TreeshipWritingBlogDocsGitHub

Writing

Blog

Releases, integrations, guides and engineering notes: what Treeship signs, for which systems, and how to check it.

Latest

Any judge, one receipt

Fast decision models now sit between agents and actions, and none of them leaves a record a stranger can check. Treeship 0.31.6 to 0.31.9 added the judge slot: a contract any judge can speak, a deterministic judge we own, a signed receipt for every answer, and TypeSafe's Jev as the first outside judge behind it.

integrationTypeSafe JevTreeship CLIClaude Code pluginZerker Reason7 min read

Ten steps, one receipt

TypeSafe's founder published a ten-step blueprint for building a control system around an LLM with Jev as the decision layer. Step ten is the decision receipt. Here is what Treeship signs at each of the ten, and the two fields we were missing until this week.

Signed is not true

The sharpest attack on a receipt is that a signature proves nothing about the world. It is correct. Here is exactly what a Treeship receipt proves, what it does not, and the three mechanisms that turn a signed report into something you can grade.

Accountability has to spread

The risk from autonomous agents does not sit inside the frontier labs. Agents and their subagents already run on many machines across many organizations, so accountability cannot be something the frontier labs bolt on for us. It has to be local-first and portable, installed where the agent runs, and checkable by strangers.

Treeship 0.31.2: sealed packages now verify their signatures

package verify checked the Merkle tree and nothing under it. It now verifies every artifact's Ed25519 envelope, session close seals unchained work, and the MCP bridge reports failures.

Treeship 0.31: Verifiable Intent credentials, shipped

treeship vi implements the Verifiable Intent v0.1 draft, signs the Layer 3 pair with a Treeship receipt-chain attestation inside, and interoperates with the reference SDK both ways in CI.

The operator's yes, signed once

In Anthropic's commerce-agents reference, a merchant change applies only after a human approves it. treeship-commerce 0.29.0 makes that click a signed, single-use grant the apply receipt spends exactly once, on all three runtimes, with the console loop unchanged.

Receipts for agentic commerce

Anthropic's Claude Commerce Agents blueprint tells an agent what it may do in a store. Visa, Mastercard and Google are deciding how an agent may pay. Nobody in that stack keeps a record a stranger can check. Checked against a fresh clone.

You can't have agentic commerce without tamper-evident receipts

Anthropic's commerce-agents reference enforces its gates in code and leaves the record to the deployment. treeship-commerce is that record: every tool call signed on all three runtimes, the merchant's approval as a single-use grant, and a receipt for exactly the cart that went to checkout. Verifiable offline, wired by one command.

Treeship 0.27: the custody handshake

Foreign work handed over A2A or MCP is refused until the other agent proves live key control, and the handoff receipt records that it did.

Treeship 0.26: workflow conformance

A signed workflow.v1 declaration can now be verified against what a session actually did. One fail-closed path runs from the declaration to a conformance report.

Treeship 0.25: revocation, and the wasm saga

Grant revocation works end to end and Linux arm64 binaries ship. It took four point releases to get a working verifier back onto npm, and the lesson is worth the telling.

Treeship 0.24: trusted rooms end to end

A room is a session whose participant set grows by signed invitation. 0.24 signs the room into the receipt, derives the roster from evidence, and adds a liveness challenge on join.

Treeship and Buzz: trusted rooms for agents

Three Buzz agents built Trusted Rooms into Treeship 0.24. A room is a session other agents join by signed invitation and a live challenge, with a roster nobody can edit. Here is what shipped, and what is still theirs to wire.

Treeship 0.23: grants you can issue

0.22 taught the verifier to judge delegation chains and effect finality. 0.23 gives the CLI the commands to mint grants and emit the action/v2 receipts those checks apply to.

The ack is not the act

A valid signature proves a receipt is authentic. It does not prove the thing actually happened. Treeship 0.21 makes that difference something you can check, and refuses to fake the part it cannot.

Treeship 0.20: selective disclosure

An agent can present only the capabilities a verifier needs, and the unsound Groth16 path is quarantined in favor of a statement-first design.

releasev0.20.04 min read

Treeship 0.19: the security-hardening release

Two adversarial audits, every confirmed finding in the default binary fixed with a regression test, and a receipt export any Ed25519 library can verify.

Treeship 0.18: onboard once, present anywhere

Signed work history, certificate chains to the ship, offline presentations with a challenge handshake, and a checkpoint-pinned track record.

Verify any agent in five minutes: a Treeship walkthrough

A complete worked example, from installing the CLI to a stranger verifying your agent over the network with nothing but one pinned key. Every command, every expected output, and what each one proves.

What Zerker Gateway Can Be

We've gotten very good at building agents and very bad at building the plumbing between them. Zerker Gateway is the traffic path for AI agents -- self-hosted, in the path, and honest about every call.

Treeship 0.15: bridges sign with their own keys

The MCP and A2A bridges provision per-agent keys by default, A2A skills become cards, and audit proves a hub log was only appended to.

Treeship 0.14: capability cards and the agent resolver

Agents get per-agent keys, signed capability cards, and a hub-backed resolver with a transparency log that your own machine re-verifies.

Capability Cards: Proving What an Agent Can Do, Not Just What It Says

Descriptor formats like A2A's AgentCard tell you what an agent claims it can do. None of them tell you whether the claim is bound to a key you trust, or whether the agent's actual behavior matches. Here is the arc we shipped to close that gap: a predicate registry, signed capability cards, per-actor signing that makes an agent's identity provable, revocation, and the same verdict in the browser as on the command line.

Introducing Zerker Labs: the trust layer for the agentic economy

Treeship is the first product from Zerker Labs, an applied AI lab building the trust and verification layer for AI agents. Our thesis is simple: the bottleneck is no longer capability. It is trust.

Treeship 0.11: agent invitations

A second agent can join a session through a signed, single-use, expiring invitation that the host countersigns. Plus a local dashboard, a feature inventory, and new skills.

Robinhood Agentic Trading Needs Receipts

How Treeship can provide local proofs, approvals, and audit trails for agents connected to Robinhood Trading MCP.

Treeship 0.10.4: the audit hardening release

A keystore that claimed AES-GCM but was not, verifiers that trusted embedded keys, and a Merkle downgrade path. 0.10.3 and 0.10.4 close the audit findings and publish TS-2026-001.

Treeship Agent Skills: One Skill, Every Agent

Install Treeship on Kimi Code CLI, Claude Code, Codex, Cursor, OpenClaw, and Hermes. One skill file teaches every agent how to create cryptographically signed trust receipts.

Treeship 0.10.1: agent-native sharing and a supply-chain floor

An agent in a fresh sandbox can install Treeship, run a session, and return three working URLs. 0.10.1 hardens the binary, keystore, SDK, and MCP server underneath.

Treeship 0.9.10: approval authority

Grants define authority, uses prove consumption, an append-only journal enforces replay, and packages carry the evidence. The 0.9.10 patch closes the bypasses an adversarial review found.

Treeship 0.9.6: the trust fabric

Three-layer file capture, tool usage checked against the agent certificate, and scoped approvals. A receipt can now say whether the agent stayed inside its bounds.

Treeship 0.9: the official Claude Code plugin

Two commands install a plugin whose hooks record every Claude Code session into a sealed receipt. TREESHIP.md tells the agent exactly what is captured.

Treeship 0.9: verify a receipt anywhere it lands

treeship verify takes a URL, a package, or an id and cross-checks against an Agent Certificate. The same checks ship as WASM for Node, Deno, edge runtimes, and browsers.

Treeship 0.8: zero to receipt in under 90 seconds

treeship add instruments the agent frameworks already on your machine, quickstart walks to a first receipt, and agents get an identity certificate.

Treeship 0.7: session receipts you can verify offline

A closed session now becomes a .treeship package with a Merkle root, a static verifier page, a public hub URL, and A2A middleware.

A2A Makes Agents Interoperable. Treeship Makes That Interoperability Trustworthy.

Google's Agent2Agent protocol gives every agent a way to talk to every other agent. It does not give you a way to verify what any of them actually did. Here is how @treeship/a2a closes that gap, with worked examples you can run end-to-end.

Verifiable Intent: how Treeship becomes the agent's proof of work

Agent attestation in Verifiable Intent credentials: how Treeship proves an agent acted correctly, privately, and within scope.

Four layers of proof: how Treeship uses zero-knowledge

Signatures prove authenticity. Merkle proofs prove timing. Circom proves policy. RISC Zero proves the entire chain. Here's how they fit together.

Treeship 0.1: signed, content-addressed, verifiable offline

The first release put a DSSE signature on every agent action, named each artifact by its bytes, and let anyone check the result without a server.

Agentic Commerce with Treeship

How agents can prove they had approval before spending money.

guide6 min read

Introducing Trust Templates: Configure Once, Prove Everything

Trust templates give any workflow — a Solidity audit, a clinical AI system, an ML training pipeline — a complete attestation setup in one command. Build your own, share with your team, or publish to the community.

Every MCP Tool Call Your Agent Makes Right Now Has No Receipt

The Model Context Protocol specification is explicit: tool calls are arbitrary code execution and hosts are responsible for authorization. Most MCP implementations have no answer to this. Here's what closing that gap looks like.

The Key Management Nightmare Hiding Inside Agent Attestation

Teams adopting cryptographic attestation for agents keep hitting the same wall: one keypair per agent sounds right until you have forty agents and no coherent governance. Here's the model that actually works.

The Replay Attack Your Authorization System Doesn't Prevent

Most authorization systems for AI agents share a subtle flaw: approvals can be reused. An agent that captures an approval token can replay it. Here's the attack and how approval-based authorization prevents it by construction.

Agent Payments: Lobster.cash + Treeship

Lobster.cash handles wallet and settlement. Treeship proves what happened.

Mastercard Verifiable Intent and Treeship

How Treeship's approval receipts align with Mastercard's open standard for agent commerce.

Chain of Custody for AI Agents: What Software Can Learn from Physical Evidence Handling

Physical evidence handling has solved chain of custody over centuries. AI agent workflows need exactly this.

From Subprocess to WASM: Eliminating the Subprocess Attack Surface

When your TypeScript SDK spawns a Rust binary, you've introduced a $PATH dependency, a binary substitution attack surface, and an IPC channel. All three go away when you compile to WASM.

Why We Chose Rust for the Trust Layer

The ZK proof ecosystem is Rust-first and Rust-only in any production-ready form. Here's the complete case for Rust as the foundation of cryptographic agent infrastructure.

Privacy in Agent Workflows: Attestation Without Exposure

Attestation and privacy aren't opposites. You can prove an agent acted correctly without revealing what it acted on.

DSSE: Dead Simple Signing Explained

DSSE is the signing envelope Treeship uses for every artifact. Here's why we chose it over JWS and what the PAE construction actually does.

Approval Nonces and Why a Single Field Prevents an Entire Attack Class

The approvalNonce field in Treeship's ActionStatement is doing a lot of work. Here's the full attack class it prevents and why the design is correct.

The Case for Portable Trust

Why trust artifacts need to travel with the work, not stay locked in the platform that produced them.

Why Agent Actions Need Receipts

When a human takes an action, there's context: intent, memory, accountability. When an agent takes an action, there's just a log line. That asymmetry is the problem Treeship solves.