Guide

Agent sessions

For agentic tools like Claude Code, K-Veritas records a signed log of everything an AI agent does, so no designated action can happen off the record.

Recording a session

kveritas init --harness --agent "claude-code" --operator alice
# then run your agent normally, e.g.
claude
kveritas seal --output session.json
kveritas verify session.json

init --harness has the server sign the designation D (which actions must be recorded) and installs the Claude Code hooks. Every designated action (tool calls, file writes, prompts, sub-agent spawns) is recorded to a hash chain before it takes effect. If an action cannot be recorded, the tool is blocked.

What it guarantees

Each entry binds the acting agent's identity, the input and output content (as hashes), and its position in the order:

Existence

The action happened, and who performed it.

Content

The exact inputs and outputs.

Order

Its position in the sequence.

No party, including the agent and its operator, can deny or alter a designated action without verification rejecting and pointing to the exact entry.

Proving a specific prompt or output

The log stores only hashes, so content is never exposed. To prove one prompt or output was recorded, reveal just that entry's content and check it against its committed hash. Every other entry stays a hash:

kveritas harness-prove session.json 1 --input prompt.txt -o proof.json
kveritas verify-harness-proof proof.json

The proof carries the full signed chain plus that one entry's content. Verify confirms the chain is authentic and that the content re-hashes to the committed hash at that position. Select the entry by index or --tool-use-id; reveal the prompt with --input or the response with --output-content.

Multi-agent attribution

The main agent, nested sub-agents, and operator prompts are each attributed to who performed them. verify prints a per-agent activity tree (reads, writes, commands, spawns), rebuilt from signed facts, so re-parenting or hiding a sub-agent's action is detected. Upload the session .json at kveritas.org/verify to see it rendered.