Changelog

What shipped, dated. Each entry corresponds to a public, verifiable artifact — that's the house style.

Tanilo was named AgentOracle until September 2026. Entries before that date refer to the same service under its previous name.

  1. Site audit corrections — quorum description, per-claim evidence disclosure, incident-record dating

    "Four independent sources" was replaced across the site with an accurate description: multiple quorum members plus an adversarial re-check pass, with sources retrieved per claim. Three of the four members share a backend; the prior phrasing implied independence that didn't exist.

  2. Incident record (2026-08-25) corrected — dating and self-consistency

    The record claimed to be "not edited after publication" while carrying an undated 2026-09-22 addition; that addition is now dated and moved into the Corrections section. "Nothing below is edited for the rename" was replaced with an accurate statement: service names were updated to Tanilo, dates/hashes/key IDs/quoted findings were not. The lede's "five days undetected" was corrected to match the four-day window (21-25 August) stated elsewhere on the same page. Full record: /incidents/2026-08-25-canned-verdicts ↗.

  3. Benchmarks page — backend-replacement disclosure added to the AVeriTeC headline

    The 57.6% AVeriTeC figure is measured on the pipeline as it existed on 2026-05-28. The backend was replaced in September 2026; the page now discloses that the number has not been re-run since, rather than presenting it as current.

  4. Benchmarks page — /v1/sign, /v1/sign/batch, and /v1/compose latency withdrawn from live presentation

    All three were presented with runnable curl commands against a live host. /v1/sign and /v1/sign/batch are the forgery-oracle endpoints closed in a8ce2a18d (see the incident record) and now require auth; /v1/compose was already marked withdrawn. All three are now labeled historical, dated to their original 2026-06-25 measurement against agentoracle.co, since tanilo.io did not exist at that date and carries no live API today.

  5. Incident record published — canned verdicts, 21-25 August 2026

    Four-day window in which /evaluate signed and returned receipts for evaluations it never performed. The signed layer halted every affected request; the presentation body did not disclose that. Fixes shipped 4a8b37177, 98b3b7e78, c28c5dd6f, 49261a37b, a8ce2a18d. External review by @giskard09 found and closed a same-class defect in the conformance sample and an unauthenticated signing path; kid separation remains open with no date. Full record: /incidents/2026-08-25-canned-verdicts ↗.

  6. Verifier v0.1.0 published to PyPI — three-outcome status semantics live on the released artifact

    pip install agentoracle-receipt-verify==0.1.0 · MIT · offline verification against the published JWKS. Public API exposes STATUS_VALID, STATUS_INVALID, STATUS_INDETERMINATE. Post-publish gate ran against the installed package in a fresh venv — the no-key path returns indeterminate rather than valid. pypi ↗

  7. Experiment A pre-registered — design frozen, three model families, results Sep 2

    Two deep-research agents, one gated through /evaluate (fail-closed, replans on failing verdict), 200 questions across four domains. Measured quantity: which citations survive independent verification. Ground-truth stack deterministic. The pre-registration document was public before any data was collected; the harness and the frozen question set land before the first run, on the schedule published in the repository README. pre-registration ↗

    Corrected 2026-08-17. This entry originally read “Pre-registration document, harness, and questions all public before any data was collected.” That overstated what was public: at the time of writing the harness was a disclosed stub and the question set was an empty array, both scheduled in the repository README for 2026-08-17, ahead of the 2026-08-19 run start. The pre-registration document itself was complete and public as described. No data had been collected at any point, and none has been collected as of this correction.

  8. Virtuals showcase merged — a live production receipt now sits in Virtual-Protocol/acp-cli-demos

    10 files, +670/-0, merge commit c08af80e7a12. Receipt blob d13a275e1c4d is byte-identical to the production receipt. Anyone can clone the showcase folder, install the verifier, and run python3 verify.py receipt.json against the live JWKS. showcase ↗

  9. Deterministic mode — POST /v1/verify-facts: six check types, no LLM in the trust chain, check_mode recorded inside the signed payload

    /docs/deterministic-mode ↗

  10. v0.4 draft rev-2 — per-layer provenance design (layer_trace, mode ∈ {recomputable, signed}, three-state absence semantics) folded in from public design collaboration

    commit ↗

  11. Routine credential rotation completed — all previously issued receipts verify unchanged against the published JWKS

    jwks ↗

  12. /pricing page + MCP homepage block live

    /pricing ↗

  13. Self-serve open — card → API key → signed receipts, live

    get a key ↗

  14. v0.4 conformance suite complete — 1 accept, 3 reject, 3 status vectors; two independent implementations; every envelope and wrapper hash recomputed byte-identical on both sides

    suite ↗

  15. First v0.4 conformance vector shipped — v04-accept-001, two-party signed (AgentOracle + AgentTrust legs), byte-identical across three independent canonicalizations

    vector ↗

  16. Sequence-integrity example merged into the community pre-action governance conformance suite — N artifacts over time, Merkle inclusion + tamper demos

    merge ↗

  17. Canonical verdict→gate mapping published, content-addressed — sha256-addressed immutable doc

    mapping ↗

  18. Third cross-citing draft filed in the receipt family — draft-msebenzi-evidence-action-00 cites draft-krausz-verification-state

    datatracker ↗

  19. Composed multi-issuer envelope example merged into the community conformance suite — N signers, one artifact

    PR #4 ↗

  20. Independent byte-identical second implementation merged — AgentTrust rebuilt the format from spec text alone

    PR #33 ↗

  21. First candidate profile entry in the receipt-format registry — verification.v0.3 entered as a candidate profile in the ERC-8210 Receipt Profile Registry

    registry ↗

  22. IETF Internet-Draft FILED — draft-krausz-verification-state-01

    datatracker ↗

  23. Open-source receipt verifier published — offline JWS verification, MIT licensed

    github ↗

  24. Cross-operator benchmark live — open methodology, open submissions

    github ↗

  25. Receipt spec v0.3 — binary-halt gate + canonical/derived/version-bound mapping

    spec ↗

  26. AVeriTeC 2024 dev published — 57.6% overall, held-out 57.7%, MIT licensed

    repo ↗

  27. Pinned in x402trace v0.3.3 — first operator-contributed fixture in the harness

    release ↗

  28. Live on SKALE Base — first test settlement, gasless on SKALE

    explorer ↗

  29. Tutorial #4 — claim verification in AI content approval workflows

    Published under the pre-rename name; unlinked here. (dev.to/agentoracle/how-to-add-claim-verification-to-your-ai-content-approval-workflow-3797)

  30. Indexed in Coinbase Bazaar — 8 test settlements verified, our own payments, confirming the payment path end to end