The official plugin hooks SessionStart, PostToolUse and SessionEnd, so every session becomes a sealed package without the model being asked. Skill and MCP bridge for the lighter tiers.
Treeship produces the same signed receipt whether the agent runs in Claude Code, on a Rust framework, or behind an MCP server, and anyone verifies it the same way, offline, with no registry in the loop. Every card below says what is shipped, what is not, and how to install it.
Claude Code, Codex, Cursor and the others. One skill file teaches an agent the four Treeship commands; where the harness exposes hooks, a plugin records every tool call outside the model's context, so the record does not depend on the model choosing to keep it.
The official plugin hooks SessionStart, PostToolUse and SessionEnd, so every session becomes a sealed package without the model being asked. Skill and MCP bridge for the lighter tiers.
Skill and MCP bridge shipped. The plugin is a skill bundle awaiting marketplace listing; Codex exposes no pre/post tool-call hooks yet, so there is no bypass-proof tier to ship.
Signed receipts for tool calls through the MCP bridge, plus wrap-friendly shell hooks. A hook-tier plugin would need a VS Code extension intercepting Cursor's tool events, which Cursor does not expose.
The gateway plugin captures before_tool_call and after_tool_call in the gateway process, pairing every intent with its result. @treeship/openclaw-plugin is not yet published to npm, so build it from integrations/openclaw-plugin in the treeship repo and install it locally. Skill file and MCP bridge for the lighter tiers.
Skill and MCP bridge shipped; the actor is set by TREESHIP_ACTOR so receipts name the agent rather than the bridge. The hook plugin (PreToolUse, PostToolUse) is verified end to end and awaits listing.
Skill file and MCP bridge. Hermes has not confirmed a gateway hook surface, so skill plus MCP is the ceiling until it does; the page says so rather than implying more.
Three Buzz agents built Trusted Rooms into 0.24: a room is a session other agents join by signed single-use invitation and a live key challenge, with a roster derived from signatures. Nest agents carry the skill and MCP bridge; the channel-to-room wiring is not built.
The first host for agent-to-agent verification: the packaged skill mints the nonce, verifies the other agent's presentation, refuses on any failure and records the verify. Approvals are blocked because the decision lives only in Grok's UI.
Perplexity is shipping the official Treeship Computer skill; receipts name the agent perplexity-computer. Pro Search has first-party connectors only, so nothing ships there.
Two drop-in packages for the protocols agents use to reach tools and each other. Every MCP tool call gets an intent receipt before it runs and a result receipt after. Every A2A hand-off is refused until the sender proves it controls its key. Neither changes the wire format.
A drop-in MCP client. Every tool call gets an intent receipt before dispatch and a result receipt after; approval-gated calls are bound to their grant. Signing failures are reported, and TREESHIP_STRICT=1 fails the call instead of proceeding unrecorded.
Task intents and results attested on both sides. Since 0.27 the receiver refuses foreign work until the sender proves live key control against a nonce it minted, and the hand-off records that verify as custody: live.
For code that calls tools directly instead of through a protocol: a wrapper for Rust agents, a plugin for Anthropic's commerce blueprint, and client libraries for Python, TypeScript and Go that attest actions, spend approvals and verify packages in process.
Receipts for every tool call on all three of the reference's runtimes, single-use merchant approvals, the checkout hand-off and the host's order, and a Claude Code plugin that wires it. Refusals are signed, not missing.
Receipts for every chain and tool call through a callback handler, chained from the session root.
Wrap any Rig PortableTool and every call gets an Ed25519-signed receipt in a tamper-evident, offline-verifiable chain, in-process with no subprocess. Lives in the monorepo and publishes in lockstep with treeship-core.
Attest actions, approvals and hand-offs, add timeline events, close sessions, verify. Bootstraps the matching CLI on first use and warns when the CLI is on another release line.
The same attest and session surface for Node, shelling out to the CLI, plus the WASM verifiers (receipts, certificates, cross-verify, presentations) that run in-process with no binary on PATH. Full signature verification of a local artifact still goes through the CLI.
The Rust verifier compiled to WebAssembly, in a browser, a worker or a serverless function, with no network. Certificates, presentations and cross-checks verify signatures against your own pinned roots; a receipt JSON alone is checked structurally (Merkle root, inclusion proofs, timeline) and reports structural-pass, since signatures need the sealed package.
DPoP proof signing and receipt publishing for a Go service, tested against the real hub verifier. The path a Go backend takes to the Hub API without shelling out to the CLI.
Jev's typed answers (noul, choice, score) in the judge slot through a small adapter: every answer signed as a judgement.v1 receipt with the model version, the threshold and the outcome, marked not replayable because a sampled model is not. Independent implementation against the published API, tested with a mock, not run against the live service.
Visa, Mastercard and Google are defining how an agent proves it is allowed to pay. Those credentials cover the moment of payment. A Treeship receipt covers the steps before it: the search, the refused cart add, the merchant's approval. One draft standard carries a Treeship receipt inside its own attestation field; the others sit beside it.
An independent implementation of the v0.1 draft: treeship vi mints the agent's key, checks a purchase against the mandate, signs the Layer 3 pair for the network and the merchant, and carries a Treeship receipt in the spec's own agent_attestation claim. Interop with the reference SDK is tested both ways in CI.
Complementary, not integrated. Visa's Trusted Agent Protocol, Google's AP2 and the OpenAI + Stripe ACP sign agent identity and payment authority at the merchant's edge and on the network; Treeship signs the agent's steps, the merchant's approvals and the cart, offline. A deployment can run both.
Treeship is one of several Zerker Labs systems. Gateway governs agent traffic, Reason makes policy decisions, memory providers store what an agent knows. Each one signs or checks the same receipt format, so a policy decision and the action it authorised verify together.
A Reason action-authorization certificate signed and chained as a Treeship receipt under a registered predicate, so the policy decision behind a purchase or a price change verifies independently of the engine that made it.
The gateway that routes, observes and meters agent traffic. Treeship is the proof layer it points at for who can prove what happened.
Treeship as the portable proof layer for what an agent remembered and when: a memory write is an attested action, a recall a verifiable read.
Products and templates other teams built for their own users, carrying Treeship receipts. Each card shows the builder's own status, stated as it is.
Lobster handles the wallet and settlement; Treeship proves what happened. Every payment attested through treeship wrap, with a lobster-cash trust template in the treeship repo (not one of the built-in templates).
Local receipts, approval binding for order placement and audit trails for agents on Robinhood's trading MCP. A receipt template ships; Robinhood's own rollout is gradual and theirs.
Ninja Dev locally today; SuperNinja's remote VMs through MCP and GitHub once invitations and rooms land on their side.
Any agent that can read a skill file can produce receipts today. If the runtime exposes pre- and post-tool-call hooks, a plugin that signs outside the model's context is about a day of work against an existing one.
npx skills add zerkerlabs/treeship --skill treeship --agent <name> -g -y
How the skill works ↗