Execution receipts
receipt-vectors.v1.jsonSettles: Whether a receipt proves the action that ran was the action authorized.
Real receipts produced by executing against the protected receiver, not constructed for the file. ES256 over the compact form, raw 64-byte R||S, Base64Url. Each names the SHA-256 of the previous one, so a deleted receipt is as detectable as an altered one. One vector is a receipt whose amount was edited after signing; a verifier that reads the decoded payload without checking the signature accepts it, which is the mistake the file exists to catch.