No operator alert read has been verified.
Policy evidence onlyPrivate workspace
Choose how you want to use IPO.ONE
Sign in once, then continue as a Human, connect an Agent, review Capital Partner access, or use the versioned API.
- HumanRequest, manage, and repay purpose-bound credit.
- AgentUse scoped authority through the same credit kernel.
- Capital PartnerReview verified credit evidence in an invited workspace.
- Developer / APIIntegrate through versioned, machine-readable interfaces.
Use the single Sign in action above. Private account, wallet, and credit data remain hidden until the Tenant workspace is verified.
Portfolio command center
Your portfolio overview
Review your current credit position, next payment, and verified activity from one workspace.
Borrowing shortcuts
Start from the user you are serving
Human and Agent use different authority, then converge on the same Decision, Offer, Obligation, repayment, and Evidence record.
IPO.ONE products
Choose what you want to do
Each product keeps its own purpose while using the same identity, obligation, repayment, and Evidence record.
Workspace detailsIdentity, authority, and product status
Access modes
Human and Agent, one shared kernel
The interface and authority method change. Obligation, Ledger, risk, servicing, and Evidence do not fork.
Human Workspace
Application & Obligation
Consent, deterministic Offer, exact acceptance, repayment schedule, servicing, and owner Evidence remain one Human path.
- Offer
- Not requested
- Obligation
- Not created
- Servicing
- Not started
Agent Workspace
Identity & bounded authority
The Human Principal binds CAIP-10 identity and a scoped Mandate. The Agent receives machine-readable capability, never credentials or funds authority.
- Subject
- Not created
- Account proof
- Not submitted
- Mandate
- Not created
Verified activity
Recent credit activity
Human credit
Know every term. Own every step.
See your terms before you accept, follow one clear repayment plan, and verify every lifecycle event—all without real funds.
Your guided path
Start with a private sandbox profile
We will create an opaque profile and purpose-limited Consent. No name, bank login, wallet credential, or raw KYC is requested here.
- 1Get readyPrivate profile and Consent
- 2RequestAmount and schedule
- 3Review termsDecision and exact Offer
- 4ActivateSandbox Obligation
- 5Repay & verifySchedule and Evidence
Product protectionsView protocol controls and safety boundaries Private protocol approved
Intent, Decision, Offer, exact acceptance, and shared Obligation use one approved private protocol. Capital, custody, disbursement, and production funds stay disabled.
Authenticated application
Request and price no-funds credit
Choose an amount and schedule. You will see an explainable Offer before anything is created.
- Lifecycle
- Created
- Servicing
- Current
- Days past due
- 0
- Schedule
- v1
- Outstanding
- $0.00
- Interest due
- $0.00
- Total repaid
- $0.00
- Obligation ID
- —
- Sandbox rail receipt (offchain)
- Not executed
Early partial or full repayment is available after execution with no sandbox prepayment penalty. Fee → interest → principal; surplus is not posted.
Public-chain verification
Base Sepolia anchor
Not anchored. This sandbox Obligation and its repayments currently exist in IPO.ONE PostgreSQL only; no Base Sepolia transaction exists for this lifecycle.
- Server record
- Not loaded
- Evidence digest
- Not loaded
- Chain transaction
- Not submitted
- Chain finality
- Incomplete
- Indexer state
- Not observed
- Reconciliation
- Coverage pending
EVIDENCE-001B · owner only
Your durable Obligation timeline
Load the redacted PostgreSQL Evidence for this exact Obligation. Evidence digests are integrity checks, not blockchain transactions.
- 01Authority preflightpilotReadHumanSelfWaiting for server
- 02Credit IntentpilotRequestCreditWaiting for server
- 03Application readpilotReadCreditApplicationWaiting for server
- 04Decision & OfferpilotEvaluateCreditApplicationWaiting for server
- 05Exact acceptancepilotAcceptCreditOfferWaiting for server
- 06No-funds executionpilotExecuteSandboxObligationWaiting for server
PILOT-006 · design-partner feedback
Tell us where the product worked—or blocked you.
Choose structured signals only. This form has no comment box and accepts no name, contact detail, wallet address, KYC, or other PII.
Create or restore your Human Subject to submit one immutable categorical receipt.
Identity + authority
Human application boundary
Agent credit · Principal controlled
Same economics. Bounded machine authority.
A Human Principal must bind the Agent Subject and exact Consent-equivalent Mandate scope before the Agent application tools become available.
Activating a Mandate creates bounded authority; it does not create a Credit Intent, Offer, Obligation, execution, or repayment.
Authenticated machine journey
Intent → Decision → Offer → Acceptance → Execution
Server workflow receipts
Machine-verifiable handoff result
- Decision & Offer
- Returned only after Agent workflow
- Obligation lifecycle
- Returned only after active runtime workflow
Receipts return to the authenticated Agent runtime. They contain no credential, private key, reusable signature, or funds authority.
Dual-native parity
Different authority. One economic truth.
Private credit evidence
Checking serverCredit Passport
Share a temporary, read-only view of the facts behind your current credit Decision. You choose one authorized reviewer, how long access lasts, and exactly which facts are disclosed.
Server-derived state
No Decision Passport loaded
Complete or restore an authenticated credit application. This view will not manufacture a score, Decision, or shareable proof.
Owner / controller only
Share the current Decision
Complete a current Decision first. The verifier is never discovered or suggested by the browser.
Current sharing status
Shared Passport
Recover an existing Passport by technical ID
- Proof version
- —
- Issuer
- —
- Permitted use
- Private credit review
- Active period
- —
- Review access
- One bound same-Tenant reviewer
- Disclosed facts
- —
Issue or read an authorized artifact to inspect its selected, evidenced disclosures.
Technical receipt and integrity digests
- Source Decision Passport digest
- —
- Passport artifact digest
- —
These hashes verify integrity. They are not blockchain transaction hashes; public-chain status is shown separately in the Obligation Evidence receipt.
No artifact is trusted until an authenticated server read succeeds.
Verifier toolVerify a received proof online Not verified
Verification requires the exact authenticated verifier, current same-Tenant Membership, purpose, hash, version, source, and trusted server time.
Private proof lifecycle
Four authenticated operations create, read, verify, and terminally revoke a versioned artifact.
Evidence, not a score
Only selected factor grades, canonical reason codes, and exact Evidence lineage can be disclosed.
No bearer sharing
No public link, QR, download, credential, signature, cross-Tenant verifier, or production authority exists.
Principal-controlled Agent credit
Authorize once. Keep every limit visible.
A Human Principal approves identity and bounded authority before an Agent receives any application or runtime handoff.
Versioned integration truth
One online Agent path. Twelve protected operations.
Run the registered local reference Agent online or connect an external Agent through the protected HTTPS contract. Credentials remain server-side and every call is reauthorized.
One manifest. Twelve local tools. No ambient authority.
Waiting for authenticated catalog and Principal state.
Principal-observable Agent lifecycle
Check authenticated Agent progress online
Create a verified Agent Subject and Draft Mandate first. The external Agent uses its own credential; this Principal browser reads only durable server truth.
What “use credit” means: the Agent executes one Mandate-approved purpose through the non-withdrawable sandbox rail. It cannot transfer the credit to an arbitrary wallet. The external Agent uses its own durable, revocable credential; the Principal browser can only check sanitized, persisted workflow receipts.
agent_mcp_registry.v2
Approved Agent API operations
Catalog presence is not authorization. The Host rechecks Subject, Mandate, admission and policy on every call. Approved local stdio MCP tools remain available as an optional developer transport.
Typed SDK compositions
Three staged workflows
Optional developer tooling
CLI reference runner
The CLI remains an optional integration and debugging tool. Normal product testing uses the online reference Agent above; external Agents call the protected HTTPS API with their own credential.
Versioned local contract
OpenAPI discovery
The document describes authentication requirements but contains no credential or production endpoint.
Exact unavailable capabilities
Not hidden. Not implied. Not enabled.
Capital provider workspace
Checking private gatewayCapital Partners
Review an exact borrower-authorized Passport, set transparent sandbox terms, and monitor the resulting Obligation from execution through repayment and Evidence.
Exact authorized application
Author sandbox terms
Sign in through the invited Capital Partner workspace, then enter the exact Passport values supplied by the borrower.
Canonical Offer receipt
Terms and authority
- Capital Partner
- —
- Offer ID
- —
- Offer hash
- —
- Terms hash
- —
- Borrower
- —
- Validity
- —
Server-composed read model
Portfolio and Facility truth
Portfolio values come from canonical Offer, Obligation, servicing, repayment, and Evidence projections.
Explicit Phase 2 boundary
Bilateral terms are enabled; money movement is not
This workspace can review a bounded Passport, issue an exact synthetic Offer, and monitor canonical lifecycle truth. Public pools, deposits, custody, allocation, withdrawals, and real capital remain disabled.
Provider workspace · no funds
Checking serverProvider Network
Inspect one assigned sandbox intent from the authenticated Provider boundary. Exposure, delivery, and reconciliation remain server-derived, nonwithdrawable, and explicitly not deployed capital.
Exact assignment only
Load your assigned TransferIntent
Use the exact TransferIntent ID from your Provider assignment or invitation. This page cannot search for assignments; missing, expired, denied, and cross-Provider resources are not enumerated.
Current server state
No Provider intent loaded
The browser does not infer Provider exposure, facility state, earnings, or reconciliation from prototype data.
Mandate-bound assignment
Provider mandate
- Provider
- Server required
- Purpose
- Server required
- TransferIntent
- Server required
- Funding authority
- No · presentation only
Assigned no-funds exposure
Facility presentation
Asset unavailable until an exact intent is loaded.
Signed fixed-loopback delivery
Delivery & reconciliation
Acknowledgement is not funding, settlement, custody, or withdrawal authority. Exact retries reuse one idempotency key.
Historical example only · unapproved
Earnings simulation
Example rate: 1.25% of an exact loaded sandbox amount. It is nonbinding, unapproved, and cannot create Ledger, Evidence, or Provider entitlement.
Explicitly unavailable
Capital actions remain disabled
No TVL, public LP, remote Provider, mainnet, real capital, custody, or withdrawable balance is enabled.
Hyperliquid MVP · local no-funds
Checking contractTrading Capital
Hyperliquid testnet is the only MVP venue for this authenticated Facility and canonical Obligation. This local screen inspects and closes an existing synthetic Facility; creation, matching, funding simulation, and execution setup are role-scoped API/SDK workflows. Other venue adapters remain disabled; no redeemable settlement, external execution, or remote MCP is implied.
Exact bound resource only
Load one synthetic Facility
Use the Facility ID returned by an authorized Trading Capital API/SDK workflow. This page does not create or discover Facilities; denied, missing, and cross-Tenant resources remain non-enumerating.
Overview
Server contract availability
Deterministic close path
Settle & prove
The settlement worker accepts no caller-supplied PnL, fee, cost, or price. It conserves synthetic contributions, creates no second Ledger, and cannot move production funds.
Authentication + bounded execution
Checking serverWallet & Permissions
IPO.ONE login identifies the Actor and workspace. A separate execution AccountBinding proves control of one external account; only canonical Mandate, CreditLine, Obligation, and risk state can derive bounded execution authority.
Current server session
Checking authentication
No wallet or server-session authority is assumed before verification.
Authentication remains separate
Existing OIDC/SIWE session, Tenant, Actor, Role, and recovery semantics are unchanged by execution account actions.
Human + Agent AccountBinding
One dual-native proof contract binds an execution account to an existing Subject and grants zero authority by itself.
Exact resolver & Evidence
Gateway-owned atomic persistence records reservation, prepared execution, simulation, preflight, Events, Evidence, and outbox without moving funds.
Owned obligations
Every position, reconciled to server truth.
Review bounded owned references, exact current state, schedule, authority, sandbox rail, and immutable Evidence.
Selected shared position
Obligation status
Refresh exact owner-authorized server state before relying on an amount or status.
Bounded owned-resource composition
My obligations
Sign in to recover bounded Actor-owned Obligation references.
Positions
Unrefreshed or denied references reveal no financial values.
Select a current position
Refresh server state, then select one exact Obligation. Browser state is never financial truth.
Shared obligation.v2
—
Payment plan
Version history & corrections
Load Evidence to verify immutable state changes.
Read boundary
One state machine, exact owner reads
Human Consent and Agent Mandate change entry presentation only. List references come from the bounded authenticated workspace and every value is reauthorized by exact Obligation ID.
Human repayment
Repay with the schedule in view.
Post synthetic repayment against the exact shared Obligation and inspect deterministic allocation.
Shared servicing kernel
Servicing Case
Authenticated server truth
My positions
Refresh to load current balances and trusted-time servicing state for these authorized references.
Only Actor-bound opaque references are shown. Select one position to load its exact authorized state.
Accept and execute one exact sandbox Obligation to open its servicing view.
Case stage
DPD is derived by the authenticated worker; this page cannot change time or classification.
Cure or repay
Execute the sandbox Obligation before posting a repayment.
- Past-due principal
- $0.00
- Past-due interest
- $0.00
- Past-due fees
- $0.00
Fee → interest → principal. Cure is confirmed only by the returned Obligation.
Payment plan
Provider sandbox
Signed Provider boundary verified
One fixed loopback Provider can receive an exact assigned intent, acknowledge it, and return a signed callback without duplicating canonical state.
Capability status only — this Obligation has no Provider execution. Loopback, synthetic, no-funds, nonwithdrawable; public or remote Provider access remains disabled.
Owner Evidence
Verify the lifecycle, not a screenshot.
Load redacted immutable events for the exact Obligation owned by this authenticated Human session.
Shared immutable timeline
Obligation Evidence
Session projection only. Durable Evidence is loaded through the already-approved owner or Agent Evidence operation; this page creates no new read permission.
EVIDENCE-001C · Base Sepolia
Checking operationPublic Registry Evidence
Verify one finalized, redacted testnet credit-registry lifecycle without treating it as the signed-in user’s own repayment record.
Enter one exact public authorization hash. The authenticated Gateway returns only the bounded synthetic Base Sepolia observation.
——Obligation Evidence
Inspect the durable server lifecycle behind one shared Human or Agent Obligation.
EVIDENCE-001A
Durable audit timeline
Enter an exact Obligation ID. Access is verified by the private Gateway.
Evidence-derived only
Checking serverCredit Track Record
Summarize only the authenticated Decision and Obligation Evidence already available to this session. Browser history is not credit truth.
Current record
No verified lifecycle loaded
Restore an owned Obligation and load its Evidence. No positive history is inferred from an empty browser state.
Canonical inputs only
Current Evidence summary
- Decision Passport
- Not loaded
- Owned Evidence
- 0 events
- Finalized
- 0
- Non-final / invalidated
- 0
Evidence-derived record
Decision and owned Obligation Evidence are the only permitted inputs.
Wallet history and impact
Wallet-history import and impact simulation are not authoritative product actions.
Generated report
Create a bounded JSON or formula-safe CSV artifact from the exact owned Obligation and its persisted Evidence.
Server-generated artifacts
Checking serverReports & Exports
Create, inspect, retrieve, and revoke a bounded report derived from the current owned Obligation and its persisted Evidence. The browser transports exact verified bytes; it does not author official content.
Current artifact
No official report loaded
Load an owned Obligation first. Report content is generated and hashed by the server from bounded, redacted Evidence.
Authenticated command
Create official activity report
The server reauthorizes the exact owned Obligation and limits the source to 50 redacted Evidence events.
Authorization rechecked
Read or retrieve exact artifact
Every read and retrieval revalidates active same-Tenant ownership. Expired or revoked artifacts are unavailable.
Server metadata only
Artifact integrity
- Content SHA-256
- —
- Artifact hash
- —
- Evidence source
- —
- Expires
- —
- Authorization
- Rechecked on access
- Production fee policy
- Unavailable · principal and unrealized PnL excluded as fee bases
No HTML export, public link, bearer grant, PII, secret, raw transaction, signed URL, production fee calculation, mainnet authority, or real-funds authority is created.
Permissioned control plane · WEB-008
Portfolio risk, with protective action.
Read one exact tenant portfolio and freeze one exact Agent Subject through the authenticated Gateway. Every result is policy-bound and PII-free.
Aggregate exposure
Tenant portfolio posture
Use the portfolio ID provisioned to the invited Risk or Auditor operator. This page cannot enumerate portfolios; catalog presence does not grant access, and the Gateway verifies every read.
Identity posture
Capacity posture
Servicing posture
Asset exposure
PII-free portfolio view
PILOT-005 · privacy-safe product truth
Design-partner lifecycle health
Aggregate Human and Agent progress from durable protocol facts—without trackers, raw identifiers, KYC, or borrower PII.
Load the Tenant portfolio to verify the product funnel.
PILOT-006 · privacy-safe feedback truth
Design-partner experience
Aggregate categorical signals from Human and Agent entry modes. No feedback, Subject, Actor, wallet, KYC, or Event identifier is returned.
Load the Tenant portfolio to aggregate feedback.
SERVICING-002B · private work queue
Adverse Obligation review
Trusted-time delinquency and default cases, ordered by severity. This surface is read-only and contains no borrower PII.
Risk or Operations access and recent phishing-resistant MFA are verified on every read.
Read-only · PII excluded · no disposition authority · synthetic obligations only · no real funds.
V9-008 · checked-in control evidence
Operational assurance, without invented runtime state
Policy and runbook facts are separated from live Tenant reads. A checked-in control never becomes a current alert, reconciliation result, incident, or approval merely because it is rendered here.
No current reconciliation run has been loaded.
Worker evidence onlyNo incident acknowledgement or resolution authority is exposed.
Runbook baseline onlyA proposal locator is never approval authority.
Exact command requiredProtective-only command
Freeze Agent Subject
Suspends one exact pending or active Agent Subject. This surface cannot unfreeze, increase limits, move funds, or expand authority.
Risk or Operations authority is verified only when the command is submitted.
Explicitly unavailable
Closed permissions by design
Agent integration
From approval to action. No hidden authority.
Use one Principal-approved handoff with the approved local Agent Host. Credentials and real funds never travel in the packet.
Your integration path
Authorize this Agent
A Human Principal creates the Agent Subject and sets exact sandbox limits before any machine workflow is available.
- 1AuthorizePrincipal + bounded Mandate
- 2Prove identityOne-use CAIP-10 proof
- 3Request termsCredential-free handoff
- 4Run & verifyObligation, repayment, Evidence
Checked-in catalog + runtime response
V9 capability contract
- Catalog maturity
- Checking
- Enabled transports
- Checking
- V9 destinations
- 0/13 verified
- Safety
- Real funds disabled
No diagram, prototype export, marketing label, or browser counter can add a capability absent from the authenticated catalog.
Machine-readable integrationView handoff packet, 12 Agent operations, OpenAPI, and request log Waiting for authority
Non-authorizing manifest
Principal → Agent capability packet
This non-authorizing packet advertises twelve local Agent operations and three staged workflows. The loopback OpenAPI describes the server boundary; credentials and funds authority never enter the packet.
Local Agent MCP
Approved Host operations
Local no-funds Agent client
Reference Agent runner
Agent API contract
Approved authenticated workflows
Authenticated request telemetry