Skip to content

feat: offline-verifiable decision receipts (Ed25519 + JCS) #1499

Description

Overview

Implement offline-verifiable decision receipts as a first-party AGT capability. Every tool call an agent makes should produce a cryptographic receipt that third parties can verify without access to the original infrastructure.

Background

This feature was previously contributed by an external party but was removed in PR #1498 after the contributor was flagged for credential laundering by AGT's governance tools. The underlying concept has genuine value and should be reimplemented properly.

Requirements

  • Receipt format: Per-tool-call Ed25519 signatures over JCS-canonical (RFC 8785) payloads
  • Hash chaining: Receipts linked via parent hashes for insertion detection
  • Offline verification: CLI tool to verify receipt chains without network access
  • Cedar integration: Bind Cedar policy decisions to receipt payloads
  • Audit log integration: Two-layer integrity with AGT's existing AuditLog
  • SLSA provenance: Optional emission as SLSA provenance metadata

Standards Alignment

  • Ed25519 (RFC 8032)
  • JSON Canonicalization Scheme (RFC 8785)
  • IETF draft-farley-acta-signed-receipts
  • SLSA provenance predicates

Deliverables

  • Core receipt signing/verification module in agent-governance-python
  • CLI verification tool (pure Python, no external dependencies)
  • Tutorial covering receipt creation, verification, chaining, and CI integration
  • Quickstart example
  • Unit tests

Labels

enhancement, good first issue

Activity

  1. added a commit that references this issue on Apr 27, 2026
    5006538
  2. added a commit that references this issue on Apr 27, 2026
    847d741
  3. added a commit that references this issue on Jun 1, 2026
    3b3781d
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions