Private credit workspace

Your portfolio overview

Connecting
No-funds product sandbox
No real lending No real funds No financial advice Synthetic identity only Protocol fees disabled · Fee Policy deferred

Private workspace

Choose how you want to use IPO.ONE

Sign in once, then continue as a Human, connect an Agent, review Capital Partner access, or use the versioned API.

  • HumanRequest, manage, and repay purpose-bound credit.
  • AgentUse scoped authority through the same credit kernel.
  • Capital PartnerReview verified credit evidence in an invited workspace.
  • Developer / APIIntegrate through versioned, machine-readable interfaces.

Use the single Sign in action above. Private account, wallet, and credit data remain hidden until the Tenant workspace is verified.

Human Workspace Current statusNot started Checking server

Portfolio command center

Your portfolio overview

Review your current credit position, next payment, and verified activity from one workspace.

Available creditUnavailable
OutstandingUnavailable
Next payment
Evidence track recordNot loaded

Borrowing shortcuts

Start from the user you are serving

Human and Agent use different authority, then converge on the same Decision, Offer, Obligation, repayment, and Evidence record.

IPO.ONE products

Choose what you want to do

Each product keeps its own purpose while using the same identity, obligation, repayment, and Evidence record.

Loading authenticated server truth Workspace recovery and owned reads are still pending. No amount is inferred in the browser.
Workspace detailsIdentity, authority, and product status

Access modes

Human and Agent, one shared kernel

The interface and authority method change. Obligation, Ledger, risk, servicing, and Evidence do not fork.

Human Workspace

Application & Obligation

Not started

Consent, deterministic Offer, exact acceptance, repayment schedule, servicing, and owner Evidence remain one Human path.

Offer
Not requested
Obligation
Not created
Servicing
Not started

Agent Workspace

Identity & bounded authority

Principal setup

The Human Principal binds CAIP-10 identity and a scoped Mandate. The Agent receives machine-readable capability, never credentials or funds authority.

Subject
Not created
Account proof
Not submitted
Mandate
Not created

Verified activity

Recent credit activity

Human credit

Know every term. Own every step.

See your terms before you accept, follow one clear repayment plan, and verify every lifecycle event—all without real funds.

Your journeyGuided from request to repayment
DecisionsTerms explained before acceptance
Funds modeNo real funds

Your guided path

Start with a private sandbox profile

Step 1 of 5

We will create an opaque profile and purpose-limited Consent. No name, bank login, wallet credential, or raw KYC is requested here.

  1. 1
    Get readyPrivate profile and Consent
  2. 2
    RequestAmount and schedule
  3. 3
    Review termsDecision and exact Offer
  4. 4
    ActivateSandbox Obligation
  5. 5
    Repay & verifySchedule and Evidence
Product protectionsView protocol controls and safety boundaries Private protocol approved
StageAuthorityProduct stateFunds effect
Credit IntentActive ConsentAvailableNone
Decision & OfferDeterministic risk policyAvailableNone
AcceptanceExact Offer + Consent/MandateAvailableCreates Obligation
ExecutionSigned sandbox rail + shared ledgerAvailableNo real movement

Intent, Decision, Offer, exact acceptance, and shared Obligation use one approved private protocol. Capital, custody, disbursement, and production funds stay disabled.

Authenticated application

Request and price no-funds credit

Choose an amount and schedule. You will see an explainable Offer before anything is created.

Checking private gateway
01
Private profileCreate your sandbox profile and purpose-limited permission. No raw identity data is entered here.
Advanced: load existing identity references

Synthetic identity prerequisite: the selected Consent must have a current encrypted identity reference provisioned by the pilot operator. Raw KYC/PII is never requested or rendered here.

02
Your requestChoose a small amount and schedule. You can review the result before accepting anything.
Sandbox asset USD cent · urn:ipo-one…

Connect through the local authenticated Human pilot host to begin.

Authenticated protocol results One server receipt per completed step
  1. 01
    Authority preflightpilotReadHumanSelf
    Waiting for server
  2. 02
    Credit IntentpilotRequestCredit
    Waiting for server
  3. 03
    Application readpilotReadCreditApplication
    Waiting for server
  4. 04
    Decision & OfferpilotEvaluateCreditApplication
    Waiting for server
  5. 05
    Exact acceptancepilotAcceptCreditOffer
    Waiting for server
  6. 06
    No-funds executionpilotExecuteSandboxObligation
    Waiting for server

PILOT-006 · design-partner feedback

Tell us where the product worked—or blocked you.

Choose structured signals only. This form has no comment box and accepts no name, contact detail, wallet address, KYC, or other PII.

Ready when Subject is loaded

Create or restore your Human Subject to submit one immutable categorical receipt.

Categorical only · actor-owned Subject · no third party · no underwriting effect · sandbox only
Optional Agent pathNeed an Agent to act for you?Configure identity and bounded authority without sharing credentials or funds access. Principal controlled

Principal-controlled Agent setup

Create, review, and activate Agent authority

The authenticated Human Principal defines a bounded Mandate. The Agent receives IDs for the Agent API handoff, never permission to change or activate its own authority.

Not started
Principal authority check Verifying Principal access

The Agent authority workflow remains locked until the authenticated workspace is verified.

Identity + authority

Human application boundary

SubjectOpaque Human Subject ID
Identity evidenceEncrypted reference only
ConsentPurpose, amount, term scoped
Raw KYC / PIINever rendered

Operable no-funds lifecycle

Execution, repayment & servicing

SERVICING-001

Execute, repay, and inspect trusted-time DPD, cure, and resolution Evidence against the same shared Human/Agent Obligation kernel.

DPD clockTrusted UTC
CureSame repayment waterfall
ResolutionDual control only

Agent credit · Principal controlled

Same economics. Bounded machine authority.

A Human Principal must bind the Agent Subject and exact Consent-equivalent Mandate scope before the Agent application tools become available.

Activating a Mandate creates bounded authority; it does not create a Credit Intent, Offer, Obligation, execution, or repayment.

Entry authorityNo eligible handoff
Economic kernelSame deterministic policy
Funds modeNo real funds

Authenticated machine journey

Intent → Decision → Offer → Acceptance → Execution

Authenticated session required
01Credit IntentLocked pending bounded handoff
02Decision & OfferLocked pending bounded handoff
03Exact acceptanceLocked pending active Mandate
04No-funds executionLocked pending active Mandate

Server workflow receipts

Machine-verifiable handoff result

Versioned
Decision & Offer
Returned only after Agent workflow
Obligation lifecycle
Returned only after active runtime workflow

Receipts return to the authenticated Agent runtime. They contain no credential, private key, reusable signature, or funds authority.

Dual-native parity

Different authority. One economic truth.

Shared kernel
Human entryConsent + HTTPS receipt
Agent entryMandate + Agent receipt
Compared exactlyPrincipal, term, APR, fee, schedule
Excluded from parityIdentity, authority IDs, transport
No lender or facility is liveNo capital provider, real disbursement, withdrawable balance, mainnet action, or production underwriting is enabled by this journey.

Private credit evidence

Checking server

Credit Passport

Share a temporary, read-only view of the facts behind your current credit Decision. You choose one authorized reviewer, how long access lasts, and exactly which facts are disclosed.

Server-derived state

No Decision Passport loaded

Complete or restore an authenticated credit application. This view will not manufacture a score, Decision, or shareable proof.

Owner / controller only

Share the current Decision

Private · expiring
Current SubjectNot loaded
Current credit applicationNot loaded
What can this verifier see?

Complete a current Decision first. The verifier is never discovered or suggested by the browser.

Current sharing status

Shared Passport

Not loaded
Recover an existing Passport by technical ID
Proof version
Issuer
Permitted use
Private credit review
Active period
Review access
One bound same-Tenant reviewer
Disclosed facts

Issue or read an authorized artifact to inspect its selected, evidenced disclosures.

Technical receipt and integrity digests
Source Decision Passport digest
Passport artifact digest

These hashes verify integrity. They are not blockchain transaction hashes; public-chain status is shown separately in the Obligation Evidence receipt.

No artifact is trusted until an authenticated server read succeeds.

Verifier toolVerify a received proof online Not verified

Verification requires the exact authenticated verifier, current same-Tenant Membership, purpose, hash, version, source, and trusted server time.

Real local

Private proof lifecycle

Four authenticated operations create, read, verify, and terminally revoke a versioned artifact.

Safety invariant

Evidence, not a score

Only selected factor grades, canonical reason codes, and exact Evidence lineage can be disclosed.

Prohibited

No bearer sharing

No public link, QR, download, credential, signature, cross-Tenant verifier, or production authority exists.

Principal-controlled Agent credit

Authorize once. Keep every limit visible.

A Human Principal approves identity and bounded authority before an Agent receives any application or runtime handoff.

IdentityPrincipal setup required
AuthorityNo Mandate
Funds modeNo real funds

Versioned integration truth

One online Agent path. Twelve protected operations.

Run the registered local reference Agent online or connect an external Agent through the protected HTTPS contract. Credentials remain server-side and every call is reauthorized.

One manifest. Twelve local tools. No ambient authority.

Checking contract
Manifest
Registry parity
Transport
Workflows

Waiting for authenticated catalog and Principal state.

Principal-observable Agent lifecycle

Check authenticated Agent progress online

Waiting for Mandate

Create a verified Agent Subject and Draft Mandate first. The external Agent uses its own credential; this Principal browser reads only durable server truth.

ApplicationNot started
OfferNot loaded
ObligationNot created
Provider spendNot executed
Revenue → repaymentNot posted
EvidenceNot loaded

What “use credit” means: the Agent executes one Mandate-approved purpose through the non-withdrawable sandbox rail. It cannot transfer the credit to an arbitrary wallet. The external Agent uses its own durable, revocable credential; the Principal browser can only check sanitized, persisted workflow receipts.

Human-controlled authority

Principal binding

Waiting
Principal
Agent Subject
Subject state
Control
Principal only

Hash-only CAIP proof

Account proof

Waiting
Chain
Purpose
Verification
Proof hash

Raw accounts, signatures and reusable proofs never enter this presentation.

Exact sandbox scope

Mandate

Waiting
Mandate
Capabilities
Limit
Expires

Active Mandates cannot be edited in place.

agent_mcp_registry.v2

Approved Agent API operations

Checking

Catalog presence is not authorization. The Host rechecks Subject, Mandate, admission and policy on every call. Approved local stdio MCP tools remain available as an optional developer transport.

Typed SDK compositions

Three staged workflows

Local only
IdempotencyStable workflow + command IDs
ErrorsProblem Details + stable MCP codes
EvidenceOwned hash-only immutable reads
ConformanceRegistry · SDK · browser parity

Optional developer tooling

CLI reference runner

The CLI remains an optional integration and debugging tool. Normal product testing uses the online reference Agent above; external Agents call the protected HTTPS API with their own credential.

Versioned local contract

OpenAPI discovery

Open contract

The document describes authentication requirements but contains no credential or production endpoint.

Exact unavailable capabilities

Not hidden. Not implied. Not enabled.

Disabled

Capital provider workspace

Checking private gateway

Capital Partners

Review an exact borrower-authorized Passport, set transparent sandbox terms, and monitor the resulting Obligation from execution through repayment and Evidence.

No funds authority
Access Sign-in required Pre-provisioned operator with a dedicated least-privilege role.
Capital mode Synthetic bilateral No deposit, custody, withdrawal, or production capital.
Reporting Server-derived Offer, Obligation, servicing, repayment, and anchor coverage.

Exact authorized application

Author sandbox terms

No Offer
Borrower-authorized Passport
Transparent economic terms

Sign in through the invited Capital Partner workspace, then enter the exact Passport values supplied by the borrower.

Canonical Offer receipt

Terms and authority

credit_offer.v2
Capital Partner
Offer ID
Offer hash
Terms hash
Borrower
Validity

Server-composed read model

Portfolio and Facility truth

Not loaded
Offers0
Committed$0.00
Outstanding$0.00
Repaid$0.00

Portfolio values come from canonical Offer, Obligation, servicing, repayment, and Evidence projections.

Explicit Phase 2 boundary

Bilateral terms are enabled; money movement is not

This workspace can review a bounded Passport, issue an exact synthetic Offer, and monitor canonical lifecycle truth. Public pools, deposits, custody, allocation, withdrawals, and real capital remain disabled.

Provider workspace · no funds

Checking server

Provider Network

Inspect one assigned sandbox intent from the authenticated Provider boundary. Exposure, delivery, and reconciliation remain server-derived, nonwithdrawable, and explicitly not deployed capital.

Verifying contract capital_network_presentation.v1

Exact assignment only

Load your assigned TransferIntent

Provider AccessGrant

Use the exact TransferIntent ID from your Provider assignment or invitation. This page cannot search for assignments; missing, expired, denied, and cross-Provider resources are not enumerated.

Current server state

No Provider intent loaded

The browser does not infer Provider exposure, facility state, earnings, or reconciliation from prototype data.

Mandate-bound assignment

Provider mandate

Not loaded
Provider
Server required
Purpose
Server required
TransferIntent
Server required
Funding authority
No · presentation only

Assigned no-funds exposure

Facility presentation

Not deployed capital
No server amount

Asset unavailable until an exact intent is loaded.

Simulation onlyNonwithdrawableNo Provider funding

Signed fixed-loopback delivery

Delivery & reconciliation

Waiting for server
1AssignedExact Provider intent
2AcknowledgedIdempotent receipt
3ReconciledSigned callback processed
Allocation receiptNot loadedServer TransferIntent hash required
Reconciliation receiptNot loadedNot a settlement or funds receipt
Delivery integrityNot loadedSigned local boundary only

Acknowledgement is not funding, settlement, custody, or withdrawal authority. Exact retries reuse one idempotency key.

Historical example only · unapproved

Earnings simulation

Not pricing policy
No simulation amount

Example rate: 1.25% of an exact loaded sandbox amount. It is nonbinding, unapproved, and cannot create Ledger, Evidence, or Provider entitlement.

Explicitly unavailable

Capital actions remain disabled

Human gate required

No TVL, public LP, remote Provider, mainnet, real capital, custody, or withdrawable balance is enabled.

Hyperliquid MVP · local no-funds

Checking contract

Trading Capital

Hyperliquid testnet is the only MVP venue for this authenticated Facility and canonical Obligation. This local screen inspects and closes an existing synthetic Facility; creation, matching, funding simulation, and execution setup are role-scoped API/SDK workflows. Other venue adapters remain disabled; no redeemable settlement, external execution, or remote MCP is implied.

0 / 25 catalog parity

Exact bound resource only

Load one synthetic Facility

Not loaded

Use the Facility ID returned by an authorized Trading Capital API/SDK workflow. This page does not create or discover Facilities; denied, missing, and cross-Tenant resources remain non-enumerating.

Overview

Server contract availability

Catalog required
FacilityUnavailable
Canonical ObligationUnavailable
SettlementUnavailable
Performance ProofUnavailable

Deterministic close path

Settle & prove

Synthetic only

The settlement worker accepts no caller-supplied PnL, fee, cost, or price. It conserves synthetic contributions, creates no second Ledger, and cannot move production funds.

Authentication + bounded execution

Checking server

Wallet & Permissions

IPO.ONE login identifies the Actor and workspace. A separate execution AccountBinding proves control of one external account; only canonical Mandate, CreditLine, Obligation, and risk state can derive bounded execution authority.

Current server session

Checking authentication

No wallet or server-session authority is assumed before verification.

Server authority matrix

Effective wallet permissions

Checking
Selected Provider
None selected
Wallet account
Not bound
Network
Not bound
Authority lifecycle
Unknown
Capability Effective state Enabled

Only a current server session can authenticate a wallet. No catalog entry grants token approval, arbitrary transaction, withdrawal, or funds authority.

Execution account · not login

Connect & bind an account

Not connected

Choose a discovered wallet and approved network in the existing sign-in panel, then connect it here to the current authenticated Human or Agent Subject. The proof is one-use EIP-712 and creates neither a login session nor economic authority.

Authenticated Subject
Unavailable
Connected account
Not connected
Approved network
Not selected
AccountBinding
Not verified

Sign in to IPO.ONE first. Wallet connection and AccountBinding never replace authentication.

Canonical authority → exact execution

Prepare, simulate & preflight

No authority derived

The Gateway resolves the exact approved TransferIntent and constructs calldata and ExpectedEffects on the server. Browser-authored transaction payloads are never accepted.

DelegatedWalletGrant
Not prepared
Capacity
Zero until derived
Preflight
Not run
Submission
Disabled · local no-funds
Exact server references

These references are validated against current server projections. They do not let the browser choose an address, calldata, amount, asset, or effects.

Connect and bind an execution account. Current local runtime can prepare Evidence but cannot submit a transaction or move funds.

Real local

Authentication remains separate

Existing OIDC/SIWE session, Tenant, Actor, Role, and recovery semantics are unchanged by execution account actions.

Real local

Human + Agent AccountBinding

One dual-native proof contract binds an execution account to an existing Subject and grants zero authority by itself.

Submission disabled

Exact resolver & Evidence

Gateway-owned atomic persistence records reservation, prepared execution, simulation, preflight, Events, Evidence, and outbox without moving funds.

Owned obligations

Every position, reconciled to server truth.

Review bounded owned references, exact current state, schedule, authority, sandbox rail, and immutable Evidence.

Selected shared position

Obligation status

Not loaded
Original principal
Annual rate
Maturity
Outstanding total

Refresh exact owner-authorized server state before relying on an amount or status.

Bounded owned-resource composition

My obligations

Not loaded
Current positions0/0
OutstandingHidden
Past dueHidden
Total repaidHidden

Sign in to recover bounded Actor-owned Obligation references.

Exact authorized references

Positions

Unrefreshed or denied references reveal no financial values.

Select a current position

Refresh server state, then select one exact Obligation. Browser state is never financial truth.

Read boundary

One state machine, exact owner reads

Human Consent and Agent Mandate change entry presentation only. List references come from the bounded authenticated workspace and every value is reauthorized by exact Obligation ID.

Human repayment

Repay with the schedule in view.

Post synthetic repayment against the exact shared Obligation and inspect deterministic allocation.

Shared servicing kernel

Servicing Case

No Obligation

Enter an exact Obligation ID or create one in Human Pilot.

No active case

Accept and execute one exact sandbox Obligation to open its servicing view.

Provider sandbox

Signed Provider boundary verified

One fixed loopback Provider can receive an exact assigned intent, acknowledge it, and return a signed callback without duplicating canonical state.

DeliverySigned
AcknowledgementBound
CallbackVerified
ReplayExactly once
ReconciliationClean

Capability status only — this Obligation has no Provider execution. Loopback, synthetic, no-funds, nonwithdrawable; public or remote Provider access remains disabled.

Owner Evidence

Verify the lifecycle, not a screenshot.

Load redacted immutable events for the exact Obligation owned by this authenticated Human session.

Shared immutable timeline

Obligation Evidence

Not loaded
ObligationNot created
Events loaded0
Server Evidence stateWaiting
As ofNot queried

Session projection only. Durable Evidence is loaded through the already-approved owner or Agent Evidence operation; this page creates no new read permission.

EVIDENCE-001C · Base Sepolia

Checking operation

Public Registry Evidence

Verify one finalized, redacted testnet credit-registry lifecycle without treating it as the signed-in user’s own repayment record.

Synthetic only

Enter one exact public authorization hash. The authenticated Gateway returns only the bounded synthetic Base Sepolia observation.

Final stateNot queried
Registry contract
FinalityWaiting
ObservedNot queried
Observation hash
Finality proof hash
Lifecycle event Transaction Block Server state

Evidence-derived only

Checking server

Credit Track Record

Summarize only the authenticated Decision and Obligation Evidence already available to this session. Browser history is not credit truth.

Current record

No verified lifecycle loaded

Restore an owned Obligation and load its Evidence. No positive history is inferred from an empty browser state.

Canonical inputs only

Current Evidence summary

Not loaded
Decision Passport
Not loaded
Owned Evidence
0 events
Finalized
0
Non-final / invalidated
0
Server-backed

Evidence-derived record

Decision and owned Obligation Evidence are the only permitted inputs.

Simulation only

Wallet history and impact

Wallet-history import and impact simulation are not authoritative product actions.

Server-backed

Generated report

Create a bounded JSON or formula-safe CSV artifact from the exact owned Obligation and its persisted Evidence.

Server-generated artifacts

Checking server

Reports & Exports

Create, inspect, retrieve, and revoke a bounded report derived from the current owned Obligation and its persisted Evidence. The browser transports exact verified bytes; it does not author official content.

Current artifact

No official report loaded

Load an owned Obligation first. Report content is generated and hashed by the server from bounded, redacted Evidence.

Authenticated command

Create official activity report

No funds

The server reauthorizes the exact owned Obligation and limits the source to 50 redacted Evidence events.

Authorization rechecked

Read or retrieve exact artifact

Not loaded

Every read and retrieval revalidates active same-Tenant ownership. Expired or revoked artifacts are unavailable.

Server metadata only

Artifact integrity

Not loaded
Content SHA-256
Artifact hash
Evidence source
Expires
Authorization
Rechecked on access
Production fee policy
Unavailable · principal and unrealized PnL excluded as fee bases

No HTML export, public link, bearer grant, PII, secret, raw transaction, signed URL, production fee calculation, mainnet authority, or real-funds authority is created.

Permissioned control plane · WEB-008

Portfolio risk, with protective action.

Read one exact tenant portfolio and freeze one exact Agent Subject through the authenticated Gateway. Every result is policy-bound and PII-free.

Not loaded

Aggregate exposure

Tenant portfolio posture

No verified query yet.

Use the portfolio ID provisioned to the invited Risk or Auditor operator. This page cannot enumerate portfolios; catalog presence does not grant access, and the Gateway verifies every read.

Approved limits$0.000 credit lines
Utilized$0.000% utilization
Outstanding$0.000 open Obligations
Adverse states0Overdue + defaulted

Identity posture

Capacity posture

Servicing posture

Asset exposure

PII-free portfolio view

Not loaded
AssetLimits / utilizedOutstandingAdverse

PILOT-005 · privacy-safe product truth

Design-partner lifecycle health

Aggregate Human and Agent progress from durable protocol facts—without trackers, raw identifiers, KYC, or borrower PII.

Not loaded

Load the Tenant portfolio to verify the product funnel.

Applications00% offered
Accepted00% of applications
Executed00% of applications
Repaid00% started repayment
Fully repaid00% completed
Human entry0 applications
Agent entry0 applications
Dual-native proofWaiting
Positions0 total · 0 open
Read-only · aggregate only · PII excluded · no third-party analytics · sandbox only · no production funds.

PILOT-006 · privacy-safe feedback truth

Design-partner experience

Aggregate categorical signals from Human and Agent entry modes. No feedback, Subject, Actor, wallet, KYC, or Event identifier is returned.

Not loaded

Load the Tenant portfolio to aggregate feedback.

Total signals0
Human / Agent0 / 0
Completed0
Needs support0
Blocked0
Most common blockerNone
Aggregate only · identifiers and PII excluded · no third-party analytics · no underwriting effect.

SERVICING-002B · private work queue

Adverse Obligation review

Trusted-time delinquency and default cases, ordered by severity. This surface is read-only and contains no borrower PII.

Not loaded

Risk or Operations access and recent phishing-resistant MFA are verified on every read.

Visible cases0
Critical0
Past due$0.00
Verified
Obligation Stage Past due Outstanding Review

Read-only · PII excluded · no disposition authority · synthetic obligations only · no real funds.

V9-008 · checked-in control evidence

Operational assurance, without invented runtime state

Policy and runbook facts are separated from live Tenant reads. A checked-in control never becomes a current alert, reconciliation result, incident, or approval merely because it is rendered here.

Checking catalog
Alerts Unavailable

No operator alert read has been verified.

Policy evidence only
Reconciliation Unavailable

No current reconciliation run has been loaded.

Worker evidence only
Incidents Unconfigured

No incident acknowledgement or resolution authority is exposed.

Runbook baseline only
Dual control Unavailable

A proposal locator is never approval authority.

Exact command required
Configuration evidence is not live state Loading the versioned control boundary…

Policy ceilings · Gateway still decides

Borrower, Risk, Operations, and Auditor remain separate

These rows describe checked-in maximum authority when the matching operation exists. They do not describe the current session and cannot bypass Membership, capability, recent MFA, resource ownership, live state, admission, or audit.

Recent MFA
Actor Portfolio Queue Freeze Resolution

Health and aggregate feedback use their own recent-MFA capabilities. Catalog discovery never grants either read.

Protective-only command

Freeze Agent Subject

Step-up control

Suspends one exact pending or active Agent Subject. This surface cannot unfreeze, increase limits, move funds, or expand authority.

Risk or Operations authority is verified only when the command is submitted.

Explicitly unavailable

Closed permissions by design

Portfolio readPoint-in-time aggregates, no raw KYC or PII.
FreezeProtective-only, reason-bound, idempotent, and evidenced.
No inverse controlUnfreeze, limit increase, and generic emergency mutation remain unavailable.
No automatic actionAlerts and runbooks cannot repair state, resolve an incident, or move funds.
No demo resetHistorical prototype reset behavior is not an authenticated product control.
Break glassProtective-only, disabled by default, and unavailable in this browser.

Agent integration

From approval to action. No hidden authority.

Use one Principal-approved handoff with the approved local Agent Host. Credentials and real funds never travel in the packet.

IdentityPrincipal setup required
HandoffAwaiting Mandate
Transportlocal stdio MCP · closed_non_funds_pilot

Your integration path

Authorize this Agent

Step 1 of 4

A Human Principal creates the Agent Subject and sets exact sandbox limits before any machine workflow is available.

  1. 1
    AuthorizePrincipal + bounded Mandate
  2. 2
    Prove identityOne-use CAIP-10 proof
  3. 3
    Request termsCredential-free handoff
  4. 4
    Run & verifyObligation, repayment, Evidence
Local baseCurrent loopback origin
Tenant protocolChecking catalog
Agent SDKChecking manifest
Protocol versionChecking catalog
Agent MCPChecking manifest
HandoffAwaiting Mandate

Checked-in catalog + runtime response

V9 capability contract

Checking
Catalog maturity
Checking
Enabled transports
Checking
V9 destinations
0/13 verified
Safety
Real funds disabled
Destination Required server operations Catalog

No diagram, prototype export, marketing label, or browser counter can add a capability absent from the authenticated catalog.

Machine-readable integrationView handoff packet, 12 Agent operations, OpenAPI, and request log Waiting for authority

Non-authorizing manifest

Principal → Agent capability packet

This non-authorizing packet advertises twelve local Agent operations and three staged workflows. The loopback OpenAPI describes the server boundary; credentials and funds authority never enter the packet.

Local Agent MCP

Approved Host operations

Waiting
ipo_one_read_selfpilotReadAgentSelfWaiting
ipo_one_request_creditpilotRequestCreditWaiting
ipo_one_read_credit_applicationpilotReadCreditApplicationWaiting
ipo_one_evaluate_credit_applicationpilotEvaluateCreditApplicationWaiting
ipo_one_submit_account_proofpilotSubmitAgentAccountProofWaiting
ipo_one_read_account_bindingpilotReadAgentAccountBindingWaiting
ipo_one_read_obligationpilotReadOwnObligationWaiting
ipo_one_read_obligation_evidencepilotReadOwnObligationEvidenceWaiting
ipo_one_accept_credit_offerpilotAcceptCreditOfferWaiting
ipo_one_execute_sandbox_obligationpilotExecuteSandboxObligationWaiting
ipo_one_post_sandbox_repaymentpilotPostSandboxRepaymentWaiting
ipo_one_read_credit_registry_evidencepilotReadCreditRegistryEvidenceWaiting
Transportlocal stdio MCP · closed_non_funds_pilot
AuthenticationHost context injected out of band
API contractLoopback OpenAPI + local MCP registry
Funds authorityNone

Local no-funds Agent client

Reference Agent runner

Agent API contract

Approved authenticated workflows

3 stages
Decision & OfferTyped local MCP compositionLocked
Decision Passportrisk_decision_passport.v1 · policy + finalized Evidence lineageReturned
Obligation & repaymentLocal Host identity + Tenant protocolLocked
Servicing CasepilotReadOwnObligation + repayment + EvidenceSame state
Dual-chain conformanceLocal receipt verification, no RPCReceipt input
Structured pilot feedbackpilotSubmitPilotFeedback · closed categories · no PIITenant SDK

Authenticated request telemetry

Request log

Session VerifyingLast None0 requests