Every time your agent finishes a turn you get a receipt: what it touched (commands, files, machines), what it said it did, and whether those two match. The check is plain code running against the tool log on your own machine, and the receipt gets signed there too. Nothing gets uploaded.
curl -fsSL https://claimcheck.cc/install.sh | shThat one line wires every agent it finds on the box. If you'd rather not touch a terminal, install the plugin and tell your agent set up claimcheck. It does the rest.
How it works
Your agent already has hooks. claimcheck listens to them, so every command, edit and result lands the moment it finishes, before anything gets truncated or compacted. Each event gets redacted and chained to the one before it by hash. When the turn ends, the final message gets split into sentences and every literal in them (a path, a command, a number) gets looked up in that chain.
No model gets asked for a verdict. Same report plus same log gives you the same receipt, today and in five years.
Claude Code, Codex, Gemini CLI, Cursor and Hermes all fire hooks already. claimcheck just listens. There's no proxy in the middle and no extra agent watching your agent.
A claim counts as verified when there's a write, a command that exited 0, or an output containing the literal. "Added X" when X was only ever read comes out as pre-existing. A named command that failed comes out as contradicted.
Counts, the ledger, every claim with its evidence, and an ed25519 signature from a key that was made on your machine. claimcheck verify proves the file was never edited. So does the box further down, right in your browser.
Five verdicts
Agents get more accurate every month and I still want the receipt, for the same reason a cashier prints one. How much checking you need tracks what's at stake. The error rate barely comes into it. And the smarter the agent gets, the harder it is for a human to tell what it actually did.
The log contains what the sentence says.
"ranpytest -q, 9 passed" → command exited 0, output has 9 passedNothing in the log shows it.
"updateddocs/never.md" → no write, command or output mentions itCredit taken for something only read.
"addedwindow_width_override=1280" → it was in the file it openedThe log shows the opposite.
"pushed withgit push" → that command exited 128Nothing literal to check. Counts neither way.
"cleaned things up a bit"Verify one
A receipt's id is the hash of its own content and the signature covers the id, so your browser can recompute both right now with nothing but the Web Crypto API. Drop any claimcheck receipt in here and watch.
The receipt above
Recomputed in this tab. Nothing is sent anywhere.
Agents
Claude Code's hook payload turned into the shape everyone else copies. claimcheck reads all of them, so you get the same receipt no matter which agent did the work. A team running three different agents ends up reading one format.
/plugin marketplace add CocaKova/claimcheck then /plugin install claimcheck@claimcheck. Hooks are active at once; the plugin needs no install step.
The one-liner above. claimcheck init links the bundled plugin into ~/.hermes/plugins/ and enables it. Native hooks: every run, every profile, cron and kanban workers included.
claimcheck init writes ~/.codex/hooks.json. Same payload shape as Claude Code.
claimcheck init wires AfterTool and AfterAgent in ~/.gemini/settings.json.
claimcheck init writes ~/.cursor/hooks.json: postToolUse and afterAgentResponse.
Pipe the hook's JSON to claimcheck hook. Copilot CLI, Cline and Windsurf payloads are already understood.
Trust
The verifier runs inside the hook, in milliseconds, offline. There's no transcript upload anywhere. If you want a hosted page later, it only ever gets the signed receipt, at the privacy level you pick: full, summary, or hashes only.
Passwords, tokens, keys and PEM blocks get stripped out of every event and out of the report before anything is hashed. You can re-verify a receipt years later without the secret ever existing again.
12 real sessions are frozen as golden tests: 114 claims, every verdict hand traced back to the raw log, two real catches, zero false flags. Every false flag that shows up in the wild turns into a rule and a test.
Receipt spec v0.1 is a JSON Schema anyone can write a verifier or a viewer for. The hash chain, content id and signature are all standard primitives, which is why this page can verify one.
No model vendor should be grading its own homework. claimcheck isn't made by any of them, and it isn't made for any one of them either.
A receipt problem never touches your agent's turn. Every hook path exits 0 and anything that went wrong goes to a log you can read.
Who it's for
You asked for something and it said "done". Now you can see which parts of "done" the log actually backs up.
A receipt on every agent PR, and a merge policy that can refuse anything with a contradicted claim in it.
A branded monthly statement your client can actually read: what the robot did, verified and signed.
A signed, tamper evident record of every action an AI took with your data, and it stays on your side of the wall.
Install it, open a new session, ask your agent for one thing that touches a tool, then run claimcheck open.
curl -fsSL https://claimcheck.cc/install.sh | sh