Certify a screenshot
Send fewer image tokens without the model reading the screenshot differently. certify compresses the image to the
smallest version the target reads the same way, measures the drift with a deterministic witness (OCR here, since the image
is text), and seals the result as an Assay record signed by the issuer’s key. The image is a synthetic invoice from our own
test corpus.
Run 2026-10-11 05:26 UTC against api.s2ar.dev 0.1.1 · 2 calls · 4,922 ms · list price $0.02 for a stranger (these ran on the operator's key and cost nothing) · every number on this page re-derived by tools/walkthrough.py before it was written
1. One file in, a signed record out
curl -s -X POST 'https://api.s2ar.dev/v1/certify?probe=ocr' \
-H "Authorization: Bearer $S2AR_KEY" \
-F 'original=@invoice.png'
PASS
| kind | compression |
|---|---|
| issuer | assay |
| verdict | isomorphic |
| outcome | pass |
| replayable | true |
| payload.tokens.anthropic | {"provider": "anthropic", "before": 800, "after": 86, "saved": 714, "ratio": 0.8925} |
| payload.fidelity.drift | 0.0599 |
| payload.fidelity.tolerance | 0.06 |
| record_sha256 | f164152c1dd55564… |
| x-assay-record | f164152c1dd55564… |
| x-assay-verify | /v1/verify/f164152c1dd555641a29b7fb2a297fc54c3d805114b426c3f3ea40983fd7bc1a |
the answer, as JSON
{
"kind": "compression",
"issuer": "assay",
"verdict": "isomorphic",
"outcome": "pass",
"replayable": true,
"payload.tokens.anthropic": {
"provider": "anthropic",
"before": 800,
"after": 86,
"saved": 714,
"ratio": 0.8925
},
"payload.fidelity.drift": 0.0599,
"payload.fidelity.tolerance": 0.06,
"record_sha256": "f164152c1dd555641a29b7fb2a297fc54c3d805114b426c3f3ea40983fd7bc1a",
"x-assay-record": "f164152c1dd555641a29b7fb2a297fc54c3d805114b426c3f3ea40983fd7bc1a",
"x-assay-verify": "/v1/verify/f164152c1dd555641a29b7fb2a297fc54c3d805114b426c3f3ea40983fd7bc1a"
}
| re-derived by the generator | |
|---|---|
| ✓ | receipt sha256:4c3501f64c91f86e… re-derived: sha256 over the canonical answer, header and body agree |
| ✓ | record f164152c1dd55564… fetched back from /v1/verify: sealed, signed, and signed by assay-1 (the key at /.well-known/assay.json) |
2. The same image by URL, as a GET
A wallet that can only sign a URL sends image_url; the record names the image by hash, so the page shows the input beside it — the API returns the record, never pixels.
curl -s -X GET 'https://api.s2ar.dev/v1/certify?image_url=https%3A%2F%2Fs2ar.dev%2Fexamples%2Fmedia%2Finvoice.png&probe=ocr' \
-H "Authorization: Bearer $S2AR_KEY"
PASS
| outcome | pass |
|---|---|
| verdict | isomorphic |
| witnesses.0.name | ocr |
| subject.0.w | 1000 |
| subject.0.h | 600 |
| subject.1.w | 524 |
| subject.1.h | 314 |
| subject.1.bytes | 5966 |
| payload.tokens.anthropic | {"provider": "anthropic", "before": 800, "after": 220, "saved": 580, "ratio": 0.725} |
| payload.fidelity | {"drift": 0.0, "tolerance": 0.05, "acuity": 1568} |
| record_sha256 | 924aed0a44f0e675… |
the answer, as JSON
{
"outcome": "pass",
"verdict": "isomorphic",
"witnesses.0.name": "ocr",
"subject.0.w": 1000,
"subject.0.h": 600,
"subject.1.w": 524,
"subject.1.h": 314,
"subject.1.bytes": 5966,
"payload.tokens.anthropic": {
"provider": "anthropic",
"before": 800,
"after": 220,
"saved": 580,
"ratio": 0.725
},
"payload.fidelity": {
"drift": 0.0,
"tolerance": 0.05,
"acuity": 1568
},
"record_sha256": "924aed0a44f0e6754350a2cb7e02c8d640dbfd01057843172ea77259aa31df00"
}
| re-derived by the generator | |
|---|---|
| ✓ | receipt sha256:a81e30b8ab8145c9… re-derived: sha256 over the canonical answer, header and body agree |
| ✓ | record 924aed0a44f0e675… fetched back from /v1/verify: sealed, signed, and signed by assay-1 (the key at /.well-known/assay.json) |
| ✓ | as the prose says: outcome = "pass" · verdict = "isomorphic" |
| ✓ | the record names the image by hash: aea08f226ec7ac2a… equals sha256 of media/invoice.png |
The record keeps hashes and dimensions, never pixels: anyone holding the two images can re-measure, and anyone
at all can check the seal and the signature, free, at /v1/verify/<record_sha256>.
What this cannot buy
From the signed proceedings (/.well-known/proceedings.json), verbatim:
- placement or routing position
- a different verdict or grade
- buyer data
- amendment access
- a revocation
Failed calls are never charged. Nothing about a caller is kept. The rules: the charter.