Practical cryptographic review

Verify a multi-step AI workflow receipt.

A workflow receipt commits to an ordered set of individual execution receipt hashes. You can independently fetch each receipt, verify its output commitment, rebuild the Merkle tree, and compare the resulting root.

Live checked example

Workflow ID 42a3c2cf-2cdd-5b8a-aced-016e5a2fb634 is available at https://zambo.dev/workflow/42a3c2cf-2cdd-5b8a-aced-016e5a2fb634. Its verified root is:

a4b2fcb4684cec481e4ece889ed15c7d9e47e58d9ba4fb02ea354c0cb2ca44c4

The exact Merkle algorithm

  1. For each 1-based step, remove the sha256: prefix from its 64-character output hash and lowercase the remaining hexadecimal text.
  2. Build the leaf input as the UTF-8 bytes of decimal seq, a colon, and that lowercase hash. The leaf is SHA-256(UTF-8 bytes of seq + ":" + hash).
  3. At each parent level, concatenate the raw 32-byte left digest with the raw 32-byte right digest, then compute SHA-256 over those 64 bytes.
  4. If a level has an odd number of nodes, duplicate its last node as the right input. Continue until one root remains.

Do not hash hexadecimal digest text at the parent level. The parent input is raw bytes. Do not sort the steps: production sequence numbers define their order.

Five ordered receipt commitments

  1. Step 1 11c3a071051a42cbf5cf4da60a7577b1dffeb0419e6dd8a258b19c4c0d0d108e
  2. Step 2 68e3bcad3f46218672fd7ef7bf32f4a7089937dda2b8ade3cfe1050cec856285
  3. Step 3 3da48b2d392fb79ed78f7ed0cc8e6c122fc1089947ff6d7f829748d7745840dd
  4. Step 4 0f024f209392b918909df5478aadd3a9189520d74cfdf78e2ccf51b9f075f926
  5. Step 5 f52d9c03605047ad0ac347e5e9cbc0e2e197a009d8ee5c7d775f86f360eca963

For this example, step 1 produces the independently checked leaf afb99ba6a212e6ba2eee460ed70559234621f50876859da0bed5a8040c708e77. Repeating the process for all five leaves and duplicating the final node at the odd five-node level produces the root shown above.

How to verify it yourself

  1. Open the workflow page and record its ordered step IDs, output hashes, and root.
  2. For every step, fetch https://zambo.dev/api/receipt/{id}/verify and require a successful verification response.
  3. Confirm each returned output hash matches the workflow's corresponding hash, including the sha256: value after normalizing the prefix.
  4. Recompute leaves and parent levels with the algorithm above and compare the final lowercase hexadecimal root.

The workflow page's browser control performs the same kind of retrieval and recomputation. Independent scripts should still retain their inputs and report unavailable receipts separately from mismatched hashes.

What a valid root proves, and what it does not

A matching root supports the integrity and order of the listed receipt commitments. It does not prove task success, provider truth, user intent, authorization, output quality, or an external side effect. Check those claims through the system that owns the outcome. A missing or unavailable step means the workflow cannot be independently checked in full.