Receipts
Every call can produce a signed receipt on the public Zanii ledger.
Set a key's receipt mode when you create it:
off: no receipt.on: a receipt per call, best effort.required: receipt or nothing. If a receipt cannot be signed, the call is refunded and refused.
What is published
The prompt and the answer are not published. payload_hash is a salted hash: the salt stays
with us, so a short prompt cannot be guessed from the public log, and you can still prove later that
a particular text produced that receipt.
model_id is covered by the signature. That is what lets you prove you were served the model you
paid for, and not something cheaper.
Verifying
Fetch the proof from the ledger and check it client-side with zanii in Python or @zanii/core in
JavaScript. It is a Merkle inclusion proof against a signed tree head, so the ledger is not trusted
to vouch for its own log.