Tanilo verifies the claim before the action and issues a receipt anyone can recompute. Including people who don't trust us.
Verification over the open world is not deterministic — the judgement involves retrieval and inference, and we say so rather than claiming otherwise.
What we make deterministic is the derivation: a published rule and canonical bytes. Given the receipt and the specification, a third party recomputes the gate decision offline, without calling us and without trusting us.
One API call sits between your agent and its consequential actions. Here is the whole product:
"This invoice is unpaid." "This drug interaction is safe." "This customer is eligible." The claim that justifies the action.
Independent sources, adversarial re-checks, a published rule table — before the action runs, not after it goes wrong.
Canonical bytes (RFC 8785), Ed25519 signature, the verdict and the exact rules used — sealed at issue.
Offline, against published keys. Auditors, counterparties, courts — no account needed, no trust in us required.
Don't take the homepage's word for anything. Pull a real, live-verifying receipt from our public partner showcase and check it on your own machine, offline.
This is a real production receipt, byte-identical to the one our system issued, published in a partner's public showcase repo — not a synthetic example. The verifier is MIT-licensed, under 250 lines, no dependencies on us. Read it before you trust it — that's the point.
A Model Context Protocol server for Cursor, Claude Desktop, Codex, and any MCP-compatible client — verify signed receipts, check confidence scores, and pull the current JWKS from inside your editor. Published today as agentoracle-mcp; a tanilo-mcp release is pending.
Point at a receipt file or URL, get valid: True — or the exact reason it isn't — without leaving the editor.
The MCP server runs locally, verifies against the public JWKS, and never phones home.
Receipts the MCP verifier checks are byte-identical to the ones the reference verifiers produce.
Published on npm as agentoracle-mcp — still the real published package.
A log is the operator's story. A receipt carries a decision a third party recomputes — verdict, rules, signature.
Letting the operator keep the record is letting the suspect write the police report.
Change one byte and the signature fails. Backdating fails the same way — timestamps are bound in.
Published keys, canonical bytes. If we disappeared tomorrow, every receipt still verifies.
A separate team, working from the published specification text alone and without access to our implementation, rebuilt the format — matching to the last byte.
IETF-filed, MIT reference code, published conformance vectors in two languages.
The EU AI Act's record-keeping obligations (Article 12) apply from 2 December 2027 for standalone Annex III systems and 2 August 2028 for AI embedded in Annex I products, under Regulation (EU) 2026/1744. Receipts are records an external examiner can verify without trusting you — built for exactly that clause.
Give every consequential agent action an evidence trail. One API call in the loop; a receipt in every audit bundle, ready for whatever governance stack sits above you.
Finance, health, legal — anywhere "the AI said so" isn't a defense. When something is questioned, hand over proof instead of promises.
Self-serve checkout is launching. Email us and we'll set you up manually in the meantime — 2,000 verifications a month, full signed receipts, the works.
Early access — not yet purchasable. For autonomous agents paying their own way: x402 pay-per-call with USDC, settled on Base or SKALE. No subscription, no account — the agent pays, the receipt returns.
Volume, SLAs, custom mapping tables, composed multi-issuer receipts, co-signing with your own keys.
No — at launch, card checkout gets you an API key. Wallets are optional, and only for the x402 pay-per-call path, once it launches for autonomous agents.
That a specific claim was checked at a specific time, against named sources, under a published rule table, producing a specific verdict — and that none of it has been altered since. It proves what was checked and what the answer was. It doesn't prove things it can't: our whitepaper publishes the limits next to the strengths.
Install the MIT-licensed verifier (or write your own from the IETF draft — a team has already done exactly that, working from the published text without access to our implementation, byte-identically). Verification runs offline against our published public keys. You never need our permission, our API, or our continued existence.
Article 12 requires records of high-risk AI operation, applicable from 2 December 2027 for standalone Annex III systems and 2 August 2028 for AI embedded in Annex I products, under Regulation (EU) 2026/1744. Receipts are records that verify independently — the property plain logs can't offer an examiner. See our free Article 12 considerations tool.
You get the same signed receipt with verdict "do_not_act" and the adversarial result that produced it. The "no" is evidence too — often the more valuable kind.
At launch, yes — that's the x402 path: the agent pays per verification in USDC (settled on Base or SKALE) and gets the receipt in the response. Built for agent-to-agent commerce.