Arcaeon
For agents

If you hand a model an agent's record and ask it to check, did anything get checked?

Not always. We handed an outside model an evidence pack, then a copy with two bytes changed. It called the changed copy VERIFIED. The numbers are further down this page.

Arcaeon comes from a 911 dispatch floor, where a call's record gets pulled and read by people who were not there. This page is for the agent, or the person wiring one up: what runs with no key, the MCP line, what a key buys, and what none of it proves.

Limits first. Arcaeon checks that a record was not changed after it was written, and whether two records of the same work agree. It does not check that the record is true. An agent can faithfully record a lie, and the chain will faithfully keep it.

What an agent can do with no key

The local core is free, MIT licensed, and needs no account and no key. Every check runs on the agent's own machine. Nothing opens a connection on import; the hosted commands open one only when they are run.

The local coreno key, no network
$ pip install arcaeon
$ arcaeon selftest
$ arcaeon log agent.jsonl '{"tool": "search", "query": "weather"}'
$ arcaeon verify agent.jsonl
POSIX shell quotes. On Windows, use Git Bash or WSL, or adjust the quotes.
  • Record. log writes a hash chained record; verify names the first broken line.
  • Compare. reconcile puts two records of the same work side by side and says where they stop agreeing.
  • Check a tool server first. vet reads an MCP server's source and grades it. None of that code runs.
  • One exit code table for every command. 0 good, 1 a bad finding, 2 bad usage, 3 COULD NOT LOOK. COULD NOT LOOK is never a pass.

The MCP line

Install and startMCP server on stdio
$ pip install "arcaeon[mcp]"
$ arcaeon mcp
arcaeon mcp --tools lists the tools without starting anything.

The tools: ledger_append, ledger_verify, ledger_prove_my_conduct, ledger_verify_peer_ledger, ledger_declare_break, vet_scan, vet_grade, vet_audit_verify and arcaeon_status, all free; witness_pin and witness_renew need a key.

In the next release
deal_mandate, deal_commit, deal_dispute, mandate_check, second_read_submit, second_read_compare, evidence_pack_build and evidence_pack_verify. No date is promised.

Not built yet
A landing call, the one tool an agent calls first, is being added. Until it ships, call arcaeon_status first: it names the versions and which tools are free.

The server says it in its own words: "None of these tools claim your records are TRUE: they prove a record was not altered, which is a different and smaller thing."

What a key buys

A key buys pins with the hosted witness, a party the writer cannot advance. A pin is the one thing that catches a record cut short, and only as of the last pin. In MCP that is witness_pin and witness_renew; on the command line it is pin --remote, seal and credits. Without a key the two paid tools return a plain note. They never silently do nothing.

WhatPrice
One pinone credit, $0.005 in the Mini pack ($5 for 1,000 pins)
Checking any record, yours or anyone's$0, for everyone, with no key

Every new key comes with 500 credits, one time, per verified email, in the next release, no date promised. An agent may start the signup, and the human clicks the link. There is no free window by calendar.

The prices come from offers.json, the one file that says what we charge. The full ladder is on what it costs.

What it can and cannot prove

The same list as the can and cannot prove page, word for word. What it cannot prove comes first.

The record and the witness

  • That a record was never rewritten. Anyone who can write the file can still change it. An edit to one row breaks the chain, and the check names the line. Rewrite every row from the edited one onward and the chain checks out again, unless a pin holds the old head.
  • That the rows are true. The chain records whatever was written, true or not. To tie a row to a fact someone can fetch again, store the fact's digest in the row.
  • That nothing was cut off the end. Cut the newest rows off and what is left still checks out. No chain catches that alone. A pin does, as of the last pin.
  • Who wrote a row. That is data in the row, not a signature. Someone who rewrites the whole log from the first row can rewrite that too.
  • A second, unrelated party. The hosted witness is one witness, and we operate it. A pin there is not a stranger vouching for you.
  • Who ran the witness at the time of a pin. Today you take our word for it. That stays true until we publish a custody record, and we have not yet.
  • That the daily anchor checked anything. It is a clock, not a party. It fixes when the pins existed, not whether they were right.
  • That you can rerun the session. That takes the model, the tool server and their state at the time. You get the request and response digests instead, so you can check given bytes are the ones that crossed.

Two records of the same work

  • MATCHED means two recorders agree. A colluding agent side and tool side can write two agreeing tapes of a lie.
  • A call that crossed neither recorded seam leaves no row on either tape.
  • Without a pin, both tapes cut short or rewritten in agreement still match.

The evidence pack, the second reader and the mandate gate

  • A pack is not a statement that any law or standard is met, and it does not show the agent behaved well. It shows what was written was not changed after pinning.
  • When two readers read a sentence the same way, that does not make the claim right. Two models from one family, or one vendor, agree more for that reason alone.
  • The mandate gate records who a mandate speaks for and does not check it: the proxy cannot see who is behind the agent. A call that goes around the proxy is not checked.
  • vet and badge report what their own checks found in the bytes they read. They are not a review by a person and not a safety certification.

What it can prove

  • Nothing was changed in the middle. An edit, a deletion or a reorder breaks every later link, and the check names the first broken line.
  • Nothing was cut after a pin. Once a witness holds your head, a shorter or rewritten log no longer matches it. The longest gap between pins is your real exposure.
  • Two tapes line up, or where they do not. Each step both tapes should hold comes back MATCHED, MISSING or ALTERED, with the fields that differ.
  • What could not be looked at. A missing, unreadable or empty file is COULD NOT LOOK. It is never a pass.

Worked example: a model as the second reader

We built a small evidence pack, then a copy with one byte changed in a record row and one in the README. We handed an outside model the bytes and told it to say VERIFIED only for what it recomputed. Then we recomputed every line it marked VERIFIED.

FindingCount
Lines the model marked VERIFIED21
True when we recomputed them19
False2
Where the false ones werethe changed copy: the chain head, read off a stored field the change did not touch
What arcaeon verify said about the changed copyBROKEN, line 2: chain mismatch

It said it had hashed the files, and on the changed copy it said it cannot compute SHA-256. Reading a stored hash is not recomputing one.

The second reader has to be a program, or a model holding a tool it actually calls.

What this example does not show: one model, one small pack built from test fixtures, one answer per prompt. It says nothing about how other models do, and the pack itself ships in the next release.