Send us your receipts
The Conduct Log Commons: a free, public, append-only record of what agents do on tolled sites. Free to report to, free to read, verifiable without trusting TunnelMind.
DRAFT — the mechanics below are live and checked against the running API; the prose is a working draft and will be rewritten.
1. What you are sending
A site running tollbooth produces two kinds of signed documents: conduct receipts (an identified agent paid, ignored the offer, spoofed, or presented a mismatched voucher) and traffic snapshots (who knocked, how often, which paths). Both are signed with your site key, Ed25519 over RFC 8785 JCS. They contain no human data by design; the one free-text field is the crawler's own User-Agent.
2. Two config lines
report = true report_url = "https://data.tunnelmind.ai/v1/tollbooth/receipts"
On Cloudflare Pages with @tollbooth/cloudflare, snapshots are one more option:
snapshots: { url: "https://data.tunnelmind.ai/v1/tollbooth/report" }
There is no token and nothing to register. The signature on each document is the authentication: a document that does not verify under the key it names is refused and nothing is stored.
3. Vouch for your key (one static file)
Anyone can generate a keypair, so a bare key is stored but labelled unattested and kept out of the exhibits. To be counted, your domain says the key is yours by serving:
https://YOUR-DOMAIN/.well-known/tollbooth-site.json
{ "v": 1, "keys": ["<your site public key, base64url>"] }
Then tell the commons which domain to check, once, on any report:
X-Tollbooth-Domain: YOUR-DOMAIN
The claim is only ever turned into a fact by fetching that file over HTTPS. It is re-checked about daily; a key that disappears from the file drops back to unattested, an outage at your domain does not. Public hostnames only, no redirects.
This site's own file: /.well-known/tollbooth-site.json.
4. What you get back
| Read | URL |
|---|---|
| Browse + verify in the browser | tunnelmind.ai/conduct/log |
| Live exhibit (attested tier) | data.tunnelmind.ai/v1/tollbooth/stats |
| One UTC day, receipts, JSON Lines | data.tunnelmind.ai/v1/tollbooth/export?day=YYYY-MM-DD |
| Same, traffic snapshots | …/export?day=YYYY-MM-DD&kind=reports |
| Everything, including unattested keys, labelled | …/export?day=YYYY-MM-DD&tier=all |
Every exported line is the document exactly as it was signed, wrapped with the tier and the vouching domain. Verify a line offline with tollbooth verify or @tunnelmindai/receipt-verify: the key is the site field, nothing else is needed.
5. Limits, stated
| Rule | Value |
|---|---|
| Documents per signing key per hour | 2,000 attested · 200 unattested |
| Receipts per batch / body size | 100 / 128 KB |
| Export rows per day per read | 5,000 (cached one hour) |
| Retention | append-only; the raw record is never paywalled |
Sequencing into a Merkle log with inclusion proofs is the next step and changes nothing about what you send.