VERIFIABLE RECORDS FOR AGENTS, APIS, AND GATEWAYS

Agent actions, on the record.

Originary creates portable signed records for agent actions, API calls, MCP tool runs, gateway decisions, payments, approvals and provisioning. Your team, customers, partners and auditors can verify those records without access to the source system's private logs.

  • Payments
  • Approvals
  • Access decisions
  • API calls
  • Tool runs
  • Changes
  • Deletions
  • Handoffs
  • Built on PEAC Protocol
  • Open source
  • Offline verification
  • Self-hostable

Originary records selected facts from a local system action, signs the record, and lets anyone verify it outside the system that created it. Verification supports audit, compliance review, dispute evidence, and partner handoff.

  1. API call
  2. MCP tool run
  3. Agent action
  4. Gateway decision
  5. Payment event
  6. Provisioning event
  1. Developer verifiesdebugging, incident review
  2. Counterparty verifiesdispute, delivery, trust
  3. Auditor reviewscompliance, assurance
  4. Bundle exportsportable evidence pack

Logs stay local. Signed records travel.

Works across the agent and API stack

Interoperates across commerce, identity, and evidence

Ed25519 · JCS · Compact JWS · HTTP Message Signatures · Offline verification

the failure

Each side has logs. Neither side has evidence the other can independently verify.

A customer disputes a paid tool call. The provider has a gateway log. The customer has a charge reference. The tool server has a result. Those records live in different systems, under different operators, and may not establish the same facts.

Company A
Company B
company boundary
local logs
operator log
14:08:11 POST /v1/search 200
telemetry
span 7bc2 latency=412ms
dashboard
metric usage.api +1
trace
parent.span = a4f1d
logs stop here
Logs help operators debug. Records give counterparties something they can verify.

The problem is not the absence of data. It is the absence of a bounded, transferable evidence set.

the evidence case

One evidence case, with its gaps stated.

Verification separates what the supplied records establish from what is missing, conflicting, or not evaluated. A complete happy path would misrepresent what real evidence looks like.

Evidence casedisputed MCP tool call

3 of 6 elements verified under the supplied key. One is linked, one is bounded, one was never supplied.

Authorization referenceclient
present
Gateway decisiongateway
signature verified
MCP/API invocationtool server
signature verified
Payment-provider artifactpayment provider
linked
Delivery observationnot supplied
missing
Verification reportverifier
complete with limitations
establishedlinked artifactboundednot supplied
the product

One evidence case, assembled from the systems that already observed the action.

Originary connects selected signed records and native artifacts, verifies them under an explicit key policy, and hands the bounded result to another party.

start here

Start with one consequential workflow.

The same record path supports customer reviews, incidents, audits and disputes. Agent actions, payment events, and provisioning use the same record format. More workflows.

record gallery

See what each issuing system actually reported.

Every record is a bounded signed statement from one issuer. Each record family links to a worked example. Shipped PEAC samples can be generated and verified offline.

the boundary

A valid record can still be insufficient evidence.

Verification can establish
  • the supplied key validates the signature;
  • the protected record bytes were not changed;
  • disclosed content matches the digests bound by the record;
  • the record contains the issuer-reported claims shown.
Verification does not automatically establish
  • that every relevant event was recorded;
  • that the issuer's observation was complete or truthful;
  • that the supplied key was authorized by the claimed issuer;
  • that delivery occurred;
  • that a legal or regulatory requirement was satisfied.
open foundation
open-source protocol

Built on an open record format, not a proprietary evidence database.

PEAC Protocol is an Apache-2.0 open protocol for portable signed interaction records. Teams can issue, verify, implement, and self-host PEAC independently of Originary.

  • Portable signed records
  • Offline verification
  • Self-managed keys
  • Independent implementations
  • Conformance vectors
  • No Originary callback required
  • v0.16.3 current release
  • 12,729 tests
  • 290 conformance checks
  • 36 packages on npm
  • Apache-2.0 licensed
start with one action
Get started

Start with one action another party needs to verify.

Bring one paid tool call, API request, gateway decision, or incident workflow. We’ll determine what can be recorded, which claims are supportable, and what evidence a separate recipient would actually need.

  • Paid tool call
  • API request
  • Gateway decision
  • Incident workflow
Tell us the workflow that needs verification.

Sent to the team and routed by topic; falls back to an email draft to contact@originary.xyz if submission is unavailable. Business contact details only; never paste records, JWS strings, or keys. We use what you send only to route your message and reply, and retain it no longer than needed for that. See our privacy policy.