Skip to content

Capabilities ​

A capability is a scoped, budgeted, expiring grant that lets an agent spend at a specific site. It is the "spend key" in MotherShy's pay-to-access model.

Why identity isn't enough ​

A birth certificate proves who an agent is. But identity alone can't authorize payment — it would let a recognized agent access everything, everywhere, for free. The capability separates the two:

  • Certificate = identity (long-lived).
  • Capability = authorization (scoped, budgeted, short-lived).

A wall returns 402 spend key required for identity without a capability. This is the exact boundary between "recognized" and "authorized to pay."

The fields ​

json
{
  "v": 1,
  "id": "cap-…",
  "holder": "<b64 agent public key>",
  "aud": "example.com",
  "actions": ["retrieval"],
  "cap_microusd": 1000,
  "issued_at": 1728000000,
  "expires_at": 1728003600,
  "policy_receipt": "…",
  "verification_mode": "offline",
  "sig": "<b64 Mother signature>"
}
FieldMeaning
holderThe agent key — must match cert.pub and req.agent
audThe audience (site) — must match req.site
actionsAllowed actions; retrieval is the only one today
cap_microusdSpend budget in micro-USD
issued_at / expires_atValidity window; expiry is mandatory for offline caps
verification_modeoffline or online
sigMother's signature over the canonical capability

What the wall checks ​

  1. cap.sig verifies against the Mother root.
  2. cap.aud == request site (no spending elsewhere).
  3. cap.holder == request agent (the key is yours).
  4. amt_microusd ≤ cap_microusd (within budget).
  5. now ≤ expires_at (not expired).
  6. verification_mode is satisfiable (offline caps must be, well, offline).

Offline caps can't be revoked ​

An offline capability is a bearer grant — a wall can't check "was this revoked?" without phoning home. That's the trade-off:

  • Offline → no network, no revocation, so expiry is mandatory and budgets are scoped.
  • Online → revocation + reservation (per-request locked spend), at the cost of a live check.

The self-hosted walls (WordPress/Node/Nginx/Vercel/Netlify) ship offline verify-only. The online path is Cloudflare-only today. See Verification modes.

Next ​

MotherShy — the economic operating layer for AI agents and publishers.