Skip to content

Notes · 03 · 4 min

What a receipt proves, and what it does not

Every reply carries a model name and a hash. Here is exactly how far that gets you.


Every reply an operator writes carries two things besides the answer: the id of the model that answered, as the gateway named it in its response, and a receipt — the keccak256 hash of the gateway’s response id. Both go into the event log forever. This note is about what those two fields let you check, and what they do not.

What the contract checks

Nothing. The contract cannot see the gateway, so it cannot know whether the model named is the model used or whether the response id exists. It stores the fields and emits them. If the oracle claimed otherwise it would be lying in its ABI.

What a reader can check

ClaimHowWho can
This reply came from a bonded operatorreply() reverts otherwise; the event is proofAnyone, from the log
The operator has a recordoperators(addr) returns answered and won countsAnyone, from the chain
A gateway call with this id happenedOrbio’s generation lookup, given the raw idThe operator (it has the id) or Orbio
That call used the model namedThe same lookup returns the modelSame
That call was run on the asker’s promptNot from the receipt. Orbio keeps no promptsNobody, after the fact

The receipt is a hash, not the id itself, so a stranger cannot look it up. That is deliberate: a raw response id is a handle on someone else’s billing record. What the hash gives you is a commitment. If an operator is challenged — by an asker, by another operator, by anyone who thinks a reply was fabricated — it can produce the id, and anyone can hash it and compare. An operator that cannot produce an id matching its receipt has been caught.

What that is worth

Less than a proof and more than nothing. It rules out the laziest fraud: an operator that never called a model at all and returned a byte at random. It makes the second-laziest fraud, calling a cheaper model than the one named, a thing that leaves evidence in a third party’s logs. It does not rule out an operator that ran the right model on a different prompt, because Orbio keeps no prompts and the oracle cannot either without putting every asker’s question into a database somewhere.

That last gap is covered by the quorum, not the receipt. Three operators that each ran a different prompt do not agree by accident; if they agree, the prompt they ran was almost certainly the one in the log, because that is the only prompt they share.

The honest summary

A receipt proves the operator is willing to be checked. The record proves how often it has been paid for agreeing with others. The quorum proves that, this time, it did. None of those is a proof that the model was right — and the site does not use the word “proof” anywhere it is not.

If Orbio ever publishes a signed response digest — a hash of the prompt and the output, signed by the gateway — the oracle can require it in the receipt field and this note gets a shorter table. The field is thirty-two bytes for that reason.


NextPaid in the thing you spend