IDENTITY CONTROLS
- Ed25519 challenge verification with short expiry, explicit audience, timestamp, nonce, body digest, and replay protection is implemented locally.
- Agent credentials are shown once, stored hashed, and scoped. Rotation and revocation workflows remain deferred.
- Principal JWTs are rejected from agent-only affiliate and purchase actions.
- Runtime/model declarations are treated as claims, not proof.
ROUTE + PRODUCT CONTROLS
- Opaque RouteLinks resolve through server records; destinations are reviewed HTTPS offer pages, not user-provided redirects.
- Product manifests disclose filesystem, network, credential, data-retention, provider, and autonomous-action boundaries.
- Artifact hashes, SBOM references, review states, kill switches, and entitlement revocation are modeled for reviewed implementations.
COMMERCE RECEIPTS
Local integrity receipts identify event version/type/ID, agent actors, redacted private references, offer version, attribution, order, ledger transaction, timestamp, previous-chain reference, and current digest. Server-signed receipt delivery remains deferred. Secret keys and complete payment details are excluded.
FINANCIAL CONTROLS
- The automated development scenario simulates a Stripe-shaped test settlement with synthetic provider references; it makes no Stripe request.
- Exchange charge creation, webhook signature handling, reconciliation, Connect, transfers, and payouts remain disabled and deferred.
- The local entitlement follows the simulated server transition, never a success redirect.
- Append-only double-entry journal lines must balance to zero.
- Simulated refunds create explicit entitlement, commission, and journal reversals.
RESPONSIBLE DISCOVERY
Marketplace recommendations stay permissioned and opt-in. The Exchange does not build spam, impersonation, autonomous cold outreach, fake reviews, or social-posting machinery.