An agent’s day

Give one agent one morning. It needs the --glob flag’s definition from ripgrep, so it reads that one function and not the 7,700-line file it lives in. It writes a summary with three quotations: two from the function, one of the kind a model writes when it stops reading. It refuses to ship the summary unasserted, and assert finds the quote that is not in the source and signs the verdict. It certifies the screenshot it is about to send a vision model. Then it verifies every record it was handed, shows a tampered copy failing, and reads the issuer’s signed day. Six calls; every receipt and record on this page re-derived by the generator before it was written.

6calls answered
3receipts re-hashed
3records verified
$0.02list price for a stranger
5,691ms end to end
partial then pass · a tampered copy fails · 3 records verified

Run 2026-10-11 05:26 UTC against api.s2ar.dev 0.1.1 · 6 calls · 5,691 ms · list price $0.02 for a stranger (these ran on the operator's key and cost nothing) · every number on this page re-derived by tools/walkthrough.py before it was written

1. Read the function, not the file

One symbol out of 1,088; the whole file would have cost the tokens of a small book.

curl -s -X POST 'https://api.s2ar.dev/v1/sym/read' \
  -H "Authorization: Bearer $S2AR_KEY" \
  -H 'content-type: application/json' \
  -d '{"repo": "BurntSushi/ripgrep", "ref": "14.1.1", "file": "crates/core/flags/defs.rs", "symbol": "Glob as Flag"}'

→ HTTP 200 · 735 ms · list price $0.005 · receipt sha256:598d5e19ec2bace6…

tokens_est565
receipt.evidence_hashsha256:598d5e19ec2bace6…
the answer, as JSON
{
  "tokens_est": 565,
  "receipt.evidence_hash": "sha256:598d5e19ec2bace68778add369e74f054ca7dc43c2583e0e1e0c4cbefa58a832"
}

The text field:

impl Glob as Flag (crates/core/flags/defs.rs, lines 2459-2512)
 2459	impl Flag for Glob {
 2460	    fn is_switch(&self) -> bool {
 2461	        false
 2462	    }
 2463	    fn name_short(&self) -> Option<u8> {
 2464	        Some(b'g')
 2465	    }
 2466	    fn name_long(&self) -> &'static str {
 2467	        "glob"
 2468	    }
 2469	    fn doc_variable(&self) -> Option<&'static str> {
… 43 more lines
re-derived by the generator
✓receipt sha256:598d5e19ec2bace6… re-derived: sha256 over the canonical answer, header and body agree
✓the whole file is 230911 bytes, about 57,728 tokens; this answer is about 565 tokens: 57,163 tokens kept out of context

2. Refuse to ship the summary unasserted

The summary carries three quotations. quotes_in_source looks for each of them, verbatim, in the text the agent just read; required_terms and length are the shape. Two quotes are there. The third is the sentence a model writes when it stops reading — the record names it.

curl -s -X POST 'https://api.s2ar.dev/v1/assert' \
  -H "Authorization: Bearer $S2AR_KEY" \
  -H 'content-type: application/json' \
  -d '{"text": "ripgrep's --glob flag is the `impl Flag for Glob` block in crates/core/flags/defs.rs: short name g, long name glob. Its doc says \"Include or exclude file paths.\" and \"This always overrides any other ignore logic.\" On precedence it says \"the first matching glob wins and later ones are ignored\".", "source": "impl Glob as Flag (crates/core/flags/defs.rs, lines 2459-2512)\n 2459\timpl Flag for Glob {\n 2460\t    fn is_switch(&self) -> bool {\n 2461\t        false\n 2462\t    }\n 2463\t    fn name_short(&self) -> Option<u8> {\n 2464\t        Some(b'g')\n 2465\t    }\n 2466\t    fn name_long(&self) -> &'static str {\n 2467\t        \"glob\"\n 2468\t    }\n 2469\t    fn doc_variable(&self) -> Option<&'static str> {\n 2470\t        Some(\"GLOB\")\n 2471\t    }\n 2472\t    fn doc_category(&self) -> Category {\n 2473\t        Category::Filter\n 2474\t    }\n 2475\t    fn doc_short(&self) -> &'static str {\n 2476\t        r\"Include or exclude file paths.\"\n 2477\t    }\n 2478\t    fn doc_long(&self) -> &'static str {\n 2479\t        r#\"\n 2480\tInclude or exclude files and directories for searching that match the given\n 2481\tglob. This always overrides any other ignore logic. Multiple glob flags may\n 2482\tbe used. Globbing rules match \\fB.gitignore\\fP globs. Precede a glob with a\n 2483\t\\fB!\\fP to exclude it. If multiple globs match a file or directory, the glob\n 2484\tgiven later in the command line takes precedence.\n 2485\t.sp\n 2486\tAs an extension, globs support specifying alternatives:\n 2487\t.BI \"\\-g '\" ab{c,d}* '\n 2488\tis equivalent to\n 2489\t.BI \"\\-g \" \"abc \" \"\\-g \" abd.\n 2490\tEmpty alternatives like\n 2491\t.BI \"\\-g '\" ab{,c} '\n 2492\tare not currently supported. Note that this syntax extension is also currently\n 2493\tenabled in \\fBgitignore\\fP files, even though this syntax isn't supported by\n 2494\tgit itself. ripgrep may disable this syntax extension in gitignore files, but\n 2495\tit will always remain available via the \\flag{glob} flag.\n 2496\t.sp\n 2497\tWhen this flag is set, every file and directory is applied to it to test for\n 2498\ta match. For example, if you only want to search in a particular directory\n 2499\t\\fIfoo\\fP, then\n 2500\t.BI \"\\-g \" foo\n 2501\tis incorrect because \\fIfoo/bar\\fP does not match\n 2502\tthe glob \\fIfoo\\fP. Instead, you should use\n 2503\t.BI \"\\-g '\" foo/** '.\n 2504\t\"#\n 2505\t    }\n 2506\t\n 2507\t    fn update(&self, v: FlagValue, args: &mut LowArgs) -> anyhow::Result<()> {\n 2508\t        let glob = convert::string(v.unwrap_value())?;\n 2509\t        args.globs.push(glob);\n 2510\t        Ok(())\n 2511\t    }\n 2512\t}\n", "checks": [{"check": "quotes_in_source", "min_words": 4}, {"check": "required_terms", "terms": ["defs.rs", "--glob"]}, {"check": "length", "unit": "words", "max": 120}]}'

PARTIAL → HTTP 200 · 139 ms · list price $0.005 · receipt sha256:0680dc3297299d83…

verdictpartial
passed2
checks3
results.0.checkquotes_in_source
results.0.okfalse
results.0.evidence{"quotes": 3, "missing": ["the first matching glob wins and later ones are ignored"]}
results.1.oktrue
results.2.oktrue
record_sha2563754515b7150255b…
the answer, as JSON
{
  "verdict": "partial",
  "passed": 2,
  "checks": 3,
  "results.0.check": "quotes_in_source",
  "results.0.ok": false,
  "results.0.evidence": {
    "quotes": 3,
    "missing": [
      "the first matching glob wins and later ones are ignored"
    ]
  },
  "results.1.ok": true,
  "results.2.ok": true,
  "record_sha256": "3754515b7150255bc42ac96cf7df751f5c37a522f26ced50442abe734673ba9e"
}

Assay badge for record 3754515b7150255b

re-derived by the generator
✓receipt sha256:0680dc3297299d83… re-derived: sha256 over the canonical answer, header and body agree
✓record 3754515b7150255b… fetched back from /v1/verify: sealed, signed, and signed by assay-1 (the key at /.well-known/assay.json)
✓as the prose says: verdict = "partial" · passed = 2 · checks = 3 · results.0.evidence.quotes = 3 · results.0.evidence.missing.0 = "the first matching glob wins and later ones are ignored"

3. Certify the screenshot before sending it

By URL, as a GET: the record names the image by hash (the API returns the record, never pixels), the witness is OCR because the image is text, and the tokens table says what each provider would have billed.

curl -s -X GET 'https://api.s2ar.dev/v1/certify?image_url=https%3A%2F%2Fs2ar.dev%2Fexamples%2Fmedia%2Finvoice.png&probe=ocr' \
  -H "Authorization: Bearer $S2AR_KEY"

PASS → HTTP 200 · 4420 ms · list price $0.01 · receipt sha256:a81e30b8ab8145c9…

the image sent, media/invoice.png
invoice.png
outcomepass
verdictisomorphic
witnesses.0.nameocr
subject.0.w1000
subject.0.h600
subject.1.w524
subject.1.h314
subject.1.bytes5966
payload.tokens.anthropic{"provider": "anthropic", "before": 800, "after": 220, "saved": 580, "ratio": 0.725}
payload.fidelity{"drift": 0.0, "tolerance": 0.05, "acuity": 1568}
record_sha256924aed0a44f0e675…
the answer, as JSON
{
  "outcome": "pass",
  "verdict": "isomorphic",
  "witnesses.0.name": "ocr",
  "subject.0.w": 1000,
  "subject.0.h": 600,
  "subject.1.w": 524,
  "subject.1.h": 314,
  "subject.1.bytes": 5966,
  "payload.tokens.anthropic": {
    "provider": "anthropic",
    "before": 800,
    "after": 220,
    "saved": 580,
    "ratio": 0.725
  },
  "payload.fidelity": {
    "drift": 0.0,
    "tolerance": 0.05,
    "acuity": 1568
  },
  "record_sha256": "924aed0a44f0e6754350a2cb7e02c8d640dbfd01057843172ea77259aa31df00"
}

Assay badge for record 924aed0a44f0e675

re-derived by the generator
✓receipt sha256:a81e30b8ab8145c9… re-derived: sha256 over the canonical answer, header and body agree
✓record 924aed0a44f0e675… fetched back from /v1/verify: sealed, signed, and signed by assay-1 (the key at /.well-known/assay.json)
✓as the prose says: outcome = "pass" · verdict = "isomorphic"
✓the record names the image by hash: aea08f226ec7ac2a… equals sha256 of media/invoice.png

4. Verify the assertion record, free

No key, no account: the record is fetched back by hash, its seal recomputed, its signature checked against the issuer’s published key.

curl -s -X GET 'https://api.s2ar.dev/v1/verify/3754515b7150255bc42ac96cf7df751f5c37a522f26ced50442abe734673ba9e'

PARTIAL → HTTP 200 · 96 ms

foundtrue
seal_oktrue
signature_oktrue
key_pinnedtrue
certificate.kindassertion
certificate.verdictpartial
the answer, as JSON
{
  "found": true,
  "seal_ok": true,
  "signature_ok": true,
  "key_pinned": true,
  "certificate.kind": "assertion",
  "certificate.verdict": "partial"
}
re-derived by the generator
✓seal recomputed ✓ · signature ✓ · key pinned to assay-1 ✓

5. Change one field; watch the seal fail

The one field a cheat would change.

curl -s -X POST 'https://api.s2ar.dev/v1/verify' \
  -H 'content-type: application/json' --data-binary @record.json   # the record above, with verdict="pass"

PARTIAL → HTTP 200 · 107 ms

seal_okfalse
signature_oknull
the answer, as JSON
{
  "seal_ok": false,
  "signature_ok": null
}
re-derived by the generator
✓one changed field and the seal fails: seal_ok: false, the signature is not even consulted

6. Read the issuer’s signed day

Calls paid, delivered and credited, the rails, the refusals by kind, the charter’s hash, the previous edition’s hash: the issuer’s own account of itself, signed.

curl -s -X GET 'https://api.s2ar.dev/.well-known/proceedings.json'

→ HTTP 200 · 193 ms

period2026-10-11
finalfalse
calls100
calls_paid0
calls_delivered100
credited_not_delivered0
distinct_payers0
charter_sha2565e12a7530c120a82…
record_sha256f1a8a66f4eb43f10…
the answer, as JSON
{
  "period": "2026-10-11",
  "final": false,
  "calls": 100,
  "calls_paid": 0,
  "calls_delivered": 100,
  "credited_not_delivered": 0,
  "distinct_payers": 0,
  "charter_sha256": "5e12a7530c120a823a28ed1e525e9c397328873bc407ca04dd9eb19ced5b5cb8",
  "record_sha256": "f1a8a66f4eb43f107067576d4af862f4676e6210475e753911c424f829131b5e"
}
re-derived by the generator
✓seal re-derived ✓ · signed by assay-1 ✓
✓chain ✓: prior_sha256 equals the 2026-10-10 edition's record_sha256
✓charter ✓: /charter hashes to the charter_sha256 the edition sealed (5e12a7530c12…)

What varies between runs: the latency, the edition of the proceedings, the record hashes. What cannot vary: the verdict (partial: two of three checks passing, so nothing ships), the quotation named as missing, the image named by hash, the seal breaking on one changed field. That is the difference between a tool that answers and a tool that answers with evidence.

What this cannot buy

From the signed proceedings (/.well-known/proceedings.json), verbatim:

Failed calls are never charged. Nothing about a caller is kept. The rules: the charter.