1. Allowed request
Merchant, payee, resource, amount, budget, integrity, and expiry all match.
- Real path may reach the signer boundary.
- Hosted scenario moves no funds.
- Separate real evidence is below.
x402 is the payment rail. AgentPay Guard is the authorization layer.
An autonomous due-diligence agent buys premium data for a tokenized parking asset without giving the model unrestricted wallet control.
Merchant, payee, resource, amount, budget, integrity, and expiry all match.
A malicious instruction attempts to substitute the payee or escalate the amount.
PAYEE_MISMATCHA consumed transaction cannot authorize a different or repeated request.
NONCE_ALREADY_USEDOne real policy-authorized native-CSPR payment. Premium data was released only after independent Casper RPC verification.
Signing ran locally with a dedicated Testnet key. The hosted Vercel app never loads private keys or initiates spending. The Odra proof recorder is a separate existing on-chain proof path.
A project-owned MCP server built with the official Model Context Protocol SDK invokes the same normalization, policy, x402 retry, and PAYMENT-RESPONSE verification used by the product. Its injected adapter is deterministic and no-spend.
agentpay_run_rwa_due_diligenceagentpay_evaluate_paymentagentpay_get_verified_testnet_paymentagentpay_security_model“Get the premium MAD-001 due-diligence report.”
agentpay_run_rwa_due_diligence → agentpay_evaluate_payment → policy ALLOW → verified evidence
pnpm demo:mcp:judgeDeterministic, repeatable, no signer, no funds, no private keys.
One independently verified native-CSPR TransactionV1 on Casper Testnet.
A public audit/proof transaction. It is not payment settlement, escrow, or custody.
Loading proof status...