cd /news/ai-agents/build-for-a-friend-receipt-lens · home › topics › ai-agents › article
[ARTICLE · art-143729] src=dev.to ↗ pub= topic=ai-agents verified=true sentiment=↑ positive

Build for a Friend: Receipt Lens

A developer built Receipt Lens, an open-source tool that verifies AER-1 execution receipts and visualizes an AI agent's step-by-step trace, including timing and cryptographic Merkle root checks. The verifier is a single Python file using only the standard library, written from the public IETF AER-1 draft, and fails closed by reporting "not verified" on any inspection error. A tampered-workflow demo shows the Merkle root check catching an altered step id with the published-versus-recomputed mismatch displayed.

by read3 min views1 publishedOct 2, 2026

Entered in the Best Use of Sentry Agent Tracing category: tooling that shows an agent's work, with traces.

A friend of mine runs AI agents to do real work: research, data pulls, summaries. The agents are useful. The problem is what happens after. The agent says "done," hands over an answer, and everything in between is a black box.

He asked me the simplest question in the world: what did the agent actually do?

I didn't have a good answer. If a step was slow, skipped, or faked, nobody would know. If the agent claimed it called five tools and called two, there was no way to check. The output looked right, so we trusted it. That's not verification. That's hope.

This weekend I built him something real.

Receipt Lens takes an AER-1 verifiable receipt (JSON) and shows you the agent's execution trace: every step it ran, in order, how long each took, and whether the receipt checks out cryptographically.

Paste a receipt, and you get:

There are three demo buttons. Click "Demo: tampered workflow" and watch it work: the same valid five-step receipt, one step id altered, and the Merkle root check catches it with the exact published vs. recomputed mismatch shown on screen.

This project exists because of an open standard.

AER-1 is an open IETF draft: a specification for verifiable execution receipts, readable by anyone, implementable by anyone. There is no permission to ask, no license to buy, no vendor to negotiate with. The draft text is public on the IETF Datatracker. The conformance test vectors are public. I wrote Receipt Lens's entire verification engine fresh from the draft text this weekend, in one session, with zero dependencies beyond Python's standard library.

That is what open innovation buys you. A closed ecosystem would have made this weekend impossible. I would have needed API keys, SDK agreements, a partnership call. Instead I needed the spec, the spec was public, and the tool exists now.

Openness also compounds. Because the format is open, anyone can mint these receipts. Because the verification is open, anyone can check them. Because the tool is open (MIT license), anyone can run it, fork it, or build something better on top of it. Every layer feeds the next. Closed formats extract value. Open formats multiply it.

The backend is one Python file, standard library only (http.server, hashlib, json). It handles three receipt shapes:

output_hash commitment over the canonical bytes. The Merkle implementation reproduces the draft's published example root from its five step ids, so I know the construction matches the spec byte for byte. Timestamps are validated strictly (February 30 gets rejected). The server fails closed: any inspection error reports "not verified," never "valid."

The frontend is a single HTML page: paste box, demo s, verdict banner, timeline visualization, check list, honest-limits panel.

git clone https://gitlab.com/rambozambodotdev/receipt-lens.git
cd receipt-lens
python3 app.py

Open http://localhost:8137. No dependencies. Paste a receipt or click a demo.

The demos cover the verifier's correctness. The next step is volume: pointing Receipt Lens at real agent runs, finding the receipts that don't verify, and figuring out why. The interesting bugs are always in production traces, not demos.

If you run agents for real work, try it on your own receipts. If something comes back invalid, that's the tool doing its job.

Built October 2, 2026, within the Hacktoberfest Weekend Challenge window. New code, written for this challenge. The AER-1 specification it implements is an open IETF draft, free for anyone to read, implement, and build on.

── more in #ai-agents 4 stories · sorted by recency
── more on @receipt lens 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/build-for-a-friend-r…] indexed:0 read:3min 2026-10-02 · —