In your post introducing the Trusted Agentic Commerce Protocol you wrote: “But this promise can only be realized on a foundation of verifiable trust.” That sentence is the reason this page exists, and it is worth taking literally.
TACP does what it says. It heavily discounts identity signals that have been fundamentally broken for decades, such as spoofable User-Agent strings and shared IP addresses, and replaces them with JSON Web Encryption under RFC 7516. The protocol states five guarantees: the data was generated by the agent, has not been altered in transit, is fresh and not a replay, is encrypted end to end, and is decrypted only by the intended recipients.
Read those five again. Every one is a property of the envelope. That is not a flaw, it is what an encryption standard is built to provide. But the schema carries session.intent, session.consent and session.signals, and the protocol deliberately does not enforce a schema. Those fields are authored by the agent. A perfectly valid envelope and a false consent field are entirely compatible, and no amount of cryptographic certainty about transport changes that.
Verifiable trust needs a second layer that operates on the claim rather than the channel. Eight receipt types below, twenty one live runs against the open verify route. Every one of them comes back valid true. The refusing cases live on the other pages in this set, and the same routes will refuse these bodies the moment a field is edited.
This is not a competing protocol and it is not a criticism of TACP. Authenticating agents in digital commerce is a real problem and an open standard is the right shape for the answer. Nothing here replaces the channel layer, and nothing here works without one.
These receipts sit above the transport. TACP establishes that a message genuinely came from a given agent, unaltered and fresh. A receipt establishes what was true before the agent acted, in a form a third party can recompute without access to either endpoint.
Nothing on this page is a legal determination. No receipt assigns liability, damages or negligence. Each states its own boundary in plain words on the page, because an instrument that overclaims fails the first time somebody tests it seriously.
The receipts are transport agnostic on purpose. If TACP becomes the standard, these ride inside it. If something else wins, they ride inside that. The commitment is to the claim layer, not to a wire format.
Each row is a real property of TACP as documented, followed by the question it deliberately leaves to another layer.
TACP’s five stated guarantees are that the data was generated by the agent, has not been altered in transit, is fresh and not a replay, is encrypted end to end, and is decrypted only by the intended recipients. Every one of those is true and every one is about the envelope.
That is precisely what an encryption standard is for. It authenticates the sender and protects the payload. It is silent, by design, on whether a field the sender authored is true.
The channel is solved. The claim inside it is not.
session.consent sits in a schema the protocol deliberately does not enforce, alongside session.intent and session.signals. The agent writes those fields. A valid envelope carrying a false consent field is not a protocol failure, it is the expected behaviour of any channel guarantee.
intent.affirmation commits what was shown to the human and what was sent to the merchant as two separate artifacts, then recomputes whether they match.
Consent stops being a field and becomes a comparison.
Authenticating the agent’s relationship to the consumer behind it settles one link. Real flows have several, and authority is supposed to shrink at each one. Nothing in an authenticated message says it did.
delegation.attenuation proves authority narrowed at every hop, and authority.qualification proves the party at the top of the chain held what it handed down.
The whole chain is checkable, not just the last hop.
You wrote that disintermediation can lead to a rapid loss of control and revenue. The loss of control shows up most expensively after something goes wrong, when merchant vendors, payment providers and support systems each bring records only they can read.
fault.attribution derives whose committed constraint was broken, including the honest finding that none was, and every receipt states its own limits on its face.
Files close instead of escalating.
TACP carries session.consent. JSON Web Encryption proves that field was generated by the agent, was not altered in transit, is fresh and not a replay, and can only be read by the intended recipients. All five of those are properties of the envelope. None of them is a statement about whether the consent happened.
This is not a gap in JWE. RFC 7516 does exactly what it says and does it well. It is a channel guarantee, and a channel guarantee is silent on the truthfulness of a field the sender authored. session.consent is authored by the agent, so a perfectly valid envelope and a false consent field are entirely compatible.
intent.affirmation commits two artifacts instead of one. PRESENTED_ARTIFACT_INTEGRITY holds the thing shown to the human, TRANSMITTED_ARTIFACT_INTEGRITY holds the thing sent to the merchant, and ARTIFACT_EQUALITY_RECOMPUTE derives whether they are the same. That comparison is the one an authenticated channel cannot make for you.
AFFIRMATION_ORDERING_RECOMPUTE puts the affirmation before the action rather than alongside it, and CHANNEL_CLASS_DECLARED records whether the person was on a screen, on a call, or in a thread. NO_AFFIRMATION_CONTENT_LEAK keeps the affirmed text out of the receipt entirely.
What it does not prove, in plain words. It does not say the person understood, agreed, had capacity, or was who they claimed to be, and it does not reproduce what they affirmed. It attests that a committed artifact was presented on a declared channel before the action, and whether it matched what was transmitted.
Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.
Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.
Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.
Your own post sets the two examples side by side. Find me reliable running shoes, and buy Nike Air Jordan Retro shoes under two hundred dollars. TACP has a session.intent field that will happily carry either one, because the protocol deliberately does not enforce a schema. Only one of those sentences can ever be enforced or disputed.
PREDICATE_CLASSIFICATION_RECOMPUTE and VERIFIABILITY_CLASS_RECOMPUTE derive the class from the predicates in the instruction rather than reading a label somebody attached. RULESET_PRECEDENCE requires the classification ruleset to have been committed before the assessment, which is what stops an instruction being reclassified as subjective after it turns out to have been breached.
Four honest classes. Checkable, partial, subjective, unclassified. Landing on subjective is a real and useful answer. It tells a merchant, before the order ships, that there is nothing here to enforce, which is a far better position than discovering it during a dispute.
INTENT_REF_INTEGRITY binds the assessment to a specific committed intent, and NO_INTENT_CONTENT_LEAK keeps the text of the shopper’s instruction out of the artifact. You can prove an instruction was unenforceable without republishing what the person asked for.
What it does not prove, in plain words. It does not say the intent was genuine, authorised, lawful or well formed, and it does not interpret what the person wanted. It attests to how a stated intent classifies under a ruleset committed before the assessment.
Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.
Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.
Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.
Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.
TACP’s first goal is that the parties authenticate each other and verify the agent’s relationship to the consumer behind it. Authentication settles who is talking. It does not settle how much authority came down the chain to get there, and in practice the chain has more than one hop.
Four gates carry it. ATTENUATION_CEILING_NONINCREASING stops a spend ceiling rising downstream. ATTENUATION_CATEGORY_SUBSET stops new categories appearing at a hand-off. ATTENUATION_EXPIRY_NONEXTENDING stops a child credential outliving its parent. ATTENUATION_DEPTH_STRICT_DECREASING stops the chain folding back on itself.
CHAIN_CONTINUITY and ROOT_AUTHORITY_BINDING tie every link back to the original grant. ACTION_CEILING_WITHIN_FINAL_LINK checks the purchase against the last link rather than the first, which is where widening normally hides, because the root grant usually looks generous enough to cover anything.
The whole chain is checkable by a party who was present at none of the hops. That is the property that matters when an assistant hands off to a shopping agent that hands off to a checkout agent, and only the last one ever speaks to the merchant.
What it does not prove, in plain words. It does not say the original authority was valid, informed or lawfully obtained, and it does not say the agents behaved well. It attests that authority did not widen at any hop and that the action fell inside the final link.
Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.
A protocol built on public key encryption is a protocol built on a directory. Every party has to look up the counterparty’s key. Keys rotate, get revoked, and occasionally were never there. Nothing in an encrypted envelope tells you what the directory said at the moment you asked.
QUERIED_KEY_COMMITMENT_BINDING binds the receipt to the exact key identifier that was looked up, and PRESENCE_VERDICT_RECOMPUTE derives whether it was present, absent or rotated instead of accepting a stated answer. Three real outcomes, and rotated is the one that causes arguments.
KEY_IDENTIFIER_SET_INTEGRITY, KEY_IDENTIFIER_SET_DIGEST_RECOMPUTE and CONTENT_KEY_SET_AGREEMENT hold the returned set together, so the observation cannot be trimmed after the fact. OBSERVATION_INSTANT_ORDERED and DRIFT_BOUND_SATISFIED fix when the lookup happened and cap how far the clocks can be apart before that ordering stops meaning anything.
NO_DIRECTORY_CONTENT_LEAK is what makes this shareable. You can prove a key was absent at 14:02 without publishing the rest of the directory, which matters when the directory is a competitive asset and the counterparty is asking to see it.
What it does not prove, in plain words. It does not say the key was trustworthy, correctly issued or properly controlled, and it does not publish the directory. It attests to what a named directory returned for a committed query at a stated instant, under a declared observer role.
Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.
Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.
Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.
Every delegation chain has a first link, and the first link is the one nobody checks. The chain can be flawless from top to bottom and still be worthless if the party at the top never held the entitlement it handed down.
ENTITLEMENT_SOURCE_LINK, ENTITLEMENT_SOURCE_INTEGRITY and ENTITLEMENT_SOURCE_TERMS bind the grant to the instrument the entitlement came from. SCOPE_CONTAINMENT and QUANTITY_CONTAINMENT then check that what was handed down fits inside what was held, which is the check that catches a granter giving away more than it had.
QUALIFICATION_PRECEDENCE requires the qualification to exist before the grant, so nobody establishes entitlement retroactively once the delegation is under scrutiny. CLOCK_CONSERVATISM resolves any timing ambiguity against the claim rather than in its favour.
QUALIFICATION_CLASS_CANDOUR is the gate that stops this from being marketing. The receipt has to state its own class honestly, so an unqualified result is a first-class outcome rather than an error, and finding it before the transaction is much cheaper than finding it after.
What it does not prove, in plain words. It does not say the entitlement was lawfully acquired, that the source instrument was valid, or that the delegation was wise. It attests that a root grant fits inside a committed entitlement that existed before the grant.
Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.
Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.
TACP is designed so parties can tell legitimate agentic activity from fraud attempts. That decision is the commercially loaded moment in the flow, and it gets re-examined by whoever loses it. Explaining a decision from an internal score is a weaker position than handing over something that recomputes.
DECISION_BASIS_RECOMPUTE and DECISION_RELATION_RECOMPUTE derive the outcome from committed inputs and require the stated reason to match the constraint that actually fired. CONSTRAINT_EVALUATION_RECOMPUTE re-runs the evaluation rather than trusting the result that came with it.
MANDATE_REF_INTEGRITY, MANDATE_SCOPE_DIGEST_RECOMPUTE and MANDATE_LIVENESS_RECOMPUTE bind the decision to the exact authority in force at that instant. The revoked case covers the situation people fight about most: authority that was live when the call was made and dead by the time anyone looked.
NO_CARDHOLDER_IDENTITY_LEAK means the reasoning travels without the shopper attached, and nothing in the receipt exposes the model or the policy that produced the verdict.
What it does not prove, in plain words. It does not say the decision was correct, fair, or commercially sensible, and it does not reveal the model or the policy. It attests that a stated decision follows from inputs committed before the decision instant.
Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.
Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.
Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.
An agent with a reasonable per-merchant limit and no aggregate limit is not constrained at all. Each merchant sees a small, well-formed, correctly authenticated order. The breach only exists in the sum, and no single merchant is standing where the sum is visible.
CONTRIBUTION_SET_INTEGRITY and CONTRIBUTION_WINDOW_MEMBERSHIP fix which transactions are inside the window before anything is added up. DISTINCT_ACCEPTOR_COUNT_RECOMPUTE and DISPERSION_CLASS_RECOMPUTE derive how far the activity is spread rather than accepting a count that came with the claim.
WINDOW_LINK, WINDOW_PREDECESSOR_INTEGRITY and WINDOW_CONTINUITY chain each window to the one before it. An agent cannot wipe its own history by opening a fresh window, which is the obvious attack once aggregate limits exist at all.
NO_ACCEPTOR_IDENTITY_LEAK is the reason this can be shared across a network. You can prove an agent went over an aggregate cap without disclosing which merchants it hit, so no participant has to expose its own transaction flow to establish the fact.
What it does not prove, in plain words. It does not say the spending was fraudulent, unauthorised or harmful, and it does not identify the acceptors. It attests that a stated cumulative position across distinct acceptors recomputes from a committed contribution set inside a linked window.
Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.
Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.
Your post names the stakeholders honestly: merchant vendors, payment providers, support systems handling cancellations and refunds. When an agentic order goes wrong across that many parties, everyone produces logs and no two sets agree. That argument is expensive whether or not anyone was actually at fault.
ATTRIBUTION_CLASS_RECOMPUTE and ATTRIBUTED_ROLE_RECOMPUTE derive both the shape of the fault and the party from committed artifacts, instead of reading a conclusion someone wrote down. PRECOMMITMENT_PRECEDENCE and VIOLATION_SUBSET_INTEGRITY block the reflex of retrofitting a constraint to fit a loss that already happened.
Three shapes. Single, shared, and hindsight. Hindsight is the finding worth having: a bad outcome where no committed constraint was broken by anyone. Being able to sign that result is what turns an unwinnable multi-party argument into a closed file.
NO_PARTY_IDENTITY_LEAK lets the finding move between parties without naming them, which matters when the counterparty in the dispute is also a participant in the protocol you are trying to standardise.
What it does not prove, in plain words. It does not assign legal liability, damages or negligence, and it is not a legal determination of any kind. It attests to which committed constraints were broken by which named party under the stated procedure.
Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.
Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.
Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.
Every receipt above is deployed, open to verify, and honest about its limits. If the argument holds, the next step is one integration against a route you can already call from a terminal.
Verify a receiptRead the canon
Each link opens that entry in the canon implementation explorer, where its schema, mint route, open verify route, auth requirement and implementation state are stated. The state shown here is read from the same registry file the explorer renders from, so the two cannot drift apart. Nothing here implies a customer, a deployment or an endorsement.