Capabilities
A capability is a scoped, budgeted, expiring grant that lets an agent spend at a specific site. It is the "spend key" in MotherShy's pay-to-access model.
Why identity isn't enough
A birth certificate proves who an agent is. But identity alone can't authorize payment — it would let a recognized agent access everything, everywhere, for free. The capability separates the two:
- Certificate = identity (long-lived).
- Capability = authorization (scoped, budgeted, short-lived).
A wall returns 402 spend key required for identity without a capability. This is the exact boundary between "recognized" and "authorized to pay."
The fields
{
"v": 1,
"id": "cap-…",
"holder": "<b64 agent public key>",
"aud": "example.com",
"actions": ["retrieval"],
"cap_microusd": 1000,
"issued_at": 1728000000,
"expires_at": 1728003600,
"policy_receipt": "…",
"verification_mode": "offline",
"sig": "<b64 Mother signature>"
}| Field | Meaning |
|---|---|
holder | The agent key — must match cert.pub and req.agent |
aud | The audience (site) — must match req.site |
actions | Allowed actions; retrieval is the only one today |
cap_microusd | Spend budget in micro-USD |
issued_at / expires_at | Validity window; expiry is mandatory for offline caps |
verification_mode | offline or online |
sig | Mother's signature over the canonical capability |
What the wall checks
cap.sigverifies against the Mother root.cap.aud== request site (no spending elsewhere).cap.holder== request agent (the key is yours).amt_microusd ≤ cap_microusd(within budget).now ≤ expires_at(not expired).verification_modeis satisfiable (offline caps must be, well, offline).
Offline caps can't be revoked
An offline capability is a bearer grant — a wall can't check "was this revoked?" without phoning home. That's the trade-off:
- Offline → no network, no revocation, so expiry is mandatory and budgets are scoped.
- Online → revocation + reservation (per-request locked spend), at the cost of a live check.
The self-hosted walls (WordPress/Node/Nginx/Vercel/Netlify) ship offline verify-only. The online path is Cloudflare-only today. See Verification modes.