B · Signed receipt
Access receipt
- Receipt
- Actor
- Kind
- Query SHA
- Approval
- Limits
- Finding
Result cells and raw parameter values are omitted. The CLI signs this payload with a key kept in your OS keychain.
Local query gate · specimen no. 001
Put a small, read-only boundary in front of SQLite: named templates pass within limits, novel SQL waits for a human, and every attempt leaves a verifiable receipt—not a copy of the data.
cargo install db-access-receipts
Interactive field test
This browser walkthrough is illustrative and local-only. The real CLI uses SQLite's read-only mode and Ed25519 signatures.
No demo receipts yet. Run the specimen above to begin.
Run a query. Allowed, denied, and failed attempts all leave evidence.
B · Signed receipt
Result cells and raw parameter values are omitted. The CLI signs this payload with a key kept in your OS keychain.
Method, not middleware
Your client or agent invokes one binary. Credentials and query results stay on the machine.
Reviewed templates run with declared parameters. Novel reads require an attached terminal and a randomized challenge.
SQLite opens read-only. Multiple statements and writes stop. Column caps reject; row caps truncate safely.
Every outcome records actor, hashes, limits, counts, approval path, and Ed25519 signature—never result data.
db-receipts query \
--template open-orders \
--param account_id=acct_123 \
--actor analyst@team
# Verify later, without database access
db-receipts verify .db-receipts/receipts/20260827T211400Z-….json
Team field kit
$39 one-time purchase
The CLI, receipt verification, safety controls, and your data remain free and local. The paid kit adds the rollout method.
License verified
Download a clean rollout sheet and adapt it inside your private repository.
Sociobot/Dodo is the merchant of record. Refunds are handled there and revoke the license automatically. See privacy and terms.