io.github.xka0085-byte/receiptrail

ReceiptRail

Read-only on-chain receipt check for x402 payments; confirm settlement before trusting a tx.

0.3.0
Version
remote
Transport
4
Tools

Security review

Review passed

Reviewed 1d ago.

  • tools: 4 tools scanned
  • metadata: scanned

No findings.

Tools (4)

  • issue_receipt

    Anchor a SHA-256 digest of delivered content plus the x402 settlement reference on Solana. Returns a permanent, publicly verifiable receipt (poll until outcome === "settled"). Costs 0.001 USDC via x402; if x402_payment_signature is omitted, returns the payment challenge instead (pay 0.001 USDC to the service address, then call again with the payment tx signature).

  • verify_receipt

    Verify an AgentToll receipt against live Solana state: PDA owner must be the AgentToll program and the stored digest must match the receipt. Look up by receipt_id, or by x402_payment_ref (always works — the receipt lives on-chain). Read-only, no cost.

  • get_receipt

    Fetch full receipt details: digests, checks, outcome, amount, buyer, seller, timestamp, PDA. Look up by receipt_id, or by x402_payment_ref (always works — the receipt lives on-chain). Read-only, no cost.

  • verify_x402_receipt

    Verify a signed receipt in the official x402 offer-receipt extension format (docs.x402.org/extensions/offer-receipt, npm @x402/extensions). Accepts {format:"jws", signature} artifacts (JWS with EdDSA/Ed25519 or ES256/P-256), checks structure, required payload fields (version/network/resourceUrl/payer/issuedAt), cryptographic signature, optional freshness window, and optional expected values. Public key resolves automatically from did:key/did:web/did:jwk kid, or pass public_key_jwk directly. Read-only, no cost.