Receipts and attestation
A receipt is the public trace of a private session. It is designed to be useful to someone who will never see the data.
The session receipt, `hermetic/receipt/1`
The app builds it in your browser when you close a session.
| Field | Content |
|---|---|
kind |
session, or attestation when no message was sent. |
service |
The gateway that served the session, today https://api.redpill.ai. |
nonce |
The 32 random bytes your tab sent with the attestation request. |
attestation.report |
The full attestation report: TDX quote, event log, keyset, container configuration. |
attestation.report_sha256 |
sha256 of the report's canonical JSON (RFC 8785). |
attestation.workload_keyset_digest |
The keyset the quote binds: receipt signing key, E2EE keys, TLS keys. |
attestation.compose_hash |
The container configuration measured into RTMR3. |
attestation.enclave_signer |
The ECDSA address the gateway binds into a second quote, when it verified. |
conversation_sha256 |
sha256 of the conversation's canonical JSON. The text itself is not in the file. |
exchanges[] |
For each answer: the request and response hashes, and the enclave's signed ACI receipt. |
What goes on chain
HermeticRegistry.seal stores four values against the receipt hash, keccak256 of the receipt's canonical JSON:
- who sealed it and when;
- the report hash and the keyset digest;
- the ECDSA signer, or zero;
- the model id, in the event only.
No question, no answer, no prompt. A hash can be sealed once.
Verifying a receipt
Drop the file on the receipts page. Your tab:
- Recomputes the receipt hash and reads its seal from Robinhood Chain.
- Checks that the report in the file matches its recorded hash.
- Verifies the TDX quote against Intel's root, with collateral fetched fresh from the Phala PCCS.
- Recomputes the keyset digest and checks that the quote binds it together with the session nonce.
- Verifies every enclave receipt's Ed25519 signature under the attested key, and checks it commits to the recorded request and response hashes.
- Checks that the seal on chain names the same keyset and report.
Whoever kept the transcript can also match it to conversation_sha256. Nobody else learns anything from the file.