{"slug": "build-for-a-friend-receipt-lens", "title": "Build for a Friend: Receipt Lens", "summary": "A developer built Receipt Lens, an open-source tool that verifies AER-1 execution receipts and visualizes an AI agent's step-by-step trace, including timing and cryptographic Merkle root checks. The verifier is a single Python file using only the standard library, written from the public IETF AER-1 draft, and fails closed by reporting \"not verified\" on any inspection error. A tampered-workflow demo shows the Merkle root check catching an altered step id with the published-versus-recomputed mismatch displayed.", "body_md": "*Entered in the **Best Use of Sentry Agent Tracing** category: tooling that shows an agent's work, with traces.*\n\nA friend of mine runs AI agents to do real work: research, data pulls, summaries. The agents are useful. The problem is what happens after. The agent says \"done,\" hands over an answer, and everything in between is a black box.\n\nHe asked me the simplest question in the world: *what did the agent actually do?*\n\nI didn't have a good answer. If a step was slow, skipped, or faked, nobody would know. If the agent claimed it called five tools and called two, there was no way to check. The output looked right, so we trusted it. That's not verification. That's hope.\n\nThis weekend I built him something real.\n\n[Receipt Lens](https://gitlab.com/rambozambodotdev/receipt-lens) takes an AER-1 verifiable receipt (JSON) and shows you the agent's execution trace: every step it ran, in order, how long each took, and whether the receipt checks out cryptographically.\n\nPaste a receipt, and you get:\n\nThere are three demo buttons. Click \"Demo: tampered workflow\" and watch it work: the same valid five-step receipt, one step id altered, and the Merkle root check catches it with the exact published vs. recomputed mismatch shown on screen.\n\nThis project exists because of an open standard.\n\nAER-1 is an open IETF draft: a specification for verifiable execution receipts, readable by anyone, implementable by anyone. There is no permission to ask, no license to buy, no vendor to negotiate with. The draft text is public on the IETF Datatracker. The conformance test vectors are public. I wrote Receipt Lens's entire verification engine fresh from the draft text this weekend, in one session, with zero dependencies beyond Python's standard library.\n\nThat is what open innovation buys you. A closed ecosystem would have made this weekend impossible. I would have needed API keys, SDK agreements, a partnership call. Instead I needed the spec, the spec was public, and the tool exists now.\n\nOpenness also compounds. Because the format is open, anyone can mint these receipts. Because the verification is open, anyone can check them. Because the tool is open (MIT license), anyone can run it, fork it, or build something better on top of it. Every layer feeds the next. Closed formats extract value. Open formats multiply it.\n\nThe backend is one Python file, standard library only (`http.server`, `hashlib`, `json`). It handles three receipt shapes:\n\n`output_hash` commitment over the canonical bytes.\nThe Merkle implementation reproduces the draft's published example root from its five step ids, so I know the construction matches the spec byte for byte. Timestamps are validated strictly (February 30 gets rejected). The server fails closed: any inspection error reports \"not verified,\" never \"valid.\"\n\nThe frontend is a single HTML page: paste box, demo loaders, verdict banner, timeline visualization, check list, honest-limits panel.\n\n```\ngit clone https://gitlab.com/rambozambodotdev/receipt-lens.git\ncd receipt-lens\npython3 app.py\n```\n\nOpen [http://localhost:8137](http://localhost:8137). No dependencies. Paste a receipt or click a demo.\n\nThe demos cover the verifier's correctness. The next step is volume: pointing Receipt Lens at real agent runs, finding the receipts that don't verify, and figuring out why. The interesting bugs are always in production traces, not demos.\n\nIf you run agents for real work, try it on your own receipts. If something comes back invalid, that's the tool doing its job.\n\n*Built October 2, 2026, within the Hacktoberfest Weekend Challenge window. New code, written for this challenge. The AER-1 specification it implements is an open IETF draft, free for anyone to read, implement, and build on.*", "url": "https://wpnews.pro/news/build-for-a-friend-receipt-lens", "canonical_source": "https://dev.to/rambozambo/build-for-a-friend-receipt-lens-pjk", "published_at": "2026-10-02 07:52:04+00:00", "updated_at": "2026-10-02 08:06:57.304476+00:00", "lang": "en", "topics": ["ai-agents", "ai-safety", "developer-tools", "agent-protocols", "ai-tools"], "entities": ["Receipt Lens", "AER-1", "IETF", "GitLab", "Hacktoberfest", "Sentry"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/build-for-a-friend-receipt-lens", "markdown": "https://wpnews.pro/news/build-for-a-friend-receipt-lens.md", "text": "https://wpnews.pro/news/build-for-a-friend-receipt-lens.txt", "jsonld": "https://wpnews.pro/news/build-for-a-friend-receipt-lens.jsonld"}}