Prove the outcome wasn't chosen after the fact.
OpenRNG is the trust and observability layer for autonomous AI systems. It makes AI decisions β and any selection process β provably fair and independently verifiable.
The fastest path to trustworthy randomness. Commit to your candidates before the randomness exists β then prove it.
// TypeScript β run: npx tsx fair-selection.ts
import { createHash } from 'node:crypto';
const BASE_URL = 'https://x402.openrng.io/v1/rng';
const candidates = ['alice', 'bob', 'charlie', 'diana', 'evan'];
const domain = 'grant-round-12';
// 1. Hash the candidate set BEFORE any randomness is involved
const candidateSetHash = createHash('sha256').update(candidates.join(',')).digest('hex');
// 2. Commit to a future VDF epoch
const commitRes = await fetch(`${BASE_URL}/commit`, {
method: 'POST',
headers: { 'Content-Type': 'application/json' },
body: JSON.stringify({ epoch_offset: 3, candidate_set_hash: candidateSetHash, domain }),
});
const commitment = await commitRes.json() as any;
console.log('π Receipt:', { id: commitment.commitment_id, epoch: commitment.committed_epoch });
// 3. Share this publicly β anyone can verify candidates were locked before randomness
console.log('π Proof-of-commit:', JSON.stringify({ id: commitment.commitment_id, candidateSetHash }));
// 4. Wait for epoch maturity (VDF sequential β nobody could preview it)
await new Promise(r => setTimeout(r, (commitment.estimated_ready_seconds + 2) * 1000));
// 5. Reveal and verify locally
const revealRes = await fetch(`${BASE_URL}/reveal/${commitment.commitment_id}`);
const reveal = await revealRes.json() as any;
if (!reveal.verification.commitment_hash_verified || !reveal.verification.temporal_valid)
throw new Error('Verification failed β reject this result.');
console.log('β
Verified:', reveal.verification.temporal_note);
// 6. Derive winner
const idx = Number(BigInt('0x' + reveal.value) % BigInt(candidates.length));
console.log(`π Winner: ${candidates[idx]} β verify: ${reveal.verification.verify_url}`);Full TypeScript tutorial β Β· Python tutorial β
npm install @openrng/client # coming to npmimport { OpenRNGClient } from '@openrng/client';
const client = new OpenRNGClient();
const result = await client.fairSelect({
candidates: ['alice', 'bob', 'charlie', 'diana', 'evan'],
domain: 'grant-round-12',
epochOffset: 3,
});
console.log(result.winner); // 'charlie'
console.log(result.proof.verifyUrl); // https://verify.openrng.io/340386
console.log(result.receipt); // { id, epoch, candidateSetHash, commitTime }SDK source β Β· Full API docs β
| Claim | How |
|---|---|
| Candidates were fixed before randomness | candidateSetHash committed on-chain before VDF epoch runs |
| Operator couldn't predict or rig the output | VDF sequential computation β even the operator can't fast-forward |
| This specific randomness determined the winner | commitment_hash_verified: true |
| Randomness was generated AFTER commitment | temporal_valid: true β epoch sequence enforced |
Anyone can verify the full chain at verify.openrng.io.
# TypeScript (30 lines, zero extra deps)
cd examples/fair-selection-ts && npm install && npx tsx fair-selection.ts
# Python (30 lines, stdlib only)
cd examples/fair-selection-py && python3 fair_selection.pyBeyond randomness, OpenRNG records, proves, and explains AI decisions using the VEO-2 standard (Verifiable Execution Objects).
import OpenAI from 'openai';
import { auto } from '@openrng/auto';
const client = auto(new OpenAI());
// Every AI call now emits a Verifiable Execution Object.
const response = await client.chat.completions.create({
model: 'gpt-4o',
messages: [{ role: 'user', content: 'What is the capital of France?' }],
});import { capture, signVEO, verifySignature, generateSigningKeys } from '@openrng/core';
const keys = generateSigningKeys();
const veo = capture({ provider: 'my-service', prompt: '...', output: '...', model: 'gpt-4o' });
const signed = signVEO(veo, keys.privateKey);
verifySignature(signed, keys.publicKey); // true β prove it came from you
verifySignature(signed); // true β prove it hasn't been modifiedA Verifiable Execution Object is a signed, tamper-evident record of any AI execution. It captures what happened, proves it hasn't been modified, and makes it independently verifiable.
| Class | Name | Use Case |
|---|---|---|
| VEO-2A | Raw Execution | Single AI call (chat, completion, inference) |
| VEO-2B | Composite | Multi-step chains, agent pipelines |
| VEO-2C | Anchored | With blockchain proof / Merkle anchor |
| VEO-2D | Governed | With policy assertions, human approvals |
| Package | Version | Purpose |
|---|---|---|
@openrng/client |
0.1.0 |
One-line provably fair selection (SDK wrapper) |
@openrng/core |
VEO-2 types, creation, Ed25519 signing, validation | |
@openrng/auto |
Auto-instrument AI SDK calls | |
@openrng/verify |
coming soon | Anchor-bound verification |
@openrng/replay |
coming soon | Decision replay and debugging |
| Example | Language | What it shows |
|---|---|---|
fair-selection-ts |
TypeScript | 30-line commit/reveal, full protocol |
fair-selection-py |
Python | Same in stdlib Python |
agent-arbiter |
TypeScript | Three AI agents compete for tasks |
game-loot |
TypeScript | Game loot drops backed by VEO |
langchain |
TypeScript | LangChain integration |
| Service | URL | Status |
|---|---|---|
| API | api.openrng.io | Operational β 200+ CCU, <200ms |
| RNG API | x402.openrng.io/v1/rng | Commit/reveal endpoint |
| Docs | api.openrng.io/docs | API documentation |
| Play | play.openrng.io | Provably fair Sic Bo demo |
| Verify | verify.openrng.io | Independent verification |
1. You hash your candidate list β candidateSetHash = SHA256(list)
2. You POST a commitment β commitment_id + committed_epoch
3. VDF computes epoch N sequentially β can't be skipped, can't be previewed
4. [Publish commitment_id publicly] β anyone can audit what you committed to
5. Epoch matures, you reveal β value + cryptographic proof
6. Local verification β commitment_hash β + temporal order β
7. Derive winner: BigInt(value) % N β deterministic, reproducible by anyone
The security guarantee: the VDF is sequentially computed. Nobody β including the service operator β can compute epoch N faster than the VDF clock allows. Your commitment was recorded before the clock finished. Therefore: the output was unknowable when you committed.
git clone https://github.com/ned-del/openrng.git
cd openrng
# Run the 30-line tutorial (proves everything works)
cd examples/fair-selection-ts && npm install && npx tsx fair-selection.ts
# Build the client SDK
cd packages/client && npm install && npm run build
# Core SDK
cd packages/core && npm install && npm run build && npm test
# Auto-instrumentation
cd packages/auto && npm install && npm run build && npm testThe VEO-2 RFC defines the Verifiable Execution Object standard.
PCT/CN2026/086184 β ISR favorable (all Category A, no prior art threats).
| # | Coverage |
|---|---|
| 1 | Trustworthy entropy (Merkle batch RNG) |
| 2 | Verifiable execution (VDF anti-preview) |
| 3 | Entropy as infrastructure |
| 4 | Decision coordination and lineage |
| 5 | Runtime trust and governance ("Trust Health") |
MIT
OpenRNG β Open infrastructure for verifiable AI execution