EcoCloud snapshots an agent’s live governance state into a short-lived ECDSA-signed proof. A verifier checks any proposed action offline — no database, no trust.
POST /api/v1/agent/proof), which checks the ECDSA signature and evaluates your action against the embedded caps — the same logic the live constitution runs. Tamper with the proof and the signature check fails. Verify the signing key yourself at the JWKS.