A named human approved this agent to do this.
The entire signed event rides in the URL fragment, so it verifies in your browser and never reaches our server — we do not learn that you opened it. Forward it to a regulator, a customer, or a sceptic.
How it works
They sign the exact action with their own Ed25519 key. We never hold it.
The whole signed decision is encoded into the URL fragment.
Their browser verifies it against the key inside the event itself.
A fragment is never sent to a server. Not ours, not anyone's.
What a receipt does NOT say
That the purchase was wise, that the supplier is legitimate, or that anyone independent reviewed it. It says one person, named and holding a key, approved this exact amount to this exact merchant, and cannot later deny it. Everything else is somebody else's job.
Receipts for your own approvals
Every high-stakes action your agents take, with a link like this one you can forward to anyone.
One field. One click to leave. Never sold.