{"product":"agent-commerce-reliability-ledger","title":"ApexScout Payment-to-Outcome Reliability Ledger for x402 Agents","release":"v2.2.238-ledger-sdk226-offline-refresh-20261004","positioning":"A bodyless GET containing scoped x402 SDK 2.26 offline findings and separately labeled historical buyer-client, failure and payment records. Includes tested cases, limitations, evidence digests and expiry. Not current wallet or mainnet compatibility, an incident diagnosis, or independent certification; it never initiates payment or handles buyer identity.","schemaVersion":"1.4.0","generatedAt":"2026-10-04T23:26:18.598Z","validUntil":"2026-10-11T23:26:18.598Z","previousDigest":"sha256:381a517ecf2a43abe382ec5fd025e3af39dc592ae53b0f68e11a6c253b26dbda","contentDigest":"sha256:2698d97e4ef5a048acad2bcd95f6a6db8e2b40b5b6ccaa756d85c3c0ae69323d","freshnessPolicy":{"cadence":"weekly evidence-gated edition with a seven-day maximum age","staleAfter":"2026-10-11T23:26:18.598Z","buyerRule":"Do not use the artifact as current after validUntil; inspect the free preview for genuinely newer evidence before considering any purchase.","compatibilityEntryStaleAfterDays":30,"refreshRule":"Only ApexScout-owned public-safe evidence or approved official protocol documentation may change entries."},"currentFreshness":{"status":"current","generatedAt":"2026-10-04T23:26:18.598Z","validUntil":"2026-10-11T23:26:18.598Z","purchaseRecommended":true,"failClosed":false,"reason":"The scoped offline SDK findings remain inside their declared validity window. Historical buyer-client and payment records were not re-verified."},"paidPurchaseAvailable":true,"paidPurchaseAvailabilityReason":"The scoped offline SDK findings remain inside their declared validity window. Historical buyer-client and payment records were not re-verified.","whatChangedInThisEdition":{"summary":"Re-executed the 39 installed SDK 2.26 offline fixtures on October 4: 24 HTTP/server cases, 12 route-template cases and three exact EVM requirement-construction cases. All passed with a new execution binding, unchanged fixture source and package bindings, and an October 11 expiry. Historical client observations and payment records are unchanged; no new live compatibility claim or failure-to-client applicability is added.","entriesAdded":[],"entriesChanged":["sdk-findings-core-http-server","sdk-findings-bazaar-route-validation","sdk-findings-exact-evm-requirements","offline-evidence-execution-binding"],"entriesRetired":[],"compatibilityEntriesAdded":0,"failureSignaturesAdded":0,"fullPaidDatasetExposed":false},"coverage":{"buyerClients":4,"clientVersions":6,"failureSignatures":12,"verifiedMitigations":7,"offlineSdkCases":39,"currentBuyerRuntimesVerified":0},"sdkEvidence":{"evidenceClass":"installed-sdk-offline-fixture","generatedAt":"2026-10-04T23:26:18.598Z","validUntil":"2026-10-11T23:26:18.598Z","freshness":{"status":"current","current":true,"scope":"offline-sdk-observations-only","evaluatedAt":"2026-10-08T07:22:09.551Z","rule":"Status is evaluated only at evaluatedAt; compare validUntil with the actual read time. The immutable Ledger freezes this field at observation time; its preview reports current freshness separately."},"binding":{"recordDigest":"sha256:af7045262ce4ea8da391b10abb0c664b0869d700aad25bf30f67a47ea7f5b237","executionDigest":"sha256:196399a4aaa24817feafa41cc465ae89749030012544884c5cc339520156a454","sourceDigest":"sha256:5e7603f0f37f015715201bda4f7397583207d04a8f85951cb39e4bfe1ec92fa8","packageDigest":"sha256:009bc3af09a3caeca4f14c7800208f9f305a3d8b2714fd9bbd08d950025afab7","baselineContentDigest":"sha256:80ac57ec2ad92b1b77af6167c77387a0d9968a786310ffa1740065e80bc1f8df","meaning":"Digests identify the frozen record, separate execution receipt, bound fixture source, frozen comparison baseline and installed package trees. The comparison baseline is distinct from the Ledger's immediately previous edition. The fixture source binding excludes this public projection, which is checked separately. They do not authenticate an independent witness or identify current production source."},"summary":{"passed":39,"failed":0,"importOnlyChecks":7},"scope":"Installed SDK 2.26 synthetic offline cases only. Package imports are not buyer-runtime support; no new wallet, payment, delivery or mainnet evidence.","historicalEvidenceReverified":false},"historicalEvidence":{"sourceEdition":"v2.2.235-agentcore-bazaar-ledger-refresh","contentDigest":"sha256:16af2ff53c053a79a93e08de1bd61c7bcc30134aac4b31ec5c15e473b74d98d8","generatedAt":"2026-08-22T01:18:17.000Z","validUntil":"2026-08-29T01:18:17.000Z","compatibilityObservationsReverified":false,"failureApplicabilityReverified":false,"paymentObservationsReverified":false,"note":"Compatibility entries, failure signatures, fixes and buyer recipes are retained historical context. The new SDK fixtures do not refresh their verification dates, establish a current incident diagnosis or authorize a retry."},"schema":{"type":"object","required":["product","schemaVersion","release","generatedAt","validUntil","previousDigest","contentDigest","editionDelta","coverage","compatibilityMatrix","failureSignatures","verifiedFixes","buyerRecipes","bazaarMcpBuyerRecipe","buyerRuntimeRecipes","evidencePolicy","sdkFindings","historicalEvidence","privacy"],"properties":{"product":{"type":"string","const":"agent-commerce-reliability-ledger"},"schemaVersion":{"type":"string","const":"1.4.0"},"release":{"type":"string"},"generatedAt":{"type":"string","format":"date-time"},"validUntil":{"type":"string","format":"date-time"},"previousDigest":{"type":"string","pattern":"^sha256:[0-9a-f]{64}$"},"contentDigest":{"type":"string","pattern":"^sha256:[0-9a-f]{64}$"},"editionDelta":{"type":"object"},"coverage":{"type":"object","properties":{"buyerClients":{"type":"integer"},"clientVersions":{"type":"integer"},"failureSignatures":{"type":"integer"},"verifiedMitigations":{"type":"integer"}}},"compatibilityMatrix":{"type":"array","items":{"type":"object"}},"failureSignatures":{"type":"array","items":{"type":"object"}},"verifiedFixes":{"type":"array","items":{"type":"object"}},"buyerRecipes":{"type":"array","items":{"type":"object"}},"bazaarMcpBuyerRecipe":{"type":"object"},"buyerRuntimeRecipes":{"type":"array","minItems":5,"maxItems":5,"items":{"type":"object"}},"evidencePolicy":{"type":"object"},"sdkFindings":{"type":"object","description":"Fixed offline SDK observations with exact scope and provenance; not live buyer-client compatibility."},"historicalEvidence":{"type":"object","description":"Original observation edition, digest, dates and explicit non-reverification boundaries for retained records."},"privacy":{"type":"object"}}},"representativeEntries":{"sdkFinding":{"category":"Core HTTP and startup fixture observations","claim":{"id":"core-http-invalid-extension-header","assertion":"For twelve synthetic verify/settle responses, missing or invalid extension headers were ignored; a body extensionResponses field did not impersonate header diagnostics. Each response retained its synthetic success result, used one mocked request, and emitted no logs.","caseNames":["verify: missing extension header is ignored","verify: malformed base64 extension header is ignored","verify: malformed JSON extension header is ignored","verify: null JSON extension header is ignored","verify: array JSON extension header is ignored","verify: scalar JSON extension header is ignored","settle: missing extension header is ignored","settle: malformed base64 extension header is ignored","settle: malformed JSON extension header is ignored","settle: null JSON extension header is ignored","settle: array JSON extension header is ignored","settle: scalar JSON extension header is ignored"]},"limitations":["All facilitator responses were synthetic and intercepted inside the process; no real facilitator was contacted.","No wallet, mainnet transaction, paid delivery or third-party buyer runtime was executed.","No universal privacy, retry-safety, timeout-duration or production-readiness guarantee follows from these finite cases."],"partial":true},"compatibility":[{"id":"awal-2-12-canonical-v2","client":"AWAL CLI","version":"2.12.0","protocol":"x402-v2","network":"eip155:8453","transport":"HTTP GET with PAYMENT-REQUIRED and PAYMENT-SIGNATURE","testedStage":"canonical challenge, buyer authorization, settlement, HTTP 200, and paid content receipt","compatibilityStatus":"compatible","lastVerifiedAt":"2026-07-10T04:12:06.921Z","safeNotes":["Canonical PAYMENT-REQUIRED parsing is verified without payment.","One owner-approved capped $0.10 settlement completed on Base and returned the full ledger with HTTP 200.","The successful settlement is operator indexing QA, not organic inbound revenue.","Use one buyer-approved retry with a 100000 atomic USDC cap for this ledger."],"freshnessStatus":"stale","stale":true,"staleReason":"Not re-verified within 30 days of this edition."},{"id":"awal-2-10-legacy","client":"AWAL CLI","version":"2.10.0","protocol":"x402-v2","network":"eip155:8453","transport":"HTTP x402 command","testedStage":"legacy command and unpaid challenge contract","compatibilityStatus":"legacy_supported","lastVerifiedAt":"2026-07-08T01:30:00.000Z","safeNotes":["Legacy command metadata remains documented for compatibility review.","Refresh to AWAL 2.12.0 before a new paid retry when practical."],"freshnessStatus":"stale","stale":true,"staleReason":"Not re-verified within 30 days of this edition."}],"failureSignatures":[{"code":"RCL-001","stage":"unpaid_challenge_parse","publicSafeSymptom":"The client can inspect the route but rejects the payment-required response as invalid.","rootCauseCategory":"header_body_version_mismatch","affectedClients":["strict x402-v2 clients","body-fallback wallets"],"verifiedMitigation":"Emit x402Version 2 consistently and make paymentRequired/paymentRequirements equal the decoded canonical header.","confidence":"high","firstObservedRelease":"v2.2.185-wallet-body-fallback","lastVerifiedRelease":"v2.2.189-agent-checkout-contract"},{"code":"RCL-002","stage":"unpaid_challenge_parse","publicSafeSymptom":"A strict client sees ambiguous or folded payment-required header values.","rootCauseCategory":"duplicate_or_alternate_payment_headers","affectedClients":["strict x402-v2 clients","proxy-sensitive clients"],"verifiedMitigation":"Emit only PAYMENT-REQUIRED for the challenge and reserve PAYMENT-SIGNATURE/PAYMENT-RESPONSE for retry and receipt.","confidence":"high","firstObservedRelease":"v2.2.185-wallet-body-fallback","lastVerifiedRelease":"v2.2.189-agent-checkout-contract"}],"verifiedFixes":[{"id":"FIX-001","failureCodes":["RCL-001","RCL-002","RCL-010"],"title":"Canonical v2 challenge contract","verifiedAction":"Use PAYMENT-REQUIRED only, keep x402Version 2 in header and body, expose canonical headers through CORS, and omit Set-Cookie.","verificationStage":"Worker contract, local smoke, and live unpaid 402","safeRetryRule":"Parse first; pay only after route, method, network, and amount match buyer policy.","confidence":"high"}]},"previewIsCompleteDataset":false,"storefront":{"job":"Inspect scoped SDK behavior and distinguish it from historical payment/client observations.","input":"No request body; optional allowlisted aggregate source tag only.","price":"$0.10","result":"One deterministic JSON Ledger with offline SDK case findings, historical compatibility/failure records, source digests, limitations and the original evidence window.","oneJob":true,"oneInputContract":true,"oneFixedPrice":true,"oneResult":true},"recommendedPaidTool":{"available":false,"id":null,"operationId":null,"priceUsd":null,"requiredInputs":{},"apiHubService":null,"apiHubTool":null,"directX402Route":null,"reasonCode":"buyer_specific_input_required","reason":"The free preview contains no buyer-specific failure code or previous digest, so it does not recommend a paid operation by default.","automaticPayment":false,"buyerApprovalRequired":true,"autoExecuted":false},"paidResponseIncludes":["Scoped SDK 2.26 findings linked to 39 retained offline cases; seven import checks are not runtime verification.","The complete historical buyer-client compatibility matrix with unchanged observation dates.","Historical public-safe failure signatures, mitigations and retry rules; not re-verified by the new SDK cases.","Historical buyer recipes and command examples, subject to current terms and explicit buyer approval.","Content digest, generatedAt, validUntil, evidence policy, and privacy contract.","Bazaar MCP discovery and buyer-controlled proxy purchase instructions.","Buyer-controlled purchase recipes for Composer/AgentCash, Coinbase Payments MCP, AgentCore with Bazaar MCP, and MPP Tempo."],"excludes":["raw service logs","raw buyer input","full wallet addresses","payment signatures","payment payloads","facilitator secrets","private keys or API keys","unpublished exploit instructions","competitor proprietary data"],"paidRoute":{"method":"GET","path":"/api/agent-commerce-reliability-ledger","url":"https://apexscout.ai/api/agent-commerce-reliability-ledger","sourceTag":null,"priceUsd":"0.10","displayPrice":"$0.10","amountAtomicUsdc":"100000","network":"eip155:8453","scheme":"exact","rail":"Base mainnet x402","canonicalPaymentProtocol":"x402","paymentProtocols":[{"protocol":"x402","network":"eip155:8453","rail":"Base mainnet x402","challengeHeader":"PAYMENT-REQUIRED","receiptHeader":"PAYMENT-RESPONSE"},{"protocol":"mpp","method":"tempo","intent":"charge","network":"eip155:4217","rail":"Tempo mainnet MPP","currency":"0x20C000000000000000000000b9537d11c60E8b50","challengeHeader":"WWW-Authenticate","credentialHeader":"Authorization: Payment","receiptHeader":"Payment-Receipt","durableReplayProtection":true}],"requestBodyRequired":false,"expectedUnpaidStatus":402,"expectedPaidStatus":200,"buyerControlledPaymentOnly":true,"paymentIdentifier":{"supported":true,"required":false,"requestFingerprintBound":true,"duplicatePaymentProcessingPrevented":true,"cacheTtlSeconds":86400,"expiryPolicy":"After the cache TTL expires, the identifier may be processed as a new request and therefore requires fresh explicit buyer approval."}},"verifiableBuyerPolicy":{"schemaVersion":"1.0","autoSpend":false,"explicitApprovalRequired":true,"offerVerificationRequired":true,"termsHashVerificationRequired":true,"receiptVerificationRequired":true,"paymentIdentifierPreferred":true,"maxPaidCallsPerTask":1,"stages":["Fetch the commerce-trust manifest.","Fetch the legal-context manifest.","Verify the exact terms bytes against the Agentic Transaction Receipt hash.","Request the paid route without payment.","Verify the signed offer and its payment-choice binding.","Confirm the route, method, amount, network, recipient, Builder Code policy, and maximum spend.","Generate and retain a Payment-Identifier when the route supports it.","Ask for explicit buyer approval.","Pay at most once.","Require HTTP 200, a valid signed receipt, the same terms hash, and the delivered content digest.","Stop on any mismatch."],"decisionOrder":["Inspect every advertised payment choice before selecting one.","Verify method, resource URL, scheme, network, asset, amount, recipient, and expiry against buyer policy.","Verify the signed offer and its signing identity when the route declares one.","Verify the exact terms bytes against the advertised Agentic Transaction Receipt hash.","Require direct buyer approval before one capped payment retry.","Treat HTTP 402, verification failure, or settlement failure as unpaid.","Treat HTTP 200 as paid delivery only when PAYMENT-RESPONSE evidence and the signed receipt policy validate."],"stopConditions":["A payment choice differs from the buyer's approved method, network, asset, amount, recipient, or resource.","The signed offer is missing, invalid, expired, or bound to a different payment choice.","The exact terms bytes do not match the advertised hash.","The buyer did not explicitly approve the retry.","A second automatic paid retry would be required."],"compatibility":{"paymentIdentifierOptional":true,"olderClientsRemainSupported":true,"siwxRequired":false},"evidenceBoundary":{"signedOfferIsNotSettlementProof":true,"signedReceiptIsIssuedOnlyAfterLegitimatePaidHttp200":true,"builderCodeDeclarationIsNotAttributedSettlementProof":true,"legalContextHashIsNotLegalAdviceOrGuaranteedEnforceability":true},"privacy":{"aggregateOnlyPublicMetrics":true,"buyerIdentityPublic":false,"rawPaymentPayloadPublic":false,"rawTransactionDataPublic":false}},"sourceAttribution":{"previewSourceTag":null,"paidSourceTag":null,"aggregateOnly":true,"buyerLevelDataStored":false,"monitorProbeCreatesRuntimeInterest":false},"mcp":{"toolName":"apexscout_agent_commerce_reliability_ledger","status":"external-catalog-visibility-unverified","purchaseAvailable":null,"currentExternalCatalogVisibility":"unverified","bazaarMcpServer":"https://api.cdp.coinbase.com/platform/v2/x402/discovery/mcp","bazaarMcpBuyerRecipe":{"searchQueries":["agent commerce reliability data","x402 buyer compatibility","agent payment failure signatures","x402 remediation guidance","payment-to-outcome verification","payment delivery evidence"],"searchTool":"search_resources","purchaseTool":"proxy_tool_call","buyerControlledPayment":true,"apexScoutPaysForBuyer":false,"paidCompletionDefinition":"settled buyer-controlled payment followed by full Ledger delivery","purchaseAvailable":null,"purchaseAvailability":"unverified","currentExternalCatalogVisibility":"unverified","availabilityReason":"Current Bazaar listing and proxy purchase are unverified. Fresh Ledger evidence does not verify an external listing.","directResource":"https://apexscout.ai/api/agent-commerce-reliability-ledger"},"directApexScoutRemoteMcpActive":false,"remotePaidToolRuntimeActive":false,"note":"Current Bazaar listing and proxy purchase are unverified. If search returns this exact Ledger URL, verify its terms before using your own buyer client. Otherwise use the direct HTTP route below. ApexScout does not claim a separate direct remote paid MCP runtime."},"bazaarMcpBuyerRecipe":{"searchQueries":["agent commerce reliability data","x402 buyer compatibility","agent payment failure signatures","x402 remediation guidance","payment-to-outcome verification","payment delivery evidence"],"searchTool":"search_resources","purchaseTool":"proxy_tool_call","buyerControlledPayment":true,"apexScoutPaysForBuyer":false,"paidCompletionDefinition":"settled buyer-controlled payment followed by full Ledger delivery","purchaseAvailable":null,"purchaseAvailability":"unverified","currentExternalCatalogVisibility":"unverified","availabilityReason":"Current Bazaar listing and proxy purchase are unverified. Fresh Ledger evidence does not verify an external listing.","directResource":"https://apexscout.ai/api/agent-commerce-reliability-ledger"},"mppMarketplaceBuyerRecipe":{"id":"mpp-native-ledger-purchase","status":"prepared-pending-owner-controlled-directory-publication","discoverySources":["MPPScan","mpp.dev"],"steps":["Discover ApexScout through MPPScan or the mpp.dev catalog after an owner-controlled listing is public; until then use the canonical ApexScout preview and docs.","Inspect GET /api/agent-commerce-reliability-ledger and confirm the fixed $0.10 charge.","Verify tempo/charge, Tempo eip155:4217, 100000 atomic USDC, recipient, issuedAt, and expiresAt from the live challenge.","Confirm the current Ledger edition and content digest on the free preview.","Ask for explicit buyer approval for one $0.10 call.","Pay once with the buyer's own MPP client. ApexScout never operates the buyer wallet.","Require Payment-Receipt, HTTP 200, and the complete Ledger delivery.","Stop after delivery or any mismatch, expiry, rejection, or incomplete response; never pay or retry automatically."],"expiryRule":"If the Commerce Intent expires before payment begins, fetch one fresh unpaid challenge without a payment credential, verify identical terms, and ask for fresh approval. The refresh is stateless and a settled intent can never refresh into another charge.","maximumPaidCalls":1,"apexScoutOperatesBuyerWallet":false,"externalListingClaimed":false,"purchaseAvailable":true,"availabilityReason":"The scoped offline SDK findings remain inside their declared validity window. Historical buyer-client and payment records were not re-verified."},"buyerRuntimeRecipes":[{"id":"RUNTIME-A","runtime":"x402scan Composer / AgentCash","sourceTags":["x402scan-composer","x402scan-composer-preview","x402scan-composer-ledger","agentcash-skill","agentcash-skill-preview","agentcash-skill-ledger"],"discover":["Use Composer resource search or `npx -y agentcash@latest discover https://apexscout.ai`.","Read GET /api/agent-commerce-reliability-ledger/preview with src=x402scan-composer-preview or src=agentcash-skill-preview before considering payment."],"inspectPrice":["Run `npx -y agentcash@latest check https://apexscout.ai/api/agent-commerce-reliability-ledger` or inspect the Composer resource price.","Require GET, 0.10 USD, Base eip155:8453, and no request body."],"setMaximumSpend":["Set or retain a buyer-controlled maximum of $0.10 / 100000 atomic USDC for this task.","Allow at most one paid Ledger call for the task."],"approval":["Explain what the full Ledger adds beyond the preview.","Ask the buyer to explicitly approve the exact route, $0.10 amount, Base network, and single call."],"purchaseOnce":["Only after approval, call GET /api/agent-commerce-reliability-ledger once with src=x402scan-composer-ledger or src=agentcash-skill-ledger.","Do not retry automatically after any failure or HTTP 402."],"verifyDelivery":["Require HTTP 200 and the complete Ledger fields: edition delta, compatibility matrix, failure signatures, verified fixes, generatedAt, validUntil, and contentDigest.","Treat HTTP 402, search, preview, or resource selection as unpaid interest rather than revenue."],"stop":["Stop after one paid call, any rejection, a price or network mismatch, missing approval, or incomplete delivery.","Never request wallet secrets, private keys, seed phrases, signatures, or raw payment payloads."],"verifiableBuyerPolicy":{"schemaVersion":"1.0","autoSpend":false,"explicitApprovalRequired":true,"offerVerificationRequired":true,"termsHashVerificationRequired":true,"receiptVerificationRequired":true,"paymentIdentifierPreferred":true,"maxPaidCallsPerTask":1,"stages":["Fetch the commerce-trust manifest.","Fetch the legal-context manifest.","Verify the exact terms bytes against the Agentic Transaction Receipt hash.","Request the paid route without payment.","Verify the signed offer and its payment-choice binding.","Confirm the route, method, amount, network, recipient, Builder Code policy, and maximum spend.","Generate and retain a Payment-Identifier when the route supports it.","Ask for explicit buyer approval.","Pay at most once.","Require HTTP 200, a valid signed receipt, the same terms hash, and the delivered content digest.","Stop on any mismatch."],"decisionOrder":["Inspect every advertised payment choice before selecting one.","Verify method, resource URL, scheme, network, asset, amount, recipient, and expiry against buyer policy.","Verify the signed offer and its signing identity when the route declares one.","Verify the exact terms bytes against the advertised Agentic Transaction Receipt hash.","Require direct buyer approval before one capped payment retry.","Treat HTTP 402, verification failure, or settlement failure as unpaid.","Treat HTTP 200 as paid delivery only when PAYMENT-RESPONSE evidence and the signed receipt policy validate."],"stopConditions":["A payment choice differs from the buyer's approved method, network, asset, amount, recipient, or resource.","The signed offer is missing, invalid, expired, or bound to a different payment choice.","The exact terms bytes do not match the advertised hash.","The buyer did not explicitly approve the retry.","A second automatic paid retry would be required."],"compatibility":{"paymentIdentifierOptional":true,"olderClientsRemainSupported":true,"siwxRequired":false},"evidenceBoundary":{"signedOfferIsNotSettlementProof":true,"signedReceiptIsIssuedOnlyAfterLegitimatePaidHttp200":true,"builderCodeDeclarationIsNotAttributedSettlementProof":true,"legalContextHashIsNotLegalAdviceOrGuaranteedEnforceability":true},"privacy":{"aggregateOnlyPublicMetrics":true,"buyerIdentityPublic":false,"rawPaymentPayloadPublic":false,"rawTransactionDataPublic":false}},"apexScoutOperatesBuyerWallet":false},{"id":"RUNTIME-B","runtime":"Coinbase Agentic Wallet Payments MCP","sourceTags":["coinbase-payments-mcp"],"discover":["Install the official buyer runtime with `npx @coinbase/payments-mcp` and use its service discovery against apexscout.ai.","Read the free preview first at /api/agent-commerce-reliability-ledger/preview?src=coinbase-payments-mcp."],"inspectPrice":["Inspect the discovered Ledger contract and require GET, 0.10 USD, Base eip155:8453, and no request body.","Do not treat wallet funding, service discovery, or HTTP 402 as a purchase."],"setMaximumSpend":["In the buyer wallet UI, set max per call to $0.10 and keep the task/session allowance limited to one Ledger call.","The buyer, not ApexScout, controls wallet sign-in, funding, and limits."],"approval":["Show the route, price, network, freshness window, and one-call maximum.","Ask for explicit buyer approval before the MCP runtime is allowed to pay."],"purchaseOnce":["After approval, instruct Payments MCP to fetch /api/agent-commerce-reliability-ledger?src=coinbase-payments-mcp once.","Do not ask the runtime to retry automatically."],"verifyDelivery":["Require HTTP 200, a paid response receipt, the complete Ledger arrays, generatedAt, validUntil, and contentDigest.","Reject a response that remains HTTP 402 or omits the full paid dataset boundary."],"stop":["Stop after one paid call or any mismatch, rejection, or incomplete response.","Never paste email OTPs, wallet secrets, private keys, or payment payloads into ApexScout."],"verifiableBuyerPolicy":{"schemaVersion":"1.0","autoSpend":false,"explicitApprovalRequired":true,"offerVerificationRequired":true,"termsHashVerificationRequired":true,"receiptVerificationRequired":true,"paymentIdentifierPreferred":true,"maxPaidCallsPerTask":1,"stages":["Fetch the commerce-trust manifest.","Fetch the legal-context manifest.","Verify the exact terms bytes against the Agentic Transaction Receipt hash.","Request the paid route without payment.","Verify the signed offer and its payment-choice binding.","Confirm the route, method, amount, network, recipient, Builder Code policy, and maximum spend.","Generate and retain a Payment-Identifier when the route supports it.","Ask for explicit buyer approval.","Pay at most once.","Require HTTP 200, a valid signed receipt, the same terms hash, and the delivered content digest.","Stop on any mismatch."],"decisionOrder":["Inspect every advertised payment choice before selecting one.","Verify method, resource URL, scheme, network, asset, amount, recipient, and expiry against buyer policy.","Verify the signed offer and its signing identity when the route declares one.","Verify the exact terms bytes against the advertised Agentic Transaction Receipt hash.","Require direct buyer approval before one capped payment retry.","Treat HTTP 402, verification failure, or settlement failure as unpaid.","Treat HTTP 200 as paid delivery only when PAYMENT-RESPONSE evidence and the signed receipt policy validate."],"stopConditions":["A payment choice differs from the buyer's approved method, network, asset, amount, recipient, or resource.","The signed offer is missing, invalid, expired, or bound to a different payment choice.","The exact terms bytes do not match the advertised hash.","The buyer did not explicitly approve the retry.","A second automatic paid retry would be required."],"compatibility":{"paymentIdentifierOptional":true,"olderClientsRemainSupported":true,"siwxRequired":false},"evidenceBoundary":{"signedOfferIsNotSettlementProof":true,"signedReceiptIsIssuedOnlyAfterLegitimatePaidHttp200":true,"builderCodeDeclarationIsNotAttributedSettlementProof":true,"legalContextHashIsNotLegalAdviceOrGuaranteedEnforceability":true},"privacy":{"aggregateOnlyPublicMetrics":true,"buyerIdentityPublic":false,"rawPaymentPayloadPublic":false,"rawTransactionDataPublic":false}},"apexScoutOperatesBuyerWallet":false},{"id":"RUNTIME-C","runtime":"AWS AgentCore Gateway with Coinbase Bazaar MCP","sourceTags":["agentcore-bazaar"],"discover":["Add the official Coinbase Bazaar MCP target https://api.cdp.coinbase.com/platform/v2/x402/discovery/mcp to an owner-controlled AgentCore Gateway with no outbound authorization.","Search for ApexScout Agent Commerce Reliability Ledger, then read the free preview with src=agentcore-bazaar."],"inspectPrice":["Inspect the Bazaar result and runtime challenge; require GET, 0.10 USD / 100000 atomic USDC, and Base eip155:8453.","Do not select a similarly named resource or a route with different terms."],"setMaximumSpend":["Configure the owner-controlled AgentCore payment policy for a maximum $0.10 single call and one call for the task.","Do not enable an unbounded PaymentManager session."],"approval":["Show the exact selected resource, amount, network, and one-call policy.","Require explicit buyer or operator approval before the payment plugin handles the 402."],"purchaseOnce":["After approval, invoke the selected Ledger tool once through the Gateway using src=agentcore-bazaar when the runtime permits the query tag.","Do not issue a second tool call to repair telemetry or indexing."],"verifyDelivery":["Require successful tool delivery containing the complete Ledger, generatedAt, validUntil, and contentDigest.","Count a paid completion only after buyer-controlled settlement and full HTTP 200/tool delivery."],"stop":["Stop after one paid call, any policy denial, resource mismatch, 402 loop, or incomplete delivery.","ApexScout never receives the buyer's AgentCore credentials, payment instrument, or wallet secrets."],"verifiableBuyerPolicy":{"schemaVersion":"1.0","autoSpend":false,"explicitApprovalRequired":true,"offerVerificationRequired":true,"termsHashVerificationRequired":true,"receiptVerificationRequired":true,"paymentIdentifierPreferred":true,"maxPaidCallsPerTask":1,"stages":["Fetch the commerce-trust manifest.","Fetch the legal-context manifest.","Verify the exact terms bytes against the Agentic Transaction Receipt hash.","Request the paid route without payment.","Verify the signed offer and its payment-choice binding.","Confirm the route, method, amount, network, recipient, Builder Code policy, and maximum spend.","Generate and retain a Payment-Identifier when the route supports it.","Ask for explicit buyer approval.","Pay at most once.","Require HTTP 200, a valid signed receipt, the same terms hash, and the delivered content digest.","Stop on any mismatch."],"decisionOrder":["Inspect every advertised payment choice before selecting one.","Verify method, resource URL, scheme, network, asset, amount, recipient, and expiry against buyer policy.","Verify the signed offer and its signing identity when the route declares one.","Verify the exact terms bytes against the advertised Agentic Transaction Receipt hash.","Require direct buyer approval before one capped payment retry.","Treat HTTP 402, verification failure, or settlement failure as unpaid.","Treat HTTP 200 as paid delivery only when PAYMENT-RESPONSE evidence and the signed receipt policy validate."],"stopConditions":["A payment choice differs from the buyer's approved method, network, asset, amount, recipient, or resource.","The signed offer is missing, invalid, expired, or bound to a different payment choice.","The exact terms bytes do not match the advertised hash.","The buyer did not explicitly approve the retry.","A second automatic paid retry would be required."],"compatibility":{"paymentIdentifierOptional":true,"olderClientsRemainSupported":true,"siwxRequired":false},"evidenceBoundary":{"signedOfferIsNotSettlementProof":true,"signedReceiptIsIssuedOnlyAfterLegitimatePaidHttp200":true,"builderCodeDeclarationIsNotAttributedSettlementProof":true,"legalContextHashIsNotLegalAdviceOrGuaranteedEnforceability":true},"privacy":{"aggregateOnlyPublicMetrics":true,"buyerIdentityPublic":false,"rawPaymentPayloadPublic":false,"rawTransactionDataPublic":false}},"apexScoutOperatesBuyerWallet":false},{"id":"RUNTIME-D","runtime":"MPP Tempo buyer","sourceTags":["mpp-tempo"],"discover":["Read the free preview, then fetch the Ledger route without a credential and parse its WWW-Authenticate Payment challenge.","Use src=mpp-tempo only as an aggregate protocol source tag; it does not identify the buyer."],"inspectPrice":["Require tempo/charge, 0.10 USD / 100000 atomic USDC, Tempo eip155:4217, and no request body.","Read the recipient and expiry from the signed MPP challenge instead of static page copy."],"setMaximumSpend":["Keep the buyer-controlled maximum at $0.10 and allow one Ledger call for the task.","Do not reuse a credential or bypass the atomic replay guard."],"approval":["Show the exact Ledger route, amount, Tempo network, recipient, and one-call limit.","Require explicit buyer approval before creating the Payment credential."],"purchaseOnce":["After approval, retry GET /api/agent-commerce-reliability-ledger?src=mpp-tempo once with Authorization: Payment.","Do not retry after rejection, timeout, or incomplete delivery."],"verifyDelivery":["Require HTTP 200, Payment-Receipt, the complete Ledger arrays, generatedAt, validUntil, and contentDigest.","Treat the unpaid challenge as discovery and not as revenue."],"stop":["Stop after one paid call or any route, amount, network, recipient, expiry, or delivery mismatch.","Never send the MPP credential to the origin or expose it on aggregate surfaces."],"verifiableBuyerPolicy":{"schemaVersion":"1.0","autoSpend":false,"explicitApprovalRequired":true,"offerVerificationRequired":true,"termsHashVerificationRequired":true,"receiptVerificationRequired":true,"paymentIdentifierPreferred":true,"maxPaidCallsPerTask":1,"stages":["Fetch the commerce-trust manifest.","Fetch the legal-context manifest.","Verify the exact terms bytes against the Agentic Transaction Receipt hash.","Request the paid route without payment.","Verify the signed offer and its payment-choice binding.","Confirm the route, method, amount, network, recipient, Builder Code policy, and maximum spend.","Generate and retain a Payment-Identifier when the route supports it.","Ask for explicit buyer approval.","Pay at most once.","Require HTTP 200, a valid signed receipt, the same terms hash, and the delivered content digest.","Stop on any mismatch."],"decisionOrder":["Inspect every advertised payment choice before selecting one.","Verify method, resource URL, scheme, network, asset, amount, recipient, and expiry against buyer policy.","Verify the signed offer and its signing identity when the route declares one.","Verify the exact terms bytes against the advertised Agentic Transaction Receipt hash.","Require direct buyer approval before one capped payment retry.","Treat HTTP 402, verification failure, or settlement failure as unpaid.","Treat HTTP 200 as paid delivery only when PAYMENT-RESPONSE evidence and the signed receipt policy validate."],"stopConditions":["A payment choice differs from the buyer's approved method, network, asset, amount, recipient, or resource.","The signed offer is missing, invalid, expired, or bound to a different payment choice.","The exact terms bytes do not match the advertised hash.","The buyer did not explicitly approve the retry.","A second automatic paid retry would be required."],"compatibility":{"paymentIdentifierOptional":true,"olderClientsRemainSupported":true,"siwxRequired":false},"evidenceBoundary":{"signedOfferIsNotSettlementProof":true,"signedReceiptIsIssuedOnlyAfterLegitimatePaidHttp200":true,"builderCodeDeclarationIsNotAttributedSettlementProof":true,"legalContextHashIsNotLegalAdviceOrGuaranteedEnforceability":true},"privacy":{"aggregateOnlyPublicMetrics":true,"buyerIdentityPublic":false,"rawPaymentPayloadPublic":false,"rawTransactionDataPublic":false}},"apexScoutOperatesBuyerWallet":false},{"id":"RUNTIME-E","runtime":"Solana Agent Registry","sourceTags":["solana-agent-registry"],"discover":["Resolve the finalized ApexScout onchain identity, then read the public Registry metadata and free Commerce Explorer with src=solana-agent-registry.","Read the free Ledger preview with src=solana-agent-registry before considering the paid route."],"inspectPrice":["Require the existing GET Ledger route, paymentNetwork=solana, exact scheme, 0.10 USD / 100000 atomic USDC, Solana mainnet, and the published USDC mint.","Confirm the Registry identity proof and seller recipient from public metadata without requesting a wallet secret."],"setMaximumSpend":["Keep the buyer-controlled maximum at $0.10 and permit one Ledger call for the task.","A Registry entry, metadata read, preview, or HTTP 402 is not purchase approval."],"approval":["Show the exact route, Solana network, recipient, amount, edition digest, and one-call maximum.","Ask the buyer to explicitly approve the selected Solana Ledger call."],"purchaseOnce":["Only after approval, call GET /api/agent-commerce-reliability-ledger?paymentNetwork=solana&src=solana-agent-registry once with the buyer-controlled wallet.","Never pay or retry automatically."],"verifyDelivery":["Require buyer-controlled settlement, HTTP 200, a protocol-native receipt, and the complete Ledger with generatedAt, validUntil, and contentDigest.","Keep the onchain identity transaction separate from a paid Ledger completion."],"stop":["Stop after one paid call or any identity, route, price, network, asset, recipient, expiry, receipt, or delivery mismatch.","Never request private keys, seed phrases, wallet exports, signatures, or raw payment payloads."],"verifiableBuyerPolicy":{"schemaVersion":"1.0","autoSpend":false,"explicitApprovalRequired":true,"offerVerificationRequired":true,"termsHashVerificationRequired":true,"receiptVerificationRequired":true,"paymentIdentifierPreferred":true,"maxPaidCallsPerTask":1,"stages":["Fetch the commerce-trust manifest.","Fetch the legal-context manifest.","Verify the exact terms bytes against the Agentic Transaction Receipt hash.","Request the paid route without payment.","Verify the signed offer and its payment-choice binding.","Confirm the route, method, amount, network, recipient, Builder Code policy, and maximum spend.","Generate and retain a Payment-Identifier when the route supports it.","Ask for explicit buyer approval.","Pay at most once.","Require HTTP 200, a valid signed receipt, the same terms hash, and the delivered content digest.","Stop on any mismatch."],"decisionOrder":["Inspect every advertised payment choice before selecting one.","Verify method, resource URL, scheme, network, asset, amount, recipient, and expiry against buyer policy.","Verify the signed offer and its signing identity when the route declares one.","Verify the exact terms bytes against the advertised Agentic Transaction Receipt hash.","Require direct buyer approval before one capped payment retry.","Treat HTTP 402, verification failure, or settlement failure as unpaid.","Treat HTTP 200 as paid delivery only when PAYMENT-RESPONSE evidence and the signed receipt policy validate."],"stopConditions":["A payment choice differs from the buyer's approved method, network, asset, amount, recipient, or resource.","The signed offer is missing, invalid, expired, or bound to a different payment choice.","The exact terms bytes do not match the advertised hash.","The buyer did not explicitly approve the retry.","A second automatic paid retry would be required."],"compatibility":{"paymentIdentifierOptional":true,"olderClientsRemainSupported":true,"siwxRequired":false},"evidenceBoundary":{"signedOfferIsNotSettlementProof":true,"signedReceiptIsIssuedOnlyAfterLegitimatePaidHttp200":true,"builderCodeDeclarationIsNotAttributedSettlementProof":true,"legalContextHashIsNotLegalAdviceOrGuaranteedEnforceability":true},"privacy":{"aggregateOnlyPublicMetrics":true,"buyerIdentityPublic":false,"rawPaymentPayloadPublic":false,"rawTransactionDataPublic":false}},"apexScoutOperatesBuyerWallet":false}],"noSpend":{"previewIsFree":true,"previewCallsPaidRoute":false,"previewCreatesPaymentAttempt":false,"previewCreatesPaidCompletion":false,"paidUpstreamCalls":false,"automaticPayment":false},"privacy":{"aggregateOnlyMetrics":true,"buyerLevelDataExposed":false,"rawBuyerInputExposed":false,"rawLogsExposed":false,"rawUserAgentsExposed":false,"ipAddressesExposed":false,"fullWalletAddressesExposed":false,"paymentSignaturesExposed":false,"rawPaymentPayloadsExposed":false,"secretsExposed":false,"requestBodyRequired":false,"accountRequired":false,"apiKeyRequired":false},"claims":{"guaranteedRevenueClaimed":false,"officialEndorsementClaimed":false,"adviceProvided":false}}