Receipts for AI agent runs

Your agent says it's done. claimcheck checks.

Every time your agent finishes a turn you get a receipt: what it touched (commands, files, machines), what it said it did, and whether those two match. The check is plain code running against the tool log on your own machine, and the receipt gets signed there too. Nothing gets uploaded.

curl -fsSL https://claimcheck.cc/install.sh | sh

That one line wires every agent it finds on the box. If you'd rather not touch a terminal, install the plugin and tell your agent set up claimcheck. It does the rest.

Agents, one hook
5
Per receipt, offline
~20 ms
Bytes uploaded
0
Signed, anyone can verify
ed25519
claimcheck receiptrcpt_5fc0c1354e1d…
2026-09-26 · hermes · qwen3.8-flash-next

Sonic side-scroller: rings, parallax, empty bottom half

askedReview: See where mistakes happened, if you fixed them, and if not…

tool calls
59
commands run
29 · 1 failed
files written · read
3 · 7

One claim took credit for something the agent only read.

claims, as writtenverdict
  • Old single-frame ring.png replaced by ring_0..3.png.

    ring_0 in command (exit ok); 3.png in command (exit ok) · unchecked: ring.pngverified
  • Bigger picture - added window_width_override=1280 / window_height_override=720.

    window_width_override=1280, window_height_override=720 appears only in content the agent read; never in anything…pre-existing
  • Parallax layers ran out of tiles mid-stage (main.gd:79-110).

    main.gd in writeverified
  • Now guarded on the texture before get_image().save_png.

    get_image().save_png in writeverified
  • Verdict: after fixes — Approve.

    nothing literal to checkunchecked

verified
27
pre-existing
1
unchecked
6
claims, split by code
34
rcpt_5fc0c1354e1df219a040277a
ed25519
key CAAF50F9

Sealed: this tab checked the signature.

This is a real receipt from one of my own agent runs (paths and hosts swapped out). Watch the stamps: the verifier walks the report one sentence at a time and looks for each literal in what the agent actually wrote, ran and saw. The seal only lands once this tab has checked the signature.

How it works01

The check runs on your machine. Only the receipt leaves it.

Your agent already has hooks. claimcheck listens to them, so every command, edit and result lands the moment it finishes, before anything gets truncated or compacted. Each event gets redacted and chained to the one before it by hash. When the turn ends, the final message gets split into sentences and every literal in them (a path, a command, a number) gets looked up in that chain.

No model gets asked for a verdict. Same report plus same log gives you the same receipt, today and in five years.

  1. event 0 · terminalpytest -q tests/prev000000…hash9c41e2…
  2. event 1 · write_fileapp/config.pyprev9c41e2…hash5b0d77…
  3. event 2 · read_filesettings.yamlprev5b0d77…hashe17ac0…
  4. event 3 · terminalgit push origin mainpreve17ac0…hash22f9b1…
  5. 4 events · signedreceiptchain head22f9b1…
capture01

Every tool call, as it happens

Claude Code, Codex, Gemini CLI, Cursor and Hermes all fire hooks already. claimcheck just listens. There's no proxy in the middle and no extra agent watching your agent.

check02

Claims against the log, by code

A claim counts as verified when there's a write, a command that exited 0, or an output containing the literal. "Added X" when X was only ever read comes out as pre-existing. A named command that failed comes out as contradicted.

sign03

A receipt you can hand to anyone

Counts, the ledger, every claim with its evidence, and an ed25519 signature from a key that was made on your machine. claimcheck verify proves the file was never edited. So does the box further down, right in your browser.

Five verdicts02

It isn't trying to catch your agent lying. It's a record of what happened.

Agents get more accurate every month and I still want the receipt, for the same reason a cashier prints one. How much checking you need tracks what's at stake. The error rate barely comes into it. And the smarter the agent gets, the harder it is for a human to tell what it actually did.

What the agent saidverdict

What the run log shows4 events

  1. 1terminal · exit 0$ pytest -q9 passed in 1.42s
  2. 2read_fileproject.godot[display] window_width_override=1280
  3. 3write_fileapp/config.py18 lines
  4. 4terminal · exit 128$ git push origin mainfatal: could not read Username for 'https://github.com'

WhyPoint at a sentence on the left and the line that backs it up gets marked on the right.

A made-up turn, so all five verdicts show up at once. The receipt at the top of the page is a real one. Hover or tap any sentence.

verified

The log contains what the sentence says.

unverified

Nothing in the log shows it.

pre-existing

Credit taken for something only read.

contradicted

The log shows the opposite.

unchecked

Nothing literal to check. Counts neither way.

Check one yourself03

Try to fake one.

You don't have to take my word for it. Change anything on this receipt, even one digit, and it stops checking out. Your browser does the checking, right here, and nothing gets sent anywhere.

Try itClick the orange stamp to let the agent off the hook, or click a number and make it look better.

claimcheck receiptrcpt_5fc0c1354e1d…

Sonic side-scroller: rings, parallax, empty bottom half

claims, as writtenverdict
  • Old single-frame ring.png replaced by ring_0..3.png.

    ring_0 in command (exit ok); 3.png in command (exit ok) · unchecked: ring.png
  • Bigger picture - added window_width_override=1280 / window_height_override=720.

    window_width_override=1280, window_height_override=720 appears only in content the agent read; never in…
  • Now guarded on the texture before get_image().save_png.

    get_image().save_png in write

rcpt_5fc0c1354e1df219a040277a
ed25519
key CAAF50F9
Checking…

How the check works

A receipt's id is the hash of its own content and the signature covers the id, so your browser can recompute both right now. The id is a sha-256 of everything on the receipt except the id, the signature and the timestamp. The signature is ed25519, from a key that was made on the machine that ran the agent. Change one byte and the id no longer matches, and the signature no longer covers it. claimcheck verify does the same check in a terminal.

  • spec shapeclaimcheck 0.1 · required members present
  • content idsha-256 over the canonical document, minus id · signature · created_at
  • signatureed25519 over the canonical document, minus signature
Have a receipt of your own? Drop its JSON file here or . It loads into the receipt here and gets the same check. Nothing is uploaded.

Agents04

One hook command, and it speaks every agent that has hooks.

Claude Code's hook payload turned into the shape everyone else copies. claimcheck reads all of them, so you get the same receipt no matter which agent did the work. A team running three different agents ends up reading one format.

Claude Code{"hook_event_name": "PostToolUse", "tool_name": "Bash", "tool_input": {"command": "npm test"}, "tool_response": {"stdout": "12 passing"}}
Codex{"hook_event_name": "PostToolUse", "tool_name": "shell", "tool_input": {"command": ["bash", "-lc", "npm test"]}, "tool_response": {"output": "12 passing", "exit_code": 0}}
Gemini CLI{"hook_event_name": "AfterTool", "tool_name": "run_shell_command", "tool_input": {"command": "npm test"}, "tool_response": {"llmContent": "12 passing"}}
Cursor{"hook_event_name": "postToolUse", "tool_name": "Shell", "tool_input": {"command": "npm test"}, "tool_output": "12 passing"}
claimcheck receipt1 command · 0 failed

Ran npm test: 12 passing.

verified
same receipt4/4 agents

The same command, as four agents hand it to their hooks (trimmed to the fields that matter). Different names, different shapes. claimcheck reads each one and writes the same receipt line.

Claude Codelive

/plugin marketplace add CocaKova/claimcheck then /plugin install claimcheck@claimcheck. Hooks are active at once; the plugin needs no install step.

Hermes Agentlive

The one-liner above. claimcheck init links the bundled plugin into ~/.hermes/plugins/ and enables it. Native hooks: every run, every profile, cron and kanban workers included.

Codex CLI

claimcheck init writes ~/.codex/hooks.json. Same payload shape as Claude Code.

Gemini CLI

claimcheck init wires AfterTool and AfterAgent in ~/.gemini/settings.json.

Cursor

claimcheck init writes ~/.cursor/hooks.json: postToolUse and afterAgentResponse.

Anything with hooks

Pipe the hook's JSON to claimcheck hook. Copilot CLI, Cline and Windsurf payloads are already understood.

Trust05

Built so people who don't trust me can still check it.

§ 1

Nothing leaves your machine

The verifier runs inside the hook, in milliseconds, offline. There's no transcript upload anywhere. If you want a hosted page later, it only ever gets the signed receipt, at the privacy level you pick: full, summary, or hashes only.

§ 2

Redacted before hashing

Passwords, tokens, keys and PEM blocks get stripped out of every event and out of the report before anything is hashed. You can re-verify a receipt years later without the secret ever existing again.

§ 3

Measured on real sessions

12 real sessions are frozen as golden tests: 113 claims, every flag and every unchecked claim traced back to the raw log by hand, two real catches, zero false flags. Every false flag that shows up in the wild turns into a rule and a test.

§ 4

Open format

Receipt spec v0.1 is a JSON Schema anyone can write a verifier or a viewer for. The hash chain, content id and signature are all standard primitives, which is why this page can verify one.

§ 5

Vendor independent

No model vendor should be grading its own homework. claimcheck isn't made by any of them, and it isn't made for any one of them either.

§ 6

Fails open

A receipt problem never touches your agent's turn. Every hook path exits 0 and anything that went wrong goes to a log you can read.

Who it's for06

For anyone who has to trust work they didn't watch.

A

People running agents

You asked for something and it said "done". Now you can see which parts of "done" the log actually backs up.

B

Teams merging agent PRs

A receipt on every agent PR, and a merge policy that can refuse anything with a contradicted claim in it.

C

Agencies billing for agent work

A branded monthly statement your client can actually read: what the robot did, verified and signed.

D

Practices whose records matter

A signed, tamper evident record of every action an AI took with your data, and it stays on your side of the wall.

Pricing07

The part on your machine is free, and it stays free.

Everything above runs locally for $0: every agent, unlimited receipts, signed and checked. The paid plans are for when a receipt has to leave your machine. That means a private page you can send someone, history you don't have to keep yourself, a team, or a client.

I'm building those now. Join early access and you'll hear the day they open. Nobody gets charged before then.

Free

available
$0

On your own machine

  • Every agent with hooks
  • Unlimited receipts, signed with your own key
  • Verify any receipt, offline or right in the browser
  • Open format, Apache-2.0
Install
Prices in USD. Where sales tax or VAT applies, it gets added at checkout.Need retention, audit export or SSO?

claimcheck · first receipt

Start with one turn.

Install it, open a new session, ask your agent for one thing that touches a tool, then run claimcheck open.

curl -fsSL https://claimcheck.cc/install.sh | sh
Install
one line
Setup
your agent can do it
Uploads
none
Cost
$0.00

Keep your receipts

claimcheck · early access

Early access

You'll get one email the day it opens. No charge until then.

I'll only email you about claimcheck, and you can ask me to delete your address any time. Privacy