Diff two screenshots

Diff the golden frame against today’s without asking a model at a thousand tokens a look. diff answers with three deterministic witnesses and no model at all: a 9×8 luma difference hash for structure, an 8×8 RGB signature for colour, and the change in gradient energy for texture, each against a threshold. It seals the three distances as a signed Assay record that carries both images by hash, never by pixels. The frames here are a StarLab render of a sphere and the same render with its red and blue channels swapped: the palette regression a luma hash is blind to.

3calls answered
2receipts re-hashed
3records verified
$0.01list price for a stranger
1,532ms end to end
pass then fail · 3 records verified

Run 2026-10-11 05:26 UTC against api.s2ar.dev 0.1.1 · 3 calls · 1,532 ms · list price $0.01 for a stranger (these ran on the operator's key and cost nothing) · every number on this page re-derived by tools/walkthrough.py before it was written

1. The golden frame against itself

Identical bytes: every distance is exactly 0.0 and the verdict is same. The record’s subject names both images by sha256, width, height and byte count.

curl -s -X GET 'https://api.s2ar.dev/v1/diff?a=https%3A%2F%2Fs2ar.dev%2Fexamples%2Fmedia%2Fscene.png&b=https%3A%2F%2Fs2ar.dev%2Fexamples%2Fmedia%2Fscene.png' \
  -H "Authorization: Bearer $S2AR_KEY"

PASS → HTTP 200 · 699 ms · list price $0.005 · receipt sha256:b9ba56c3ad2038fc…

the image sent, media/scene.png
scene.png
verdictsame
outcomepass
passed3
checks3
distances{"dhash": 0.0, "color_sig": 0.0, "grad": 0.0}
a.sha25654dca830c9c24ab3…
a.w729
a.h381
b.sha25654dca830c9c24ab3…
record_sha256cd69a8df62c7dad2…
x-assay-recordcd69a8df62c7dad2…
x-assay-verify/v1/verify/cd69a8df62c7dad2e2a999f123047dc471e3a5ce9ceb375981e1edc574320af0
the answer, as JSON
{
  "verdict": "same",
  "outcome": "pass",
  "passed": 3,
  "checks": 3,
  "distances": {
    "dhash": 0.0,
    "color_sig": 0.0,
    "grad": 0.0
  },
  "a.sha256": "54dca830c9c24ab36bd271b096564930d82b3a2266ae37162ec595127a89604a",
  "a.w": 729,
  "a.h": 381,
  "b.sha256": "54dca830c9c24ab36bd271b096564930d82b3a2266ae37162ec595127a89604a",
  "record_sha256": "cd69a8df62c7dad2e2a999f123047dc471e3a5ce9ceb375981e1edc574320af0",
  "x-assay-record": "cd69a8df62c7dad2e2a999f123047dc471e3a5ce9ceb375981e1edc574320af0",
  "x-assay-verify": "/v1/verify/cd69a8df62c7dad2e2a999f123047dc471e3a5ce9ceb375981e1edc574320af0"
}

Assay badge for record cd69a8df62c7dad2

re-derived by the generator
✓receipt sha256:b9ba56c3ad2038fc… re-derived: sha256 over the canonical answer, header and body agree
✓record cd69a8df62c7dad2… fetched back from /v1/verify: sealed, signed, and signed by assay-1 (the key at /.well-known/assay.json)
✓as the prose says: verdict = "same" · outcome = "pass" · passed = 3 · checks = 3 · distances.dhash = 0.0 · distances.color_sig = 0.0 · distances.grad = 0.0
✓the record names the image by hash: 54dca830c9c24ab3… equals sha256 of media/scene.png

2. The same frame with red and blue swapped

The luma structure is nearly unchanged, so dhash passes; the colour signature moves far past its threshold and names the regression. grad sees the same texture.

curl -s -X GET 'https://api.s2ar.dev/v1/diff?a=https%3A%2F%2Fs2ar.dev%2Fexamples%2Fmedia%2Fscene.png&b=https%3A%2F%2Fs2ar.dev%2Fexamples%2Fmedia%2Fscene-rb.png' \
  -H "Authorization: Bearer $S2AR_KEY"

FAIL → HTTP 200 · 730 ms · list price $0.005 · receipt sha256:0345d7480fcc73a4…

the image sent, media/scene.png
scene.png
the image sent, media/scene-rb.png
scene-rb.png
verdictregression
outcomefail
passed2
checks3
regressed["color_sig"]
distances{"dhash": 0.0625, "color_sig": 0.060417, "grad": 0.041722}
results.0.oktrue
results.1.okfalse
results.1.distance0.060417
results.1.threshold0.02
results.2.oktrue
record_sha256f9e3d02ec9667b9d…
the answer, as JSON
{
  "verdict": "regression",
  "outcome": "fail",
  "passed": 2,
  "checks": 3,
  "regressed": [
    "color_sig"
  ],
  "distances": {
    "dhash": 0.0625,
    "color_sig": 0.060417,
    "grad": 0.041722
  },
  "results.0.ok": true,
  "results.1.ok": false,
  "results.1.distance": 0.060417,
  "results.1.threshold": 0.02,
  "results.2.ok": true,
  "record_sha256": "f9e3d02ec9667b9df56f25870879df7c61ad717b95c9621f1a47fb4d1b051e74"
}

Assay badge for record f9e3d02ec9667b9d

re-derived by the generator
✓receipt sha256:0345d7480fcc73a4… re-derived: sha256 over the canonical answer, header and body agree
✓record f9e3d02ec9667b9d… fetched back from /v1/verify: sealed, signed, and signed by assay-1 (the key at /.well-known/assay.json)
✓as the prose says: verdict = "regression" · outcome = "fail" · passed = 2 · checks = 3 · regressed.0 = "color_sig" · results.0.ok = true · results.1.ok = false · results.2.ok = true
✓the record names the image by hash: 54dca830c9c24ab3… equals sha256 of media/scene.png
✓the record names the image by hash: a15b4d6696a03593… equals sha256 of media/scene-rb.png

3. Anyone verifies the regression record, free

No key, no account: the record is fetched back by hash, its seal recomputed, its signature checked against the issuer’s published key.

curl -s -X GET 'https://api.s2ar.dev/v1/verify/f9e3d02ec9667b9df56f25870879df7c61ad717b95c9621f1a47fb4d1b051e74'

FAIL → HTTP 200 · 104 ms

foundtrue
seal_oktrue
signature_oktrue
key_pinnedtrue
certificate.kindimage-diff
certificate.verdictregression
certificate.replayabletrue
certificate.payload.regressed["color_sig"]
certificate.harness.thresholds{"color_sig": 0.02, "dhash": 0.1, "grad": 0.25}
the answer, as JSON
{
  "found": true,
  "seal_ok": true,
  "signature_ok": true,
  "key_pinned": true,
  "certificate.kind": "image-diff",
  "certificate.verdict": "regression",
  "certificate.replayable": true,
  "certificate.payload.regressed": [
    "color_sig"
  ],
  "certificate.harness.thresholds": {
    "color_sig": 0.02,
    "dhash": 0.1,
    "grad": 0.25
  }
}
re-derived by the generator
✓seal recomputed ✓ · signature ✓ · key pinned to assay-1 ✓

The hashes travel, the pixels do not. Anyone holding the two files can re-measure the three distances and compare them with the record; anyone at all can verify the seal and the signature free at /v1/verify/<record_sha256>. For a run of frames, an agent diffs each against its golden and reads only the verdict line, pulling a contact sheet only when a verdict flags a regression worth a look.

What this cannot buy

From the signed proceedings (/.well-known/proceedings.json), verbatim:

Failed calls are never charged. Nothing about a caller is kept. The rules: the charter.