# Server side of the "Three deliveries" demo

Everything the browser talks to, published so the measurement can be read, not believed.

| file | role |
|---|---|
| `proxy.py` | the only server process. Receives page requests, calls the Extella platform, calls the model once per teach, counts model calls at that boundary. Secrets (platform token, model key) come from the environment; none are in the code. |
| `route_core.py` | the route language: grammar, validator, engine, level 1, map generator without ties, test levels. |
| `handler_tail.py` | the device-side entry point appended to the core; together they form the handler that runs on a device. |
| `build_registrar.py` | builds `demo_register_route.fython` from the two files above, computes the handler sha256 and registers the handler on our devices. |
| `demo_register_route.fython` | the registrar as deployed: the handler text sits between the triple quotes. |

## How to check the two claims yourself

**No model call during a run.** In `proxy.py` the model is reached in exactly one function, `generate_program`. It increments a per-request counter. `/api/robot/run` never calls that function; its response carries the counter as `model_calls_measured`. `/api/robot/teach` calls it once, or twice on a repair, and reports `model_calls_create`.

**The handler on the device is this handler.** Take the text between the triple quotes in `demo_register_route.fython`, delete the line starting with `HANDLER_SHA = `, and sha256 the rest. Every run reports the same value as `handler_sha`; the proxy recomputes it from this file as `handler_sha_expected`.

What this does not prove: that the server executes these exact bytes. That gap closes only by running the expert on your own device, which the page offers under "Run it on your machine".

Source of truth: private repository `extella-tech-pr`, folder `demo/route/`. This copy is refreshed on every deploy.
