frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Circe – Deterministic, offline-verifiable receipts for AI agent actions

https://github.com/wv26296-ux/circe-receipts
1•W_rey45•1h ago
I’ve been working on a small primitive for agentic systems: a cryptographically signed receipt that records what an AI agent decided, what it did, and what changed — as a single canonical JSON artifact.

The problem: Agent systems today rely on logs, dashboards, or proprietary consoles for truth. Those are easy to forge, truncate, or lose. If an agent takes a high-stakes action (e.g. a firewall change, a deployment, a purchase), there’s no portable artifact you can independently verify later.

The idea: Treat agent execution like a signed transaction, not a log stream. Each run emits a receipt that can be verified offline, without trusting the issuer’s infrastructure.

How it works (minimal core):

Deterministic signing: Ed25519 signatures over a canonical JSON byte string

Canonicalization: RFC 8785-style JSON canonicalization (stable key ordering, UTF-8 encoding, no insignificant whitespace)

Tamper evidence: Any mutation of the signed payload flips the SHA-256 hash and invalidates the signature

Offline verification: A standalone verifier script; no network calls, no dependencies on the issuer

Try it locally (no network):

python verify_receipt.py hn_receipt.json python verify_receipt.py hn_receipt_tampered.json

The first passes; the second fails after a single-field mutation.

This is intentionally not a logging system, observability platform, or policy engine. It’s a small integrity / provenance primitive intended to compose with higher-level agent frameworks.

I’d appreciate feedback on:

Threat-model gaps (e.g. confused-deputy or context-hijacking risks)

Schema ergonomics for high-frequency or long-running agent pipelines

Canonicalization edge cases worth enforcing earlier

Comments

W_rey45•1h ago
Threat model / scope: This design assumes the signer’s private key is trusted at issuance time; it does not attempt to prove semantic correctness of the agent’s reasoning or inputs. The signature covers only the canonicalized signed_block; any mutation invalidates verification. Receipts are portable and verifiable offline but do not prevent a malicious issuer from signing false data (integrity primitive, not a truth oracle). Replay is detectable (e.g. via hash chaining or external indexing) but not prevented by the receipt alone. Confidentiality is out of scope; receipts are integrity-only artifacts. The goal is to make post-hoc tampering and log forgery detectable, not to replace policy enforcement or access control.
nulone•38m ago
Solid primitive. Two questions:

1. Crash edge case: If an agent executes a side-effect and dies before signing the receipt, is that action orphaned? Any WAL-style intent/completion model?

2. Multi-step workflows: Do receipts chain natively (parent pointers/Merkle) or via external linking? (I see storage/ledgers are out of scope, but curious about the linkage design.)

The negative proof angle (proving AI didn't touch prod) is compelling for compliance.

C++26 Reflection loves QRangeModel

https://www.qt.io/blog/c26-reflection-qrangemodel
1•jandeboevrie•29s ago•0 comments

The Paper 3

https://zenodo.org/records/18293965
1•KaoruAK•4m ago•0 comments

X algorithm has been open sourced

https://github.com/xai-org/x-algorithm
1•grainier•4m ago•0 comments

Management Time: Who's Got the Monkey? [pdf]

https://www.med.unc.edu/uncaims/wp-content/uploads/sites/764/2014/03/Oncken-_-Wass-Who_s-Got-the-...
1•rintrah•9m ago•1 comments

Chatbot Psychosis

https://en.wikipedia.org/wiki/Chatbot_psychosis
3•tbmtbmtbmtbmtbm•11m ago•0 comments

Stevey's Birthday Blog

https://steve-yegge.medium.com/steveys-birthday-blog-34f437139cb5
1•throwawayHMM19•14m ago•0 comments

Crypto criminals stole $700M from people

https://www.bbc.com/news/articles/c93w30gl5jno
2•dayli•15m ago•0 comments

Show HN: Stashcast – Self-hosted custom podcast feeds for any media

https://github.com/jonocodes/stashcast
1•jonotime•23m ago•0 comments

China's Birthrate Sinks to Record Low

https://www.wsj.com/world/china/chinas-population-falls-for-fourth-straight-year-409986bd
6•RestlessMind•26m ago•0 comments

Run coding agents on your desktop without breaking your flow

https://www.ami.dev/
1•alexinavar•31m ago•1 comments

Show HN: Crapless craps – flutter PWA vibe coded from my phone

https://craps.exe.xyz:8081/
2•calderwoodra•34m ago•0 comments

Let's Buy California from Trump – Denmark's Next Big Adventure

https://denmarkification.com/
7•mil22•35m ago•0 comments

Building Production-Grade Micro Services on Azure Kubernetes

https://medium.com/@koladilip/building-production-grade-micro-services-on-azure-kubernetes-2884b5...
1•koladilip•36m ago•0 comments

Why 33% of NYC logistics thefts happen when the driver is nearby (Analysis)

https://www.tranzia.com/blog/nyc-logistics-safety
1•mednosis•42m ago•1 comments

My favorite NP-complete problem (2016) [video]

https://www.youtube.com/watch?v=BJBnR5Sn-sc
1•todsacerdoti•49m ago•0 comments

Show HN: Saile – credential once, work anywhere for clinicians

https://www.saileapp.com/
1•mayoub1•49m ago•0 comments

Japan's 40-year bond yield hits 4% record on fiscal jitters

https://www.cnbc.com/2026/01/20/japan-40-year-jgb-government-bond-yield-record-fiscal-jitters-sna...
2•zerosizedweasle•50m ago•0 comments

OpenAI launches GPT-audio and GPT-audio-mini

https://platform.openai.com/docs/models/gpt-audio
2•reed1234•51m ago•1 comments

Validation Economy: How Western Creators Monetize South Asia's Need to Be Seen

https://skift.com/2026/01/18/the-validation-economy-how-western-travel-creators-monetize-south-as...
1•ilamont•52m ago•1 comments

Show HN: Hammer of JSON

https://github.com/andrewbaxter/hammer-of-json
3•rendaw•52m ago•0 comments

EmuDevz – A game about building emulators

https://store.steampowered.com/app/4260720/EmuDevz/
3•evo_9•56m ago•1 comments

The Catcher in the Prompt: Day 60

https://blog.pytoshka.me/post/the-catcher-in-the-prompt/
1•kenny-opennix•57m ago•1 comments

Chinese Batteries Will Run the World

https://www.nytimes.com/2026/01/19/opinion/trump-energy-china-future.html
5•cmod•58m ago•0 comments

Show HN: A simple fork of gpodder2go for lightweight self-hosted podcast sync

https://github.com/ijustlovemath/gpodder2go
1•ijustlovemath•1h ago•0 comments

The Overcomplexity of the Shadcn Radio Button

https://maxkapur.com/2025/12/19/perfect-match-integer-programming.html
2•owenlacey•1h ago•0 comments

Hijacking Bluetooth Accessories Using Google Fast Pair

https://whisperpair.eu/
1•csmantle•1h ago•0 comments

RCS for Business

https://developers.google.com/business-communications/rcs-business-messaging
3•sshh12•1h ago•1 comments

Cyberpunk 2077 VR mod disappears after mod maker pulls the plug

https://www.pcgamer.com/games/vr/cyberpunk-2077-vr-mod-disappears-after-mod-maker-decides-hed-rat...
1•evo_9•1h ago•0 comments

The Tenth Watch for the Tenth Pitch Drop

http://thetenthwatch.com
2•mattas•1h ago•0 comments

Product Validation Launch Platform

https://www.launchradar.cc/
1•abdullah9•1h ago•0 comments