Send us your receipts

The Conduct Log Commons: a free, public, append-only record of what agents do on tolled sites. Free to report to, free to read, verifiable without trusting TunnelMind.

DRAFT — the mechanics below are live and checked against the running API; the prose is a working draft and will be rewritten.

1. What you are sending

A site running tollbooth produces two kinds of signed documents: conduct receipts (an identified agent paid, ignored the offer, spoofed, or presented a mismatched voucher) and traffic snapshots (who knocked, how often, which paths). Both are signed with your site key, Ed25519 over RFC 8785 JCS. They contain no human data by design; the one free-text field is the crawler's own User-Agent.

2. Two config lines

report = true
report_url = "https://data.tunnelmind.ai/v1/tollbooth/receipts"

On Cloudflare Pages with @tollbooth/cloudflare, snapshots are one more option:

snapshots: { url: "https://data.tunnelmind.ai/v1/tollbooth/report" }

There is no token and nothing to register. The signature on each document is the authentication: a document that does not verify under the key it names is refused and nothing is stored.

3. Vouch for your key (one static file)

Anyone can generate a keypair, so a bare key is stored but labelled unattested and kept out of the exhibits. To be counted, your domain says the key is yours by serving:

https://YOUR-DOMAIN/.well-known/tollbooth-site.json

{ "v": 1, "keys": ["<your site public key, base64url>"] }

Then tell the commons which domain to check, once, on any report:

X-Tollbooth-Domain: YOUR-DOMAIN

The claim is only ever turned into a fact by fetching that file over HTTPS. It is re-checked about daily; a key that disappears from the file drops back to unattested, an outage at your domain does not. Public hostnames only, no redirects.

This site's own file: /.well-known/tollbooth-site.json.

4. What you get back

ReadURL
Browse + verify in the browsertunnelmind.ai/conduct/log
Live exhibit (attested tier)data.tunnelmind.ai/v1/tollbooth/stats
One UTC day, receipts, JSON Linesdata.tunnelmind.ai/v1/tollbooth/export?day=YYYY-MM-DD
Same, traffic snapshots…/export?day=YYYY-MM-DD&kind=reports
Everything, including unattested keys, labelled…/export?day=YYYY-MM-DD&tier=all

Every exported line is the document exactly as it was signed, wrapped with the tier and the vouching domain. Verify a line offline with tollbooth verify or @tunnelmindai/receipt-verify: the key is the site field, nothing else is needed.

5. Limits, stated

RuleValue
Documents per signing key per hour2,000 attested · 200 unattested
Receipts per batch / body size100 / 128 KB
Export rows per day per read5,000 (cached one hour)
Retentionappend-only; the raw record is never paywalled

Sequencing into a Merkle log with inclusion proofs is the next step and changes nothing about what you send.