Nobody can answer that today. Forge Box issues an ed25519-signed receipt for every agent execution: what ran, what it cost, what policy allowed. Verifiable offline, forever.
{
"id": "rcpt_797a7ff6d425",
"action": "workflow_execution",
"risk_score": 10,
"cost_usd": 0.001,
"timestamp": "2026-09-17T20:49:50.138Z",
"algorithm": "ed25519",
"key_id": "key_2b47722ac3eed01a",
"signature": "RKSobO4a1Y/sBv27ivpb5GNM..."
}
Canonical JSON + ed25519 signature. Byte-exact — one changed field and verification fails. Not "trust our logs."
Spend limits, allowed domains, risk scoring 0-100. Guardrails evaluate before anything executes — denials are recorded too.
Public signing key at a stable endpoint. Your auditor verifies receipts years from now without ever calling your API vendor.
This is the production sandbox — same infrastructure, same signing key, no simulation.
Press "Run it" — output, risk score, and receipt signature appear here.
Free tier. No credit card. Every run comes with a signed receipt — including the ones you run today.
Get audit-ready freeFree tier. Every execution gets a signed receipt.
Already have an account? Sign in