- ✓Open-source license (MIT)
- ✓Actively maintained (<30d)
- ✓Documented (README)
- !No description
git clone https://github.com/mglbagi/agent-output-verifierTools overview
# Agent Output Verifier
Independently verify an agent's output before you pay.
Independent, deterministic checks of structure, formats, ranges and cross-field rules, such as
"line totals must equal the total," against your own requirements, written in standard JSON Schema
plus optional rules. Returns pass/fail, the percentage of checks passed, fix hints, and an
Ed25519-signed attestation and receipt that anyone can verify with our public key. Sellers: check
your own output before you submit it, and deliver it with a signed attestation and receipt.
No signup: pay per call with x402 v2, in USDC on Base or Solana. 3 free calls a day through MCP.
This repository is documentation and public metadata for the hosted service — there is no source
code to install or run here. The service itself is a live API at
`https://fastapi-service-5ag4.onrender.com`.
## Endpoints
| Purpose | Endpoint |
|---|---|
| MCP (Streamable HTTP) | `https://fastapi-service-5ag4.onrender.com/mcp` |
| Verify an output (REST) | `POST https://fastapi-service-5ag4.onrender.com/verify/schema` |
| Look up an agent's trust score (REST) | `GET https://fastapi-service-5ag4.onrender.com/score/{agent_id}` |
| Agent card (discovery) | `GET https://fastapi-service-5ag4.onrender.com/.well-known/agent-card.json` |
| x402 discovery manifest | `GET https://fastapi-service-5ag4.onrender.com/.well-known/x402` |
| llms.txt | `GET https://fastapi-service-5ag4.onrender.com/llms.txt` |
| Interactive API docs | `GET https://fastapi-service-5ag4.onrender.com/docs` |
Two MCP tools are exposed over the same endpoint: `verify_schema` (`POST /verify/schema`) and
`get_verification_record` (`GET /score/{agent_id}`).
## Pricing and networks
Paid per call with [x402](https://github.com/coinbase/x402) v2, in USDC, on either network below —
no account or signup required:
| Route | Price | Networks |
|---|---|---|
| `POST /verify/schema` | $0.02 USDC | Base (`eip155:8453`), Solana (`solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp`) |
| `GET /score/{agent_id}` | $0.01 USDC | Base (`eip155:8453`), Solana (`solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp`) |
`/.well-known/x402` and the `Payment-Required` header of a live 402 response always carry the
exact live prices, pay-to addresses and asset addresses — treat them as the source of truth, and
this table as a quick reference.
## Free trial
Each MCP tool carries its own free-trial allowance: **3 free calls per day**, available over MCP.
After that, a call requires an x402 payment carried in the MCP request's `_meta` under
`x402/payment`, or a standard x402 payment header on REST.
## Verifying a receipt, step by step
Every response from `/verify/schema` and `/score/{agent_id}` carries a signed `verify` section and
an `attestation` block, for example:
```json
"verify": {
"public_key_url": "https://fastapi-service-5ag4.onrender.com/.well-known/agent-card.json",
"key_version": "v1-2026-09c",
"canonicalization": "RFC 8785 (JCS)",
"hash_algorithm": "SHA-256",
"service": "Agent Output Verifier",
"mcp": "https://fastapi-service-5ag4.onrender.com/mcp"
},
"attestation": {
"algorithm": "Ed25519",
"key_version": "v1-2026-09c",
"timestamp": "2026-10-01T01:01:09.606993+00:00",
"signature": "8UexIObSAwQxjj8/rbEpLRgbYY6XO+wg5+b0D8I3BRfbOxl+ouwcKNPE/hp+9p37Tm2wwdmCqPjBgOMLGQtGAQ=="
}
```
Nothing but the response itself and `verify.public_key_url` is needed:
1. **Fetch the public key.** `GET` the agent-card at `verify.public_key_url`. Its
`capabilities.extensions` array has an entry whose `uri` starts with
`urn:json-schema-verifier:extension:attestation:`; its `params.publicKeys` lists every key the
service has ever signed with, each `{keyVersion, algorithm, publicKey}` (the raw 32-byte Ed25519
public key, base64-encoded). Pick the entry whose `keyVersion` equals
`response.attestation.key_version`.
2. **Rebuild the signed document.** It's a JSON object with exactly these five keys:
```json
{
"context": "json-schema-verifier/verify-schema-attestation/v1",
"algorithm": "Ed25519",
"key_version": "<attestation.key_version>",
"attested_at": "<attestation.timestamp>",
"response": { "...": "the full response, with the attestation field removed" }
}
```
`context` is `json-schema-verifier/verify-schema-attestation/v1` for `/verify/schema` responses,
or `json-schema-verifier/trust-score-attestation/v1` for `/score/{agent_id}` responses.
3. **Canonicalize it with RFC 8785 (JCS):** UTF-8 bytes of the JSON document above, object keys
sorted recursively, no insignificant whitespace, numbers printed the way ECMAScript prints them
(`1.0` becomes `1`).
4. **Verify the Ed25519 signature** (`response.attestation.signature`, base64-decoded) over those
canonical bytes, using the public key from step 1.
5. **Check the four receipt hashes**, each SHA-256 over the RFC 8785 (JCS) canonical JSON of the
named value: `output_hash` (of `submitted_output`), `schema_hash` (of `expected_schema`),
`rules_hash` (of `{"bounds": ..., "rules": ...}`), and `request_hash` (of the whole request as
parsed, full detail only). Recompute them yourself and compare — this is what binds the receipt
to the exact data that was checked.
A minimal Python verifier, using only the standard library plus `cryptography`:
```python
import base64, json
from decimal import Decimal
from cryptography.hazmat.primitives.asymmetric.ed25519 import Ed25519PublicKey
def es_number(x: float) -> str:
"""A float exactly as ECMAScript / RFC 8785 (JCS) print it (1.0 -> "1", 1e-7 -> "1e-7")."""
if x == 0:
return "0"
sign = "-" if x < 0 else ""
digits_tuple = Decimal(repr(abs(x))).as_tuple()
digits = "".join(map(str, digits_tuple.digits)).rstrip("0") or "0"
n = len(digits_tuple.digits) + digits_tuple.exponent # position of the decimal point
k = len(digits)
if k <= n <= 21:
body = digits + "0" * (n - k)
elif 0 < n <= 21:
body = digits[:n] + "." + digits[n:]
elif -6 < n <= 0:
body = "0." + "0" * (-n) + digits
else:
e = n - 1
body = digits[0] + ("." + digits[1:] if k > 1 else "") + f"e{'+' if e >= 0 else '-'}{abs(e)}"
return sign + body
def canonical(v) -> str:
if isinstance(v, bool):
return "true" if v else "false"
if isinstance(v, float):
return es_number(v)
if isinstance(v, dict):
return "{" + ",".join(f"{canonical(k)}:{canonical(v[k])}" for k in sorted(v)) + "}"
if isinstance(v, list):
return "[" + ",".join(canonical(x) for x in v) + "]"
return json.dumps(v, ensure_ascii=False) # covers None, int, str
def verify(response: dict, public_key_b64: str, context: str) -> bool:
att = response["attestation"]
body = {k: v for k, v in response.items() if k != "attestation"}
message = canonical({
"context": context,
"algorithm": att["algorithm"],
"key_version": att["key_version"],
"attested_at": att["timestamp"],
"response": body,
}).encode("utf-8")
key = Ed25519PublicKey.from_public_bytes(base64.b64decode(public_key_b64))
try:
key.verify(base64.b64decode(att["signature"]), message)
return True
except Exception:
return False
```
Tested against both receipts in the worked example below — both verify `True`.
## Worked example: invoice verification
Both calls below are **genuine, live, paid** calls against the production service — real x402
payments on Base, settled on-chain, with the resulting signed receipts shown exactly as received.
Both are independently verifiable: fetch the agent-card above, confirm `key_version: v1-2026-09c`
is listed, and verify each `attestation.signature` with the steps above.
### 1. Draft invoice — fails on a cross-field rule (`detail: "full"`)
Request:
```json
{
"task_id": "invoice-7731-draft",
"agent_id": "test-seller-invoice-agent",
"expected_schema": {
"type": "object",
"required": ["invoice_id", "currency", "line_items", "total"],
"properties": {
"invoice_id": { "type": "string", "pattern": "^INV-[0-9]{4}$" },
"currency": { "enum": ["USD", "EUR"] },
"line_items": {
"type": "array",
"minItems": 1,
"items": {
"type": "object",
"required": ["sku", "qty", "line_total"],
"properties": {
"sku": { "type": "string" },
"qty": { "type": "integer", "minimum": 1 },
"line_total": { "type": "number", "minimum": 0 }
}
}
},
"total": { "type": "number" }
}
},
"submitted_output": {
"invoice_id": "INV-7731",
"currency": "USD",
"line_items": [
{ "sku": "CRWL-100", "qty": 3, "line_total": 87.0 },
{ "sku": "CRWL-200", "qty": 1, "line_total": 42.5 }
],
"total": 135.0
},
"rules": [
{ "type": "sum_equals", "field": "line_items[].line_total", "equals_field": "total" }
],
"enforce_rules": true,
"detail": "full"
}
```
The line items sum to 129.5, but `total` says 135.0. With `enforce_rules: true`, that rule
violation fails the result and comes with a fix hint:
```json
{
"summary": {
"result": "fail",
"blocking_checks": ["consistency:sum_equals"]
},
"next_actions": [
{ "action": "repair_and_reverify", "using": "hints" }
],
"result": "fail",
"verification_id": "28afb453-7c39-4993-a9c4-fcade1b7924f",
"task_id": "invoice-7731-draft",
"agent_id": "test-seller-invoice-agent",
"output_hash": "d4fb804e434eb3ee047068cbb3691ea1e07066928e7e3efc73b94317e53ee305",
"schema_hash": "23ea3213715cfaf2011dabe2a9a69d4ac25b6eceec7ce3d4bfef9a1298b69b2a",
"rules_hash": "2acb6de92b88cfbca279ea6d5bd74b7a1e7dec0839dd093dbe041e25df3364d2",
"request_hash": "e4bf9733726b24a19ec546ecc79015c9b1cb7a6829b409b41ef56b1c8f60b881",
"verified_at": "2026-10-01T01:01:09.606993+00:00",
"verifier_version": "0.4.1",
"enforce_rules": true,
"strict_content_check": false,
"What people ask about agent-output-verifier
What is mglbagi/agent-output-verifier?
+
mglbagi/agent-output-verifier is tools for the Claude AI ecosystem with 0 GitHub stars.
How do I install agent-output-verifier?
+
You can install agent-output-verifier by cloning the repository (https://github.com/mglbagi/agent-output-verifier) or following the README instructions on GitHub. ClaudeWave also provides quick install blocks on this page.
Is mglbagi/agent-output-verifier safe to use?
+
Our security agent has analyzed mglbagi/agent-output-verifier and assigned a Trust Score of 77/100 (tier: Trusted). See the full breakdown of passed checks and flags on this page.
Who maintains mglbagi/agent-output-verifier?
+
mglbagi/agent-output-verifier is maintained by mglbagi. The last recorded GitHub activity is dated 2026-10-01, with 0 open issues.
Are there alternatives to agent-output-verifier?
+
Yes. On ClaudeWave you can browse similar tools at /categories/tools, sorted by popularity or recent activity.
Deploy agent-output-verifier to your cloud
Ship this repo to production in minutes. Each platform spins up its own environment with editable env vars.
Maintain this repo? Add a badge to your README
Drop the badge into your GitHub README to show it's tracked on ClaudeWave. Each badge links back to this page and reflects the live Trust Score.
[](https://claudewave.com/repo/mglbagi-agent-output-verifier)<a href="https://claudewave.com/repo/mglbagi-agent-output-verifier"><img src="https://claudewave.com/api/badge/mglbagi-agent-output-verifier" alt="Featured on ClaudeWave: mglbagi/agent-output-verifier" width="320" height="64" /></a>More Tools
A single CLAUDE.md file to improve Claude Code behavior, derived from Andrej Karpathy's observations on LLM coding pitfalls.
An AI skill that provides design intelligence for building professional UI/UX across multiple platforms.
🪨 why use many token when few token do trick. Viral skill + proxy for coding agents that cuts 65% of tokens by talking like a caveman.
CLI proxy that reduces LLM token consumption by 60-90% on common dev commands. Single Rust binary, zero dependencies
The fastest, litest AI Gateway. Rust core with Python SDK. Call 100+ LLM APIs in OpenAI (or native) format with cost tracking, guardrails, load balancing, and logging [Bedrock, Azure, OpenAI, Anthropic, OpenAI, VertexAI, vLLM, Nvidia NIM]
Use Claude Code, Codex, VSCode, Pi, and OpenCode (and 6 other harnesses) for free (1.3B+ free tokens) from your terminal, app, IDE, or phone, and now from the browser with native browser sessions (multi-harness + multi-model) like OpenClaw (voice supported + ToS friendly)