Measurement Capsules
A measurement capsule is one small, signed record of one check we ran: what something declared about itself, what we observed when we looked, when we looked, and the limits of the look. Every capsule is published, so anyone can re-check it without asking us. Council of AI is operated by CSOAI Ltd.
Measurement, not endorsement. A capsule records a state, such as CONSISTENT, INCONSISTENT or UNCHECKABLE. It is never a score, grade, ranking or approval of the thing measured. Something we hold no capsule about is not measured, not “clean”.
What a capsule is
- Declared vs observed. Each capsule sets a public claim (a server's own description, an agent card, an issuer's list) beside what our instrument saw, and names the difference if there is one.
- Small. One capsule is a compact JSON record, most of them a few kilobytes, so it can travel with the thing it describes.
- Content-addressed. A capsule's id is the SHA-256 of its own content (canonical JSON, keys sorted, the id field left out). Change one character and the id changes, so any copy can be checked against the original.
- Bound and signed. Capsules are grouped into batches with a Merkle root each; one daily index binds every batch, is signed with the board key
did:web:csoai.org#board-attestation-1and is timestamped. - Correctable. A capsule we got wrong is not edited; a later one points back to it, and the change is dated in the corrections ledger.
What we measure today
The current index, as of 2026-09-26 10:34:15 UTC, holds 13,184 capsules of 7 kinds, in 8 signed batches. Read from /measurement-capsules/v0.2/index.json.
MCP contract parity
Does the tool set an MCP server's public descriptions declare match the tool set the live server lists?
9,148 capsules ·
measurement.contract_parityStates: CONSISTENT 5,570, INCONSISTENT 2,905, UNCHECKABLE 673
Tool drift
Did the tools an endpoint advertised at one read change by the next read?
3,240 capsules ·
measurement.tool_driftStates: UNCHECKABLE 1,755, UNCHANGED_AT_NAME_GRANULARITY 1,485
Cross-ledger token supply
Is a token at this address the issuer's own deployment on that ledger, and what does the ledger's own state say is issued?
353 capsules ·
measurement.cross_ledger_supplyStates: CONSISTENT 101, OPERATOR_API 77, UNCHECKABLE 52, STATE_PROOF_VERIFIED 49, LISTED_NOT_READ 34, STATE_PROOF_RECORDED 10, TOTAL_COMPLETE 10, TOTAL_PARTIAL 8, PERMISSIONED_NOT_READABLE 6, INCONSISTENT 4, ISSUER_LIST_UNAVAILABLE 2
Cross-runtime reproduction
Does a signed model result come out the same when it is re-run on a different runtime?
These capsules are the evidence behind the preprint Same model, same prompts, different answers.
154 capsules in 2 batches ·
measurement.cross_runtime_reproductionStates: NOT_REPRODUCED 89, REPRODUCED_ITEMWISE 54, REPRODUCED_AGGREGATE_ONLY 11
Self-parity (our own listings)
Does a public index's listing of one of our own services say what we actually serve?
138 capsules ·
measurement.self_parityStates: NOT_LISTED 55, CONSISTENT 37, UNCHECKABLE 37, INCONSISTENT 8, NOT_DECLARED 1
Public signals
What value did this public signal (a package version, a listing, a count) read on this day, from which source?
118 capsules ·
measurement.public_signalStates: MEASURED 103, UNCHECKABLE 12, PARTIAL 3
A2A agent card signatures
Is a published agent card signed by the key it references?
33 capsules ·
measurement.a2a_card_signatureStates: VERIFIED 13, UNCHECKABLE 12, FAILED 8
The current index, its chain and its anchors
Each day's index commits to the day before, so the days form a hash chain that cannot be rewritten quietly. The chain is published on Hugging Face and anchored in public logs that show when the bytes existed. The anchors say nothing about what the capsules measured.
- Index root
- 85533b833d36f8a4165da34206ee6e39f7434c646c8a2c381d251391ceec366d
- Index SHA-256
- ee3d921750d40456eb58ed24d2a9ba141d6fc1d16510ddd338166c4f5620b72aNot the bytes the chain head of 2026-09-27 names (8d7b3647750a…). This site's copy can lag or lead the chain by a deploy.
- Chain
- 2 days from genesis (2026-09-26) to the head of 2026-09-27; last check
CHAIN_INTACTat 2026-09-27 08:12:53 UTC. Chain head - Newest day
- 2026-09-28 · that day's index
- Bitcoin
- block 968674 (2026-09-26)
- Rekor (Sigstore)
- logIndex 2981612513 — measurement-index-v0.2-2026-09-28.json
- Hugging Face
- commit 2cac8a91 (2026-09-28 08:08:02 UTC)
How to verify
In your browser
Paste an MCP server, A2A agent or x402 endpoint URL into Verify a server. You get every capsule we hold about that URL, and a button on each that recomputes its id, its Merkle path and the index signature in your browser.
From the command line
- Fetch /measurement-capsules/latest.json; it names the current index.
- Each batch folder under
/measurement-capsules/v0.2/holdscapsules.jsonl.gzandleaves.json. Recompute every capsule id (SHA-256 of the capsule's canonical JSON without itscapsule_idfield) and the batch's Merkle root (RFC 6962, leaves sorted), and compare with the index. - Check the index's signature in
index.signed.jsonagainst the board key published at csoai.org/.well-known/did.json. - Walk the daily chain back to genesis with the steps in the measurement-index README, then check the OpenTimestamps proofs (
ots verify) and the Rekor entries.
For agents
- MCP at
POST https://councilof.ai/mcp: the toolsmeasurement_index,verify_capsuleandserver_evidence. - A2A: the skills
measurement-capsulesandserver-evidence, listed in our agent card. - x402:
/api/measurement/fresh-capsulere-measures one claim about one MCP endpoint on demand and returns a new signed capsule. That door is paid; reading and verifying capsules is free, always.
Show it on your site
One script tag renders a small card that reads the current index and links here and to Verify a server. It sends nothing about your visitors anywhere; it only reads our public index.
<script src="https://councilof.ai/embed/measurement-capsules.js" async></script>
The card says “measurement, not endorsement”. It does not say anything about the site that shows it.
Objections and re-checks
If you run something we measured and think a capsule is wrong, or you want an endpoint left out, see how our crawler works and how to object, or email nicholas@csoai.org. A re-check produces a new capsule; the old one stays published, and the change is dated in the corrections ledger.