MathGround · joules, not tokens
The verifiable energy receipt
Every decision resolves at the lowest tier whose grammar covers it, is priced in energy, and carries a replayability class, signed on the device. Run a request. The result's latency is measured, the receipt is signed with a real key, and its class cannot be forged: tamper with it and the signature breaks.
Receipt
Energy per tier
Accounting. Energy = measured latency × measured device power. The per-tier watts are real: sampled on reference Apple-Silicon with macmon (no sudo) while each tier ran sustained, idle 3.9 W, then LUT 9.7 · formula 10.2 · solver 12.3 · model 21.3 W (the model tier genuinely draws ~2× the CPU). Your device differs, and the cheap tiers finish below the browser's timer resolution, so their energy is a measured upper bound. The gap to the model tier is real, measured in both latency and watts.
Power calibration · verifying signature…
Generating an on-device signing key…