# Headless Oracle daily record

Once a UTC day Headless Oracle publishes a signed, hash-chained record of its own previous day: the halt digest it served, the receipt-verify registry index, and counts of witness checkpoints, MCP use and x402 settlements. Each record is witnessed by Chirindo Witness, which is HO itself, and timestamped with OpenTimestamps; a proof becomes a Bitcoin attestation once the calendars confirm it.

## Now

- No record yet.

- Records: 0; witness receipts: 0; OpenTimestamps proofs pending 0, complete 0, failed 0
- Failed steps: none
- Signing key: key_2026_v1 at https://headlessoracle.com/v5/keys
- Witness key (dedicated to this record): kid -0bMmxck6Lc9XLCOlRWl3pNU0bndJEthVc9itDfWrLU, JWK {"kty":"OKP","crv":"Ed25519","x":"1jp4eQDU5_4AE6aoqQJVIOxL6NOtQvucF6qa9lAgrx0"}, session_id ho-record

## Check it without us

1. GET https://headlessoracle.com/record/<date> and take SHA-256 of the exact response bytes: that is record_sha256.
2. Remove signed_payload, canonical, public_key_id and signature from the parsed record, serialize the rest with RFC 8785 (JCS), and check its SHA-256 equals signed_payload.record_body_sha256; check signed_payload.date, sequence and previous_record_sha256 match the record.
3. Sort the keys of signed_payload, JSON.stringify with no whitespace, check it equals canonical, and verify signature (hex Ed25519) over those UTF-8 bytes with the public_key of the keys[] entry in https://headlessoracle.com/v5/keys whose key_id is public_key_id.
4. Check previous_record_sha256 equals the SHA-256 of the bytes served at https://headlessoracle.com/record/<date - 1 day> (null on sequence 1).
5. Run `ots verify -d <record_sha256> <date>.ots` (or `ots info`) on https://headlessoracle.com/record/<date>.ots; it is pending until a calendar commits it to Bitcoin.
6. GET https://api.headlessoracle.com/v1/witness/checkpoints?kid=<witness_key.kid>&session_id=ho-record and find the receipt whose count is the sequence and whose last_entry_hash is the entry_hash in /record/<date>/proofs; recompute entry_hash from the chain_entry shown there.

## Limits

- The record is signed by Headless Oracle with key_2026_v1 and says what Headless Oracle counted; the signature shows who published the bytes, not that the counts are true.
- The chain shows that a published record was not changed or removed later without the change being visible; it says nothing about a record before it was first published.
- A witness receipt is Headless Oracle's signed statement that it was shown the checkpoint at received_at; it is only as reliable as Headless Oracle and its signing key. Here the operator and the witness are the same party, so this proves use of the product, not independence. Independence comes from the OpenTimestamps proof.
- A timestamp proof is pending until the calendars commit it to Bitcoin; a proof becomes a Bitcoin attestation once the calendars confirm it, usually within hours. A pending proof rests on the calendars' word.
- MCP counts begin on 2026-10-10. A client is counted by the name it sends on initialize, hashed; clients that never send initialize are not counted, and two clients sending one name count once.
- Revenue, purchases and anything about named customers are not in the record.

Machine-readable: https://headlessoracle.com/record
