Receipt schema reference
scopebond:receipt evidence contract v1 — A countersigned receipt whose signature covers the complete canonical payload. It attests the gateway's recorded decision and adapter assertion; it does not independently prove an external effect or compliance.
Schema id: https://scopebond.com/schema/receipt-v1.json. Package: @scopebond/policy-schema 0.6.0 (newer published versions may add fields). A receipt has two top-level members, payload (everything that is signed, canonicalized with RFC 8785) and signature. What a receipt proves, and does not, is explained in Receipts and verification.
receipt
A countersigned receipt whose signature covers the complete canonical payload. It attests the gateway's recorded decision and adapter assertion; it does not independently prove an external effect or compliance.
| Field | Required | Shape | Description |
|---|
payload | yes | object | |
signature | yes | object | |
receipt.payload
| Field | Required | Shape | Description |
|---|
type | yes | const "scopebond:receipt" | |
evidence_version | yes | const "1.0" | |
canonicalization | yes | const "RFC8785" | |
intent | yes | object | The action the agent signed (the ACTA payload_digest source). |
intent_hash | yes | string, pattern ^[0-9a-f]{64}$ | Compatibility alias of action_ref.authorized_intent_hash. |
action_ref | yes | object | |
policy_hash | yes | string | ACTA policy_digest = the registered policy hash. |
policy_version | yes | integer, min 1 | |
policy_ref | yes | object | |
verifier_version | yes | string | |
realtime_result | yes | "allow" · "deny" · "approved" · "timeout" · "not_evaluated" | |
executed | yes | boolean | |
execution_ref | yes | string \| null | Compatibility alias of execution.reference. |
execution | yes | object | |
redaction | yes | object | |
authorization | yes | object or object or object or object | |
attester | yes | object | |
timestamp | yes | string, format date-time | |
evidence_class | no | "signed_intent" · "pep_authorized" · "boundary" | Evidence class (§15). Absent = legacy, inferred at read time. Never upgraded. |
principal | no | object | Required for pep_authorized: the validated identity subject and issuer. |
boundary | no | object | Required for boundary: the gate that decided a consequence and the attributed actor. |
override | no | object or object | A person at the computer allowed an action a rule blocked (agent_dialog, with a reason whose SHA-256 is reason_digest), or the coding agent's own permission prompt was offered for it (harness_prompt). Present only with realtime_result "approved". |
receipt.payload.intent
The action the agent signed (the ACTA payload_digest source).
| Field | Required | Shape | Description |
|---|
action_type | yes | string | |
asset | no | string | |
amount | no | integer, min 0 | |
params | no | object | |
receipt.payload.action_ref
| Field | Required | Shape | Description |
|---|
action_id | no | string, length 16–200 | |
authorized_intent_hash | yes | string, pattern ^[0-9a-f]{64}$ | |
evidence_intent_hash | yes | string, pattern ^[0-9a-f]{64}$ | |
receipt.payload.policy_ref
| Field | Required | Shape | Description |
|---|
id | yes | string \| null | |
version | yes | integer, min 1 | |
digest | yes | string, pattern ^[0-9a-f]{64}$ | |
receipt.payload.execution
| Field | Required | Shape | Description |
|---|
state | yes | "simulated" · "observed_not_evaluated" · "denied" · "allowed_pending" · "cooperative_allow" · "executed" · "failed" · "outcome_unknown" | |
assertion | yes | "none" · "gateway_simulation" · "adapter_reported_success" · "adapter_reported_failure" · "adapter_outcome_unknown" | |
reference | yes | string \| null | |
external_effect | yes | const "not_independently_verified" | |
receipt.payload.redaction
| Field | Required | Shape | Description |
|---|
profile | yes | const "scopebond:minimized-intent/v1" | |
paths | yes | array, items: string | |
| Field | Required | Shape | Description |
|---|
mode | yes | const "authenticated" | |
agent | yes | see intentAuthorization | |
approval | yes | see approval or null | |
| Field | Required | Shape | Description |
|---|
mode | yes | const "insecure_development" | |
agent | yes | null | |
approval | yes | null | |
No agent authorization — a gate attested a consequence (boundary-class receipts). Identity is the receipt's boundary attribution.
| Field | Required | Shape | Description |
|---|
mode | yes | const "boundary" | |
agent | yes | null | |
approval | yes | null | |
No agent signature — a proxy/PEP decided a request carrying the caller's own identity (pep_authorized receipts). Identity is the receipt's principal.
| Field | Required | Shape | Description |
|---|
mode | yes | const "pep" | |
agent | yes | null | |
approval | yes | null | |
receipt.payload.attester
| Field | Required | Shape | Description |
|---|
kind | yes | "gateway" · "module" · "resource" | |
kid | yes | string | |
receipt.payload.principal
Required for pep_authorized: the validated identity subject and issuer.
| Field | Required | Shape | Description |
|---|
subject | yes | string, length 1+ | |
issuer | yes | string, length 1+ | |
receipt.payload.boundary
Required for boundary: the gate that decided a consequence and the attributed actor.
| Field | Required | Shape | Description |
|---|
gate | yes | "merge" · "deploy" · "egress" · "platform_event" | |
outcome_ref | yes | string, length 1+ | |
attribution | yes | object | |
receipt.payload.boundary.attribution
| Field | Required | Shape | Description |
|---|
kind | yes | "asserted" · "inferred" | |
actor | yes | string, length 1+ | |
receipt.payload.override
A person at the computer allowed an action a rule blocked (agent_dialog, with a reason whose SHA-256 is reason_digest), or the coding agent's own permission prompt was offered for it (harness_prompt). Present only with realtime_result "approved".
| Field | Required | Shape | Description |
|---|
version | yes | const 1 | |
rule | yes | string, pattern ^[a-z0-9-]{1,64}$ | |
method | yes | "agent_dialog" · "harness_prompt" | |
state | yes | "allowed" · "offered" | |
repeat_of | yes | null or string, length 16–200 | |
reason_digest | yes | null or string, pattern ^[0-9a-f]{64}$ | |
reason_length | yes | null or integer, min 1 | |
os_user_digest | yes | null or string, pattern ^[0-9a-f]{64}$ | |
decided_at | yes | string, format date-time | |
receipt.signature
| Field | Required | Shape | Description |
|---|
alg | yes | "Ed25519" · "ES256" · "secp256k1" · "EIP-712" | |
sig | yes | string | |
Consistency rules
The schema enforces these if/then relations inside payload:
- if `
= ? then realtime_result = "approved"` - if
evidence_class = "boundary" then ` = ?, otherwise = ?` - if
evidence_class = "pep_authorized" then ` = ?, otherwise = ?` - if
execution.state = "executed" then executed = true, otherwise executed = false - if
execution.state = "simulated" then execution.assertion = "gateway_simulation" - if
execution.state = "observed_not_evaluated" then realtime_result = "not_evaluated", otherwise realtime_result ≠ "not_evaluated"
Definitions ($defs)
identity
| Field | Required | Shape | Description |
|---|
kid | yes | string, pattern ^key:[0-9a-f]{16}$ | |
alg | yes | const "Ed25519" | |
intentAuthorization
| Field | Required | Shape | Description |
|---|
version | yes | const "1.0" | |
request_id | yes | string, pattern ^[A-Za-z0-9._:-]+$, length 16–200 | |
issued_at | yes | string, format date-time | |
expires_at | yes | string, format date-time | |
signer | yes | see identity | |
intent_hash | yes | string, pattern ^[0-9a-f]{64}$ | |
signature | yes | string, length 40+ | |
approval
| Field | Required | Shape | Description |
|---|
version | yes | const "1.0" | |
approval_id | yes | string, pattern ^[A-Za-z0-9._:-]+$, length 16–200 | |
issued_at | yes | string, format date-time | |
expires_at | yes | string, format date-time | |
approver | yes | see identity | |
intent_hash | yes | string, pattern ^[0-9a-f]{64}$ | |
policy_ref | yes | object | |
decision | yes | const "approve" | |
signature | yes | string, length 40+ | |