A proof URL is public, anonymous, and read-only
GET /proof/{id} serves a certified Grade as a plain artifact: no account,
no key, no auth. The same URL content-negotiates — JSON for an agent, HTML for a
browser, markdown for a markdown-preferring client — so whoever (or whatever)
holds the link can read the receipt.
What makes it more than a link is that you never have to believe it. A proof URL is designed to be checked by the reader, two independent ways.
Check one: the browser re-verifies the signature
Open the proof page and it does something no self-report can: it fetches
kestrel's published verify key from the /.well-known/kestrel-markets
discovery document and re-verifies the Grade's Ed25519 signature in your
browser, against the artifact's pinned roots. The key is public material — a
verify key can check a signature, never create one — so the page proves the
receipt was signed by the platform's key without you trusting the page itself.
Every proof also names the kid of the key that signed it and points at that
discovery document, so a determined reader can fetch the key and check the
signature entirely by hand.
Check two: the CLI recomputes the record byte for byte
The browser checks the signature. The command line checks the computation. Point the CLI at a proof and it fetches the evidence bundle, re-projects the Blotter locally with the shipped projector, and asserts the result is byte-identical to the hosted one. You are no longer trusting that the numbers are signed — you are reproducing the numbers.
A worked example
Take any generic index proof — an IDX session someone ran and shared. You did not run it, you do not have their account, you were not given a key. You still learn two things for certain: that the platform's key signed exactly this record (browser check), and that the record recomputes to the same bytes on your machine (CLI check). A screenshot could claim anything; this proof survives both checks or it does not exist.
See it in kestrel
Mint your own receipt over a generic index scenario — free, anonymous, no card:
npx kestrel.markets sim fomc-rate-decision-whipsawIt prints a proof URL. Now check a proof — this one, or the one you just minted — without any trust in the server. Re-verify its signature against the independently fetched published key:
npx kestrel.markets verify https://kestrel.markets/proof/art_d29415f0cf502f4a218a9cbaFor the full anatomy — the roots, the open judge, the discovery document — read evidence. The proof URL is the durable handle: keep it, and drop the kestrel.markets MCP server into your client so the next session picks up from it, no account in between.