{"schema":"apex-receipt-verification/1","found":true,"receipt_id":"bd2b4e65dadc4ccb6bfa4eeb025643b29aadb88d9e2cd8abbfff8ed89c21b3d0","cite_as":"Validated via Apex (smartapex.uk) agent-secret-scanner - receipt: https://api.smartapex.uk/v1/receipts/bd2b4e65dadc4ccb6bfa4eeb025643b29aadb88d9e2cd8abbfff8ed89c21b3d0","card_id":"card_agent_secret_scanner","tool_id":"agent-secret-scanner","issued_at":"2026-07-19T22:48:58.849Z","review_submitted":false,"hashes":{"input_sha256":"cdf9d22018b49025dba5e4ae731063ae967c33277df512a65ca50695889e70f4","output_sha256":"78231ca7067173d0e71e4c318a44785a601d67c1b0d3a17edd73e5d29a3a3d77","wrapper_ref_sha256":"52030bbb16600426655b630ac5d4979906569c350d9b32ef0c59cb2182455178"},"how_to_verify":"Recompute sha256(canonicalJson(input_body)) and sha256(canonicalJson(tool_output)) and compare with hashes above. tool_output = the full /run response minus its verification_receipt, usage_feedback, and cite_as fields. canonicalJson = sorted keys, undefined dropped. Match = that exact data went through this bounded Apex wrapper at issued_at. Working code: https://github.com/mickeyappol-create/apex-agent-client","card":"/v1/cards/card_agent_secret_scanner","note":"Proves a bounded read-only wrapper run was recorded. Does not prove the claim built on top of it, and never releases source."}