Never lose a Claude Code or Codex session, never miss a script going quiet. Every script and agent gets its own tamper-evident note. Free to start.

3 points•arsphy•6 days ago•3 comments•

3 comments

pushpendraw6 days ago
hash chain is the easy part, the real question is who actually checks it before something breaks.
arsphy6 days ago
Agreed. The real work is making the check actually run, and run before you need it. On my side that's a daily canary: it re-walks a random sample of already-confirmed daily anchors, recomputing each day's Merkle root from its stored leaves and comparing it to the anchored root — so one altered byte anywhere under that day breaks the match — plus a sibling that re-verifies a sample of the RFC 3161 timestamp tokens with openssl. Any discrepancy alarms me via Sentry. The point is to surface silent rot (at-rest corruption, a bad migration — the stuff fresh-fixture unit tests can't catch) while it's cheap, not the afternoon a customer pulls a proof. Honest limit: it samples rather than re-walking all of history nightly, so rot in an unsampled day sits until someone verifies a note from it.

But the check that actually matters doesn't run on my infrastructure at all. Each proof is self-contained — it carries the content preimages, the hash chain, and the Merkle path — so anyone (the /verify page, the in-browser verifier, or you offline) can re-derive that the content is intact and folds to the anchored root without trusting me, and the RFC 3161 token verifies against the TSA's public CA the same way. The one thing I don't vouch for is that the root is genuinely in Bitcoin: you confirm that yourself by running ots verify on the proof against the chain — which is the whole point, that for the part carrying the weight you check Bitcoin's word, not mine. What none of it claims is that the bytes were true when written; it proves unchanged-since, not honest-at-source.

arsphy6 days ago
I built Fresh Jots because I wanted one durable hub to easily track my agents, cron jobs, database backups, and CI results — session logs, deploy output, heartbeats. A place where I could later prove exactly what was written, and that nothing had changed since, as a proof of work. It's a private notes-and-logs store you read and write from the terminal, a REST API, or your AI over MCP.

Three things make it different from a normal notes app. It's programmable — connect Claude or Cursor to https://freshjots.com/mcp over OAuth and your agent can read and append to notes addressable by name, so a session log or a cron job's output lands in a notebook you can read on your phone. It's tamper-evident — every note is SHA-256 hashed and folded into a daily Merkle root committed to Bitcoin via OpenTimestamps, so you can prove to anyone that a log or an AI session existed by a given day and hasn't changed since — verifiable without trusting me or even having an account. Archive your Claude Code sessions with the Fresh Jots hook and each one also carries an immediate, independent trusted timestamp (RFC 3161), stamped on your machine before upload, for to-the-second proof. And it's private — you can client-encrypt any note with your own key, and the server keeps ciphertext it can't read, search, or decrypt; hashing needs no plaintext, so an encrypted note is still tamper-evident.

There's also a dead-man's switch: turn any note into a heartbeat and it emails you when the writes stop — useful for cron jobs and long-running agents.

The MCP read connection is free; agent writes and the full API are on the paid tiers and the 10 note free tier. I'd genuinely like feedback on the tamper-evidence model — a universal daily public anchor, with a client-stamped immediate timestamp on top for session logs — and whether it fits the use cases you'd have. Happy to answer anything.

Short demo: https://www.youtube.com/watch?v=m1gUwhrSwn8

Read the full thread on Hacker News →

Related stories