> ## Documentation Index
> Fetch the complete documentation index at: https://docs.mnemom.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Substrate Fingerprint

> The provider, model, SDK and optional lockfile hash recorded on each integrity checkpoint, so you can tie an agent's decisions to the stack it ran on.

The **substrate fingerprint** records what an agent ran on: the model provider, the model and, when known, the SDK and a hash of your dependency lockfile. The gateway records it on every [integrity checkpoint](/concepts/integrity-checkpoints) as the `substrate_id` field.

It is evidence for your own audit. If you later learn that an SDK release or one of your dependencies was compromised, you can find the checkpoints that ran on it, and so the agent decisions to review.

## What is recorded

Each integrity checkpoint stores these fields:

| Field | Value | Where it comes from |
| - | - | - |
| `provider` | The model provider, for example `anthropic` | The request |
| `model` | The model, for example `claude-sonnet-4-6` | The request |
| `sdk_version` | `<sdk>@<version>`, or `null` | The `X-Mnemom-Sdk-Version` header if you send it, otherwise the request's `User-Agent` |
| `lockfile_hash` | 64 lowercase hex characters, or `null` | The `X-Mnemom-Lockfile-Hash` header only. It is never inferred. |
| `substrate_id` | The fields above joined with `:` | Computed when the checkpoint is stored |

`provider` and `model` are always present. The other two are optional.

### The four collapse forms

`substrate_id` takes one of four shapes, depending on which optional fields are present:

| Fields present | `substrate_id` |
| - | - |
| Provider and model only | `<provider>:<model>` |
| SDK | `<provider>:<model>:<sdk@ver>` |
| Lockfile hash, no SDK | `<provider>:<model>::<lockfile-hash>` (empty third slot) |
| SDK and lockfile hash | `<provider>:<model>:<sdk@ver>:<lockfile-hash>` |

The separator is `:`. The `@` inside `<sdk@ver>` belongs to the SDK identifier (for example `@anthropic-ai/sdk@0.65.0`).

## The two optional headers

| Header | Effect | Validation |
| - | - | - |
| `X-Mnemom-Sdk-Version` | Sets the SDK identifier. Takes precedence over the `User-Agent`. | Free-form. Send `<package>@<version>`; a `<package>/<version>` value is rewritten to that form. |
| `X-Mnemom-Lockfile-Hash` | Adds the SHA-256 digest of your resolved dependency manifest. | 64 hex characters. Mixed case is accepted and stored lowercase. A malformed value is rejected with `400` and `X-Mnemom-Error: invalid-lockfile-hash`. |

Without `X-Mnemom-Sdk-Version`, the gateway reads the SDK from the `User-Agent` for these SDKs: `anthropic-sdk-python`, `anthropic-sdk-typescript`, `@anthropic-ai/sdk`, `openai-python`, `openai-node`, `google-genai-python` and `google-cloud-aiplatform`. For any other client, `sdk_version` is `null` unless you send the header.

Only the hash is sent. Your lockfile never leaves your environment. The [lockfile-hash opt-in guide](/guides/lockfile-hash-opt-in) shows how to compute the hash and set both headers.

## Reading it back

`substrate_id` and its parts are returned with each checkpoint:

```bash theme={null}
curl -sS \
  -H "X-Mnemom-Api-Key: $MNEMOM_API_KEY" \
  "https://api.mnemom.ai/v1/agents/$AGENT_ID/checkpoints?limit=1" \
  | jq '.checkpoints[0] | {substrate_id, sdk_version, lockfile_hash}'
```

## What it is not

* **Not signed.** The fingerprint is stored with the checkpoint but is not part of the checkpoint's signed payload. See [integrity checkpoints](/concepts/integrity-checkpoints) for what the signature covers.
* **Not a detector.** Mnemom does not compare fingerprints across customers or raise supply-chain alerts from them. The fingerprint tells you what ran; deciding whether that stack was compromised is up to you and your other tooling.
* **Not a replacement for package provenance.** Verify the packages you install with SLSA provenance, Sigstore and dependency scanning. See [supply-chain trust](/guides/supply-chain-trust).

## See also

* [Lockfile-hash opt-in](/guides/lockfile-hash-opt-in) — computing the hash and setting the headers
* [Supply-chain trust](/guides/supply-chain-trust) — verifying Mnemom's own packages
* [Integrity checkpoints](/concepts/integrity-checkpoints) — the record the fingerprint is stored on


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.