The receipt tree

On 26 September 2026 one agent session produced ten runs. Each run ends in an execution hash, and the ten hashes fold into a single Merkle root that three independent timestamp authorities signed. This page rebuilds that tree in your browser from the real hashes, edits one run to see exactly which hashes break, and proves a single run with four sibling hashes.

Goal of this animation

Show how ten real runs fold into one timestamped root, why one edited run is caught, and how one run can be proven without revealing the others.

🔒 No personal dataThe ten runs are synthetic demonstration runs and the page holds only their hashes. Apart from loading its fonts and its own files, the page makes no network requests, and every hash on the bricks is computed in your browser. The page's security policy blocks fetch, XHR and WebSocket connections outright (connect-src 'none'), and nothing is stored.
☁ Our server is Cloudflare“AINumbers server” means Cloudflare today: the site's files are delivered through Cloudflare's network. This page never asks it anything after loading. You do trust the page for its verifier code and pinned roots, and limit 3 below says how to check without it.
What the red, amber and green bricks mean
● green · recomputed here and it matches● amber · could not be fully checked here● red · a mismatch was caught
✓ MATCHESThe hash on the brick was recomputed from the bricks below it, and the root equals the root the timestamp authorities signed.
✗ MISMATCH CAUGHTOne edited run changes every hash on its path to the root and nothing else. The new root no longer fits the timestamps.
? NOT FULLY CHECKEDThe Sigstore token's imprint and signature verify, but its certificate chain is not pinned in this page. That is never counted as a pass.
WHAT A MATCH CANNOT TELLA root shows which hashes belong together and a timestamp shows when. Neither shows that a run was computed correctly or that its inputs were true.
Ten runs, ten hashes
✓recomputed, matches?not fully checked✗mismatch caught┄dashed brick: paired with itself
drag to rotate

Limits of this page

1. The evidence is the ten execution hashes and three timestamp tokens of the Agent Staircase session of 26 September 2026. This page holds the hashes alone. The runs' inputs and outputs are not in it, so it can show how the hashes fold and what a change does, and it cannot re-run any run.

2. The folding rule is the one build_session_receipt uses in the MCP worker: SHA-256 over the two child hashes written as lowercase hex text and joined, a binary tree, and the last node of an odd level paired with itself. The page applies that rule through the shared verifier kit and reproduces the anchored root from the ten hashes.

3. Two of the three timestamps chain to roots pinned in this page, DigiCert and FreeTSA. The Sigstore token's imprint and signature check, but its root is not pinned here, so its chain shows as not checked. The timestamp verifier in this page checks one certificate hop and does not look up revocation, so a full audit would also use the Anchor Suite verifier. An auditor who trusts nothing here can check each token with openssl ts -verify.

4. An inclusion proof shows the hashes of neighbouring runs. A hash does not reveal a run's inputs, though anyone who can guess the inputs can test the guess against it. The tamper and proof views run only in this page's memory and nothing is sent or stored.

Evidence from github.com/PostOakLabs/ainumbers · runs in your browser · Zero PII · CC BY 4.0 · Post Oak Labs