NikaReceipt is an opaque readonly record. The SDK never constructs it,
extracts a path from it, enriches it by reading a workflow, or implements
cryptography. It asks the authoritative engine to verify the object unchanged.
The runtime writes and seals trace evidence. Verification reads what already
exists; it never creates a journal or seals an incomplete one. Paused results
can carry evidence for the completed observation leg while the durable job
remains resumable.
Local verification can return verified or invalid. The remote endpoint
currently returns a typed unavailable verdict with reason
trace_journal_unavailable because it has no path-free journal authority. The
diagnostic route exists; this is not a 404.
CLI trace inspection remains available for operators:
Test and trace
Keep goldens and proof verification distinct.
Run receipts pattern
Carry receipts through application boundaries.