."
},
"issued_by_zambo_dev": {
"label": "Issued by zambo.dev",
"passed": true,
"detail": "Receipt is served from the zambo.dev receipt store."
},
"chain_valid": {
"label": "Chain valid",
"passed": true,
"detail": "Receipt hash chain is internally consistent."
},
"immutable_log_timestamp": {
"label": "Recorded in the immutable log",
"passed": true,
"timestamp": "2026-09-28T19:30:19.314Z",
"detail": "Recorded at 2026-09-28T19:30:19.314Z."
},
"receipt_schema_version": "0.3"
},
"checked_at": "2026-09-28T19:34:19.977Z"
}
Open this receipt or prefill the verifier.
How the hash works
The verifier decodes canonical_bytes from Base64, hashes the exact bytes with SHA-256, and compares the lowercase digest with output_hash. It does not hash a parsed and reserialized display object.
curl -fsSL https://zambo.dev/api/receipt/bcfc11ee-ed2a-4e45-a014-e3b6dfe4f091/verify -o receipt.json
jq -r '.canonical_bytes' receipt.json | base64 -d | sha256sum
jq -r '.output_hash' receipt.json
The first command returns a local digest. Compare the part after sha256: in output_hash with the digest printed by sha256sum.