Skip to content

Trust Signals

Provenance is **mandatory** in v0.2. Every stage run records:

v0.4.0concept

Trust signals (v0.2)

Provenance is mandatory in v0.2. Every stage run records:

{
  "stage_id": "refactor",
  "started_at": "2026-09-15T12:34:56.789Z",
  "completed_at": "2026-09-15T12:35:01.234Z",
  "duration_ms": 4445,
  "model_used": "claude-3.5-sonnet",
  "uses": [
    {
      "id": "code_rewriter",
      "version": "0.2.1",
      "version_pin": "strict",
      "content_hash": "keccak256:9a4f...",
      "fetched_at": "2026-09-15T12:34:57.000Z"
    }
  ],
  "mcp_servers_validated": [],
  "input_sha256": "f4c1...",
  "output_sha256": "a92d...",
  "output_format": "code",
  "output_format_validated": true,
  "cost_micro_usdc": 12650,
  "tokens": { "input": 1234, "output": 567 }
}

Pipeline-level provenance (top-level payload) aggregates:

{
  "pipeline_name": "bobs-code-refactor",
  "pipeline_version": "1.2.0",
  "spec_hash": "keccak256:7e3b...",
  "inputs_hash": "keccak256:c1f0...",
  "outputs_hash": "keccak256:8ab2...",
  "ts": "2026-09-15T12:35:01.234Z",
  "stages": [ ... StageExecutionRecord[] ... ]
}

This entire payload is signed with the operator’s secp256k1 key (EIP-191) — buyers can verify reproducibility and that no SKILL was substituted. v0.3 will add TEE attestation alongside operator signature.