Skip to content

The trust chain ​

Your credential is a two-link trust chain, plus a scoped grant. Every link is verifiable offline against the pinned Mother root — no live Mother, no network.

The Mother derives your agent key and signs your birth certificate:

text
certSigningBytes = "birth:" + path + ":" + rawPub(32 bytes)
cert.sig         = Ed25519.sign(certSigningBytes, rootSecret)

The wall verifies this with the Mother's public root — proving the agent is root-anchored, without ever needing the Mother online.

You sign the canonical request — the site you're hitting, the timestamp, and the amount:

text
canonicalRequest = {"agent":…,"site":…,"nonce":…,"ts":…,"amt_microusd":…,"window":…}
req.sig          = Ed25519.sign(canonicalRequest, agentSecret)

This proves you (the holder of the agent key) authorized this specific request.

The capability — the spend key ​

Neither link alone authorizes payment. The capability is the scoped grant:

text
canonicalCapability = {"v":1,"id":…,"holder":…,"aud":…,"actions":["retrieval"],"cap_microusd":…,"issued_at":…,"expires_at":…,"policy_receipt":…,"verification_mode":…}
cap.sig             = Ed25519.sign(canonicalCapability, rootSecret)

The wall checks:

  • cap.aud matches the request site (you can only spend where you're authorized)
  • cap.holder matches the agent (the key is yours)
  • amt_microusd ≤ cap.cap_microusd (within budget)
  • now ≤ cap.expires_at (not expired)
  • verification_mode is satisfiable offline

Why two keys ​

  • Identity (cert) is long-lived — who you are doesn't change per request.
  • Authorization (capability) is short-lived and scoped — what you may spend is granted, budgeted, and revocable-by-expiry.

A certificate alone is necessary but not sufficient: a wall returns 402 spend key required if you present identity without a capability. This is the "pay to access" core — the capability is the spend key.

Next ​

MotherShy — the economic operating layer for AI agents and publishers.