satledger github.com/parthod0x

A usage ledger your customers can check themselves.

Tamper-evident usage ledgers for AI agents — every credit spent and every action taken, signed, replayable, and verifiable by your customers with open-source tools. No "trust our dashboard."

$ curl -s https://api.satledger.org/x402/provision 402 Payment Required · priced, machine-payable, no account
Read the capability document No signup. An agent can discover, pay and integrate without us.
KERNEL: frozen v1 VERIFICATION: offline, open-source ANCHORING: third-party timestamps OVERSPEND: impossible by rule

How it works

01 · Record

One ledger per agent

Provision an agent, grant credits, and stream usage — every grant, burn, and action is an ed25519-signed event in a hash-chained ledger. The kernel rejects overspend; nothing is a database row you could quietly edit.

02 · Export

Hand your customer the proof

One call produces a signed bundle: the full event history, public keys, action log, and manifest hashes. GET /agents/bot-1/export.zip

03 · Verify

They check it without you

Your customer replays the export offline with the open-source satroot package and the Apache-2.0 verifier included in every export. Edits to the signed event history, the action log, or the anchors are rejected.

The trust inversion

Autonomous agents spend real money and take real actions. Today, the record of what they did lives in a provider's database — your customers take it on faith, and so do you.

satledger inverts that. State is computed by replaying signed events under public, frozen rules, and every export ships an Apache-2.0 verifier your customer runs with pip install "satroot[crypto,validation]" — the same code we run, not a reimplementation. What that proves, and what it does not, is written down: see the threat model. We hold the signing keys, so completeness needs an anchor or a head you kept. We would rather say so than imply otherwise.

# your customer, on their machine:
$ pip install "satroot[crypto,validation]"
$ python export/verify_export.py export
✓ 214 records · ed25519 · public-only material
✓ event signatures · state hash · action log · anchor prefixes
✓ 2 timestamp signatures verified · genTime reported
✓ state: sha256:e1a2c685…49fb4e3
NOTE: no TSA certificate pinned; pass --trust-tsa-sha256
NOTE: action-log continuity unchecked; pass --expect-action-head

Five minutes to a verified export

Four HTTP calls. No SDK, no agent runtime to adopt, no change to how your agents work — you post what they did, when they do it.

# 1. create an agent (initial_credits funds the issuer pool)
$ curl -X POST $API/agents -H "$AUTH" -d '{"agent_id":"bot-1","display_name":"Support bot","initial_credits":10000}'

# 2. grant the agent its spendable balance
$ curl -X POST $API/agents/bot-1/grants -H "$AUTH" -d '{"amount":5000}'

# 3. record usage and actions as they happen
$ curl -X POST $API/agents/bot-1/usage -H "$AUTH" -d '{"amount":12}'
$ curl -X POST $API/agents/bot-1/actions -H "$AUTH" -d '{"kind":"refund.issued"}'

# 4. hand the customer a proof they check without you
$ curl -O $API/agents/bot-1/export.zip
export.zip · events · public keys · action log · verify_export.py

Step 3 is the only one that touches your code, and it is a single POST at the point you already log the event. Everything else is setup you do once.

Tiers

Ledger

10,000 units free
then 2,500 units for 0.50, or 100,000 for 20.00 · same price per unit either way · 1 unit = 1 recorded event

  • Credit ledgers + signed action logs
  • Verifiable exports, zip download
  • Multi-tenant API, per-workspace keys
See the live terms

Anchored

100 units per anchor
same balance · ledger + third-party timestamps

  • In development: scheduled commitments broadcast to a public blockchain. Shipping today: scheduled third-party RFC 3161 timestamps.
  • Every anchor pins a ledger prefix; timestamp signatures verified offline
  • Commitment history in every export
See the live terms

Rooted

Contact us
anchored + dedicated namespace root (in development)

  • Your namespace bound to its own on-chain root outpoint
  • The strongest provenance the protocol defines
  • For regulated and high-assurance deployments
Start a conversation

One call, no account

A timestamp receipt for 0.05. Send a SHA-256 hash, get back a Time-Stamp Authority’s signed RFC 3161 token over it. No account, no API key, nothing kept here afterwards — the response is the whole deliverable.

Your data never leaves your side; only its hash is sent. Verify the token against the authority with openssl ts -reply, not against us — and we cannot backdate it, because that would need the authority’s private key.

It proves the data you hashed existed by that time. It says nothing about what was hashed, and it bounds the time from above and never below: anyone can stamp an old document today.

Send digests instead of digest for up to ten in one call and one payment, at the same price each. They are bound to a single timestamp by a Merkle root, and every receipt still verifies on its own.

POST https://api.satledger.org/x402/receipt

Who you are paying, and who holds the keys

We operate the ledger and we hold the signing keys — which means, in principle, we could write an entry your agent never caused. That is why every export ships with an Apache-2.0 verifier you run, and why we anchor to a third-party timestamp we do not control. Neither asks you to trust us: the verifier replays every event offline, and the timestamp proves the ledger existed in that exact state at that moment. What we cannot do is quietly change history you have already exported or anchored.

What we don't claim

No tokens, no coins, no yields. Anchoring commits a hash of your ledger to a public chain; it does not put your data on-chain, and it creates no financial instrument.

The protocol layer is open (Apache-2.0) and stays open — satledger sells the hosted, anchored, multi-tenant operation of it, not access to the standard.

You never pay to leave. Exports and every read are free, permanently and at any balance — including when you have run out of units. Charging for the export would price the exit, and the exit is the whole point.