Try a local receipt proxy
This example records request and response hashes, model identifiers, and a timestamp at the proxy. It cannot establish which provider weights ran or whether the same approval was used elsewhere.
Run the supplied file locally after setting the intended upstream provider. It forwards your request and authorization header, sends request and response hashes with model identifiers and a timestamp to Hive's signer, and writes the returned signature with that record on your machine. Review both outbound paths before using sensitive content.
Save the file below and run it. It listens on port 8402 and forwards to whatever upstream you set.
Change one line in your client. Set the base URL to http://127.0.0.1:8402. Nothing else in your code changes.
The example adds an X-Hive-Receipt header and appends a record to receipts.jsonl after the signer call returns. That local record is not the format accepted by the mesh verifier. Keep the complete signer response and use a verifier documented for its exact schema and algorithm.
hive_sidecar.py
# hive_sidecar.py , one file, no Hive dependency, MIT. # Run it next to your app. Point your OpenAI client at it. # It forwards your call unchanged and writes a receipt per call. import json, hashlib, os, urllib.request from http.server import BaseHTTPRequestHandler, HTTPServer UPSTREAM = os.environ.get("UPSTREAM", "https://hivecompute-g2g7.onrender.com/v1/compute/chat/completions") SIGNER = "https://signer.thehiveryiq.com/sign" def canon(o): # the bytes that get signed, sorted and compact return json.dumps(o, sort_keys=True, separators=(",", ":")) def sha(b): return hashlib.sha256(b if isinstance(b, bytes) else b.encode()).hexdigest() def post(url, obj, hdrs=None): req = urllib.request.Request(url, data=canon(obj).encode(), headers={"Content-Type": "application/json", **(hdrs or {})}) return json.loads(urllib.request.urlopen(req, timeout=60).read()) class H(BaseHTTPRequestHandler): def do_POST(self): body = json.loads(self.rfile.read(int(self.headers["Content-Length"]))) auth = {"Authorization": self.headers.get("Authorization", "")} out = post(UPSTREAM, body, auth) record = { "v": "hive.custody.v1", "asked_digest": sha(canon(body)), # what was asked "requested_model": body.get("model"), # what was requested "served_model": out.get("model"), # what actually answered "arrived_digest": sha(canon(out)), # what arrived "served_at": out.get("created"), # and when } env = post(SIGNER, {"text": canon(record)}) sig = env.get("envelope", {}).get("envelope_signature", "") raw = json.dumps(out).encode() self.send_response(200) self.send_header("Content-Type", "application/json") self.send_header("X-Hive-Receipt", sha(canon(record))) self.send_header("X-Hive-Signature-Scheme", env.get("algorithm", "ML-DSA-65")) self.send_header("Content-Length", str(len(raw))) self.end_headers() self.wfile.write(raw) open("receipts.jsonl", "a").write(canon({**record, "signature": sig}) + "\n") HTTPServer(("127.0.0.1", 8402), H).serve_forever()
Python standard library only. No Hive package to install, nothing to sign up for, and you can read every line of it before you run it. The only outbound call it adds is the signing request, and the only thing that request carries is the digest record you see above.
This demo constructs a sample request and response in your browser, submits their record to the signer, and asks the countersigner for a second signature. The sample does not execute a provider model call, and a returned signature still needs verification.
A supported receipt binds its signed fields to a signing key. This example records a statement about a request and response; it does not prove which policy was enforced or what a recipient received. Use the complete record, a compatible verifier, and a trusted issuer key to check the signature.
Hive operates the signer and countersigner, so the second key and log do not provide an independent witness. The countersigner uses Ed25519. On September 5, 2026, its health response reported log_durable: true and log_dir: /var/hive. Those declarations do not establish tested production recovery, backup restoration, or retention enforcement. Signature algorithms and verification requirements differ by receipt endpoint.
A sidecar you run yourself can see the request and the response. It cannot see inside your provider's scheduler, it cannot observe which resident weights answered, and it cannot watch the admission window. Those stages are carried by name as absent rather than quietly dropped, so a receipt from a full deployment and a receipt from this file are told apart by anyone reading them.
Patent pending. Verification is free and needs no account.