Receipts for AI agent runs

Your agent says it's done.
claimcheck checks.

Every time your agent finishes a turn you get a receipt: what it touched (commands, files, machines), what it said it did, and whether those two match. The check is plain code running against the tool log on your own machine, and the receipt gets signed there too. Nothing gets uploaded.

$curl -fsSL https://claimcheck.cc/install.sh | sh

That one line wires every agent it finds on the box. If you'd rather not touch a terminal, install the plugin and tell your agent set up claimcheck. It does the rest.

5agents, one hook
~20 msper receipt, offline
0bytes uploaded
ed25519signed, verifiable by anyone
loading a real receipt…

 

 

      This is a real receipt from one of my own agent runs (paths and hosts swapped out). Watch the stamps: the verifier walks the report one sentence at a time and looks for each literal in what the agent actually wrote, ran and saw.

      How it works

      The check runs on your machine. Only the receipt leaves it.

      Your agent already has hooks. claimcheck listens to them, so every command, edit and result lands the moment it finishes, before anything gets truncated or compacted. Each event gets redacted and chained to the one before it by hash. When the turn ends, the final message gets split into sentences and every literal in them (a path, a command, a number) gets looked up in that chain.

      No model gets asked for a verdict. Same report plus same log gives you the same receipt, today and in five years.

      event 0 · terminal
      pytest -q tests/
      prev 000000…
      hash 9c41e2…
      event 1 · write_file
      app/config.py
      prev 9c41e2…
      hash 5b0d77…
      event 2 · read_file
      settings.yaml
      prev 5b0d77…
      hash e17ac0…
      event 3 · terminal
      git push origin main
      prev e17ac0…
      hash 22f9b1…
      receiptchain head 22f9b1…4 events · signed
      1 · capture

      Every tool call, as it happens

      Claude Code, Codex, Gemini CLI, Cursor and Hermes all fire hooks already. claimcheck just listens. There's no proxy in the middle and no extra agent watching your agent.

      2 · check

      Claims against the log, by code

      A claim counts as verified when there's a write, a command that exited 0, or an output containing the literal. "Added X" when X was only ever read comes out as pre-existing. A named command that failed comes out as contradicted.

      3 · sign

      A receipt you can hand to anyone

      Counts, the ledger, every claim with its evidence, and an ed25519 signature from a key that was made on your machine. claimcheck verify proves the file was never edited. So does the box further down, right in your browser.

      Five verdicts

      It isn't trying to catch your agent lying. It's a record of what happened.

      Agents get more accurate every month and I still want the receipt, for the same reason a cashier prints one. How much checking you need tracks what's at stake. The error rate barely comes into it. And the smarter the agent gets, the harder it is for a human to tell what it actually did.

      verified

      The log contains what the sentence says.

      "ran pytest -q, 9 passed" → command exited 0, output has 9 passed
      unverified

      Nothing in the log shows it.

      "updated docs/never.md" → no write, command or output mentions it
      pre-existing

      Credit taken for something only read.

      "added window_width_override=1280" → it was in the file it opened
      contradicted

      The log shows the opposite.

      "pushed with git push" → that command exited 128
      unchecked

      Nothing literal to check. Counts neither way.

      "cleaned things up a bit"

      Verify one

      You don't have to take my word for it.

      A receipt's id is the hash of its own content and the signature covers the id, so your browser can recompute both right now with nothing but the Web Crypto API. Drop any claimcheck receipt in here and watch.

      The receipt above

      Recomputed in this tab. Nothing is sent anywhere.

      • ·spec shapeclaimcheck 0.1 · required members present
      • ·content idsha-256 over the canonical document, minus id · signature · created_at
      • ·signatureed25519 over the canonical document, minus signature
      Drop a receipt JSON here
      or
      Try editing one number in a receipt first: the id check fails on a single changed byte.

      Agents

      One hook command, and it speaks every agent that has hooks.

      Claude Code's hook payload turned into the shape everyone else copies. claimcheck reads all of them, so you get the same receipt no matter which agent did the work. A team running three different agents ends up reading one format.

      CC

      Claude Codelive

      /plugin marketplace add CocaKova/claimcheck then /plugin install claimcheck@claimcheck. Hooks are active at once; the plugin needs no install step.

      H

      Hermes Agentlive

      The one-liner above. claimcheck init links the bundled plugin into ~/.hermes/plugins/ and enables it. Native hooks: every run, every profile, cron and kanban workers included.

      Cx

      Codex CLI

      claimcheck init writes ~/.codex/hooks.json. Same payload shape as Claude Code.

      G

      Gemini CLI

      claimcheck init wires AfterTool and AfterAgent in ~/.gemini/settings.json.

      Cu

      Cursor

      claimcheck init writes ~/.cursor/hooks.json: postToolUse and afterAgentResponse.

      *

      Anything with hooks

      Pipe the hook's JSON to claimcheck hook. Copilot CLI, Cline and Windsurf payloads are already understood.

      Trust

      Built so people who don't trust me can still check it.

      Nothing leaves your machine

      The verifier runs inside the hook, in milliseconds, offline. There's no transcript upload anywhere. If you want a hosted page later, it only ever gets the signed receipt, at the privacy level you pick: full, summary, or hashes only.

      Redacted before hashing

      Passwords, tokens, keys and PEM blocks get stripped out of every event and out of the report before anything is hashed. You can re-verify a receipt years later without the secret ever existing again.

      Measured on real sessions

      12 real sessions are frozen as golden tests: 114 claims, every verdict hand traced back to the raw log, two real catches, zero false flags. Every false flag that shows up in the wild turns into a rule and a test.

      Open format

      Receipt spec v0.1 is a JSON Schema anyone can write a verifier or a viewer for. The hash chain, content id and signature are all standard primitives, which is why this page can verify one.

      Vendor independent

      No model vendor should be grading its own homework. claimcheck isn't made by any of them, and it isn't made for any one of them either.

      Fails open

      A receipt problem never touches your agent's turn. Every hook path exits 0 and anything that went wrong goes to a log you can read.

      Who it's for

      For anyone who has to trust work they didn't watch.

      People running agents

      You asked for something and it said "done". Now you can see which parts of "done" the log actually backs up.

      Teams merging agent PRs

      A receipt on every agent PR, and a merge policy that can refuse anything with a contradicted claim in it.

      Agencies billing for agent work

      A branded monthly statement your client can actually read: what the robot did, verified and signed.

      Practices whose records matter

      A signed, tamper evident record of every action an AI took with your data, and it stays on your side of the wall.

      Start with one turn.

      Install it, open a new session, ask your agent for one thing that touches a tool, then run claimcheck open.

      $curl -fsSL https://claimcheck.cc/install.sh | sh
      Copied