Record
The public log
If it was recorded, you can prove it. Every decision the broker makes on a write is sealed here as a receipt. This page reads the log's public API and, in your browser, checks the latest checkpoint's signature, its consistency with the one you saw last, and the inclusion proof of any receipt you open.
The head
- Entries
- …
- Root
- …
- Updated
- …
- Checkpoint
- …
Log name: …
Verifier key. Pin this one and keep it with your auditors; a bundle's own log field is only a hint:
…
Since your last visit
Your browser keeps the last checkpoint it saw here (only in this browser), so next time it can prove the log only grew.
Receipts
How to read it
- Decision: what the broker did with one call:
allowed(a write that went through),held,approved,denied, orexecuted(an approved call going through). - Action: the method and the provider's API host. Never the path, query string or body.
- Rule: the rule that decided (an irreversible map rule, or a policy rule such as
policy.deny), and the map version.agent_keymeans a registered agent key signed the request;passkeymeans a passkey approved it. - parent: the hash of the account's own private audit entry, so its owner can open the receipt later. submitter is a salted commitment, different for every entry, so that field does not link entries to an account or to each other.
- Entries with
source: "broker"were written by the broker itself; no agent or API key holder can write one. Others were reported by an agent with a receipts API key.
To check a receipt bundle you downloaded, open Verify a receipt. To check one offline, see the docs.