The trust chain
Your credential is a two-link trust chain, plus a scoped grant. Every link is verifiable offline against the pinned Mother root — no live Mother, no network.
Link 1 — Root → agent (identity)
The Mother derives your agent key and signs your birth certificate:
certSigningBytes = "birth:" + path + ":" + rawPub(32 bytes)
cert.sig = Ed25519.sign(certSigningBytes, rootSecret)The wall verifies this with the Mother's public root — proving the agent is root-anchored, without ever needing the Mother online.
Link 2 — Agent → request (authorization to act)
You sign the canonical request — the site you're hitting, the timestamp, and the amount:
canonicalRequest = {"agent":…,"site":…,"nonce":…,"ts":…,"amt_microusd":…,"window":…}
req.sig = Ed25519.sign(canonicalRequest, agentSecret)This proves you (the holder of the agent key) authorized this specific request.
The capability — the spend key
Neither link alone authorizes payment. The capability is the scoped grant:
canonicalCapability = {"v":1,"id":…,"holder":…,"aud":…,"actions":["retrieval"],"cap_microusd":…,"issued_at":…,"expires_at":…,"policy_receipt":…,"verification_mode":…}
cap.sig = Ed25519.sign(canonicalCapability, rootSecret)The wall checks:
cap.audmatches the request site (you can only spend where you're authorized)cap.holdermatches the agent (the key is yours)amt_microusd ≤ cap.cap_microusd(within budget)now ≤ cap.expires_at(not expired)verification_modeis satisfiable offline
Why two keys
- Identity (cert) is long-lived — who you are doesn't change per request.
- Authorization (capability) is short-lived and scoped — what you may spend is granted, budgeted, and revocable-by-expiry.
A certificate alone is necessary but not sufficient: a wall returns 402 spend key required if you present identity without a capability. This is the "pay to access" core — the capability is the spend key.
Next
- Pay to access — how the spend key maps to money.
- Verification modes — offline vs online.