Receipt Anatomy
The fields
| Field | Lives in | What it records |
|---|---|---|
receipt_id | read API + envelope | The receipt's stable identifier (ULID). The read-API copy and the envelope copy match. |
request_id | read API + envelope | The request that produced this receipt. |
client_correlation_id | read API | Your own correlation id, if you sent one; otherwise null. |
primitive / primitive_version | read API + envelope | Which verification primitive produced the receipt (e.g. claim, hash_notarize) and its version. |
schema_version | read API + envelope | The envelope schema this receipt verifies under. Hashed into chain_self, so every receipt names its own recipe. |
produced_at | read API + envelope | When the receipt was minted (UTC). |
verdict | envelope | The primitive's verdict word — see the verdict grammar below. It lives ONLY inside the signed envelope. There is no unsigned copy of it on the read API, on purpose: an unsigned verdict can be altered while the digest, the chain value and the signature all stay valid, which produces a receipt whose every clause is true and whose whole is a lie. Read the verdict from the envelope. |
confidence / confidence_score | envelope | A coarse tier (low/medium/high) and an optional numeric score; deterministic acts carry the scoreless form. Signed-only, for the same reason as verdict — these three are the measurement, and the measurement is not repeated outside the signature. |
retention_tier / expires_at / legal_hold | read API | How long the full server-side record is retained. A receipt you hold verifies offline regardless. The public specimen is a tier B mint: it carries extracted source text alongside its digests, and its retention_tier field says so. Free-tier mints are tier C — digests only. |
signed | read API | Whether a signature rides this receipt (signed mints carry the chain block). |
content_digest | read API + envelope.chain | sha256 of the envelope's RFC 8785 canonical bytes with the chain block removed — the commitment to every signed fact. |
chain_prev / chain_self | read API + envelope.chain | The per-account hash chain: chain_prev is the prior receipt's chain_self (GENESIS for the first); chain_self commits to content_digest, chain_prev, and schema_version (the exact byte layout is published at api.bluefoxedge.ai/getting-started, step 4). |
envelope | read API | THE SIGNED FACTS, and the only place the receipt states its verdict. Everything inside (minus the chain block) is bound by content_digest, which the signature commits to. The rule the shape now enforces rather than merely documents: nothing the receipt DECIDES is repeated outside the signature. What is still repeated outside it — the identifiers, the timestamps and the chain values — is decision-inert convenience that must byte-equal its signed counterpart, and verifiers read from the envelope either way. |
envelope.edge_role | envelope | The role BlueFox claims for itself: evidence-layer. Not an authority, not an archive of record. |
envelope.assertion_type | envelope | reliance — the receipt records that a check or presentation was relied on. |
envelope.reliance_borne_by | envelope | Who bears the reliance the receipt records (e.g. customer-auditor). |
envelope.not_an_attestation | envelope | Always true. The receipt's own statement that it certifies nothing — see below. |
envelope.non_claims | envelope | The list of things this receipt is NOT, shipped inside the signed bytes so the disclaimer cannot be stripped. |
envelope.sources[] | envelope | What was checked: per-source digests (source_bytes_digest, extracted_text_hash), fetch_timestamp, extraction_method/quality, and asserted_by — who vouches for the bytes (as-observed-by-Edge, or as-stated-by-caller for presented digests). |
envelope.details | envelope | Primitive-specific record (for presented-digest mints: your digest and optional meta, stored verbatim, never interpreted). |
envelope.recompute_inputs | envelope | What you would need to re-run the check: model id, prompt identifiers, the retained-input reference, and the recompute horizon. |
envelope.chain | envelope | The signing block: key_id (the JWKS kid), signature (detached ed25519 over the chain_self string), plus chain and digest copies. Removed before the content digest is computed — the signature covers the rest. |
jwks_url | read API | Where the public keys live: https://api.bluefoxedge.ai/.well-known/jwks.json. A convenience pointer only. NORMATIVE: a verifier MUST NOT follow the jwks_url inside a receipt — it sits outside the signature, so a forged receipt can name the forger's own key set. Pin the key set out of band at https://api.bluefoxedge.ai/.well-known/jwks.json. |
The verdict grammar
verdict speaks the primitive's own vocabulary. Claim checks answer in judgment words (e.g. accurate, inaccurate, neutral, unverifiable) about the claim against the evidence in sources[]. The presented-digest mint (POST /v1/notarize/hash) always answers with the act-word notarized: it records that your digest was presented at that time — the content behind the digest is never seen, fetched, or judged.
Either way, not_an_attestation: true and the four non_claims ride inside the signed bytes of every envelope: a receipt is proof of reliance, never proof of truth — not a certification, rating, or screening decision, and stripping the disclaimer breaks the signature.
A receipt, abridged
The published specimen (fetch the complete original at www.bluefoxedge.ai/specimen-receipt.json):
{
"data": {
"receipt_id": "01KZAQKW6D4BSSKPP1YEBQ07DS",
"primitive": "claim",
"schema_version": "1.0.0",
"verdict": "neutral",
"confidence": "low",
"content_digest": "sha256:a04ed8ca54fd7da9…",
"chain_prev": "GENESIS",
"chain_self": "sha256:75c3000e255b7644…",
"envelope": {
"verdict": "neutral",
"edge_role": "evidence-layer",
"assertion_type": "reliance",
"not_an_attestation": true,
"non_claims": [
"not a data vendor / republisher of the underlying corpus",
"not a good-law / citator authority",
"not an attestation, certification, rating, or screening decision",
"not an archive of record, issuer, or trust root"
],
"sources": [ { "asserted_by": "as-observed-by-Edge", "…": "…" } ],
"recompute_inputs": { "…": "…" },
"chain": {
"key_id": "6d5714a8479aaea7…",
"signature": "iKWHcXH56aXq2Dz4…"
}
},
"jwks_url": "https://api.bluefoxedge.ai/.well-known/jwks.json"
},
"meta": { "request_id": "…", "timestamp": "…" }
}Check one yourself in three steps: Verify a Receipt. Every signed mint is also appended to a public transparency log: Walk the Log.