{"schema":"apex-receipt-verification/1","found":true,"receipt_id":"bb340ec15d932eaed617ccd844fccd2e92e05879a0b4340a0d87d61bc69ab8e4","cite_as":"Validated via Apex (smartapex.uk) agent-secret-scanner - receipt: https://api.smartapex.uk/v1/receipts/bb340ec15d932eaed617ccd844fccd2e92e05879a0b4340a0d87d61bc69ab8e4","card_id":"card_agent_secret_scanner","tool_id":"agent-secret-scanner","issued_at":"2026-07-26T00:33:11.246Z","review_submitted":false,"hashes":{"input_sha256":"44136fa355b3678a1146ad16f7e8649e94fb4fc21fe77e8310c060f61caaff8a","output_sha256":"3848ac09502bf0b3767b4c5f586c4b6800645496a0bbfe649513170315b2e155","wrapper_ref_sha256":"52030bbb16600426655b630ac5d4979906569c350d9b32ef0c59cb2182455178"},"how_to_verify":"Recompute sha256(canonicalJson(input_body)) and sha256(canonicalJson(tool_output)) and compare with hashes above. tool_output = the full /run response minus its verification_receipt, usage_feedback, and cite_as fields. canonicalJson = sorted keys, undefined dropped. Match = that exact data went through this bounded Apex wrapper at issued_at. Working code: https://github.com/mickeyappol-create/apex-agent-client","card":"/v1/cards/card_agent_secret_scanner","note":"Proves a bounded read-only wrapper run was recorded. Does not prove the claim built on top of it, and never releases source."}