No real lendingNo real fundsNo financial adviceSynthetic identity onlyEarly-access data is retained for operation, Evidence, security, and debugging under the applicable privacy termsProtocol fees disabled · Fee Policy deferred
Verifying secure session
Checking the authenticated Tenant catalog and browser session. No product operation is available until verification completes.
Verifiable Credit Infrastructure
Verifiable Credit Infrastructure for Humans and Agents
Identity, authority, capital, obligations, execution, repayment, and verified outcomes—coordinated through one shared credit kernel.
Private account, wallet, and credit data stay hidden until the exact Tenant workspace is verified. The hosted experience uses synthetic capital and grants no real-funds authority.
The Credit Loop
IdentityAuthorityIntentOfferObligationRepayCredit State
Borrow → Build → Repay → Prove
Turn each verified outcome into stronger, permissioned Credit State for the next capital decision.
A payment can show that value moved. Credit must preserve who committed, under whose authority, on which terms, what became owed, what happened afterward, and whether that outcome can become reusable credit.
Payments askDid value move?Credit must also askWho is responsible—and what did they prove?
One kernel · two native entry modes
Different interfaces. One economic truth.
Human and Agent experiences converge on the same Offer, Obligation, Ledger, servicing, Evidence, and Credit State model.
The Agent economy needs more than faster payments.
IPO.ONE turns identity, authority, obligations, execution, and repayment into verifiable Credit State—giving Humans and Agents a path from one successful outcome to the next source of capital.
Human WorkspaceCurrent statusNot startedChecking server
Portfolio command center
Your portfolio overview
Review your current credit position, next payment, and verified activity from one workspace.
Available creditUnavailable
OutstandingUnavailable
Next payment—
Evidence track recordNot loaded
Borrowing shortcuts
Start from the user you are serving
Human and Agent use different authority, then converge on the same Decision, Offer, Obligation, repayment, and Evidence record.
IPO.ONE products
Choose what you want to do
Each product keeps its own purpose while using the same identity, obligation, repayment, and Evidence record.
Loading authenticated server truth
Workspace recovery and owned reads are still pending. No amount is inferred in the browser.
Workspace detailsIdentity, authority, and product status
Access modes
Human and Agent, one shared kernel
The interface and authority method change. Obligation, Ledger, risk, servicing, and Evidence do not fork.
Human Workspace
Application & Obligation
Not started
Consent, deterministic Offer, exact acceptance, repayment schedule, servicing, and owner Evidence remain one Human path.
Offer
Not requested
Obligation
Not created
Servicing
Not started
Agent Workspace
Identity & bounded authority
Principal setup
The Human Principal binds CAIP-10 identity and a scoped Mandate. The Agent receives machine-readable capability, never credentials or funds authority.
Subject
Not created
Account proof
Not submitted
Mandate
Not created
Verified activity
Recent credit activity
Base Sepolia · one exact market · test assets only
Secured Pool, read from server truth.
The same canonical Pool state supports Human liquidity and secured-credit positions. IPO.ONE verifies the approved deployment and reads a safe block; this page cannot sign or submit a transaction.
Not loaded
Independent truth axes
What IPO.ONE can verify right now
A deployed contract can remain true even when RPC, indexer, reconciliation, or a private AccountBinding is unavailable.
DeploymentNot loadedExact profile not yet checked
RPCNot loadedNo safe block observed
IndexerNot loadedFinalized projection not yet checked
ReconciliationNot loadedNo current comparison loaded
MarketNot loadedLiquidity remains unknown until read
SubmissionUnavailableNo signer or transaction primitive
Public market · test USDC / WETH
Current read-only market
Base Sepolia exact Pool · waiting for server read
No real funds
Available liquidityUnavailableTest USDC asset units
Gross debtUnavailableTest USDC asset units
UtilizationUnavailableServer-derived basis points
LP claimUnavailableTest USDC asset units
Contract
Unavailable
Market ID
Unavailable
Safe block
Unavailable
Observed
Unavailable
Oracle
Unavailable
New-risk control
Unavailable
Private position · Subject + AccountBinding required
My authorized Pool position
Public market data never grants access to a private position. IPO.ONE returns position values only for the authenticated Actor's owned Subject and active execution AccountBinding.
Not loaded
AccountBindingUnavailable
My positionUnavailable
Supply claimUnavailable
HealthUnavailable
Read-only scenario review
Reviewing a hypothetical action only reports blockers and a preview. It creates no signature, allowance, RPC write, transaction, or funds movement.
Reviewed scenario
—
Exact amount
—
Submission authority
Unavailable · no transaction will be submitted
Refresh server truth first. An authoritative zero will be shown as zero; unavailable data will remain unavailable.
Human credit
Know every term. Own every step.
See your terms before you accept, follow one clear repayment plan, and verify every lifecycle event—all without real funds.
Your journeyGuided from request to repayment
DecisionsTerms explained before acceptance
Funds modeNo real funds
Your guided path
Start with a private sandbox profile
Step 1 of 5
We will create an opaque profile and purpose-limited Consent. No name, bank login, wallet credential, or raw KYC is requested here.
1
Get readyPrivate profile and Consent
2
RequestAmount and schedule
3
Review termsDecision and exact Offer
4
ActivateSandbox Obligation
5
Repay & verifySchedule and Evidence
Product protectionsView protocol controls and safety boundariesPrivate protocol approved
ExecutionSigned sandbox rail + shared ledgerAvailableNo real movement
Intent, Decision, Offer, exact acceptance, and shared Obligation use one approved private protocol. Capital, custody, disbursement, and production funds stay disabled.
Authenticated application
Request and price no-funds credit
Choose an amount and schedule. You will see an explainable Offer before anything is created.
Checking private gateway
04
Your sandbox credit planObligation created
Pending execution
Lifecycle
Created
Servicing
Current
Days past due
0
Schedule
v1
Outstanding
$0.00
Interest due
$0.00
Total repaid
$0.00
Technical references
Obligation ID
—
Sandbox rail receipt (offchain)
Not executed
Early partial or full repayment is available after execution with no sandbox prepayment penalty. Fee → interest → principal; surplus is not posted.
M3 · public authenticated no-funds
Metered inference resource
Checking the exact hosted synthetic Provider profile. No external Provider or real funds are used.
Checking
Provider / resource
Not loaded
Authorization cap
Not loaded
Consumed / remaining
Load Evidence
Current Obligation
Not created
Repayment
Not available
Usage Evidence
Not loaded
Public-chain verification
Base Sepolia anchor
Not anchored. This sandbox Obligation and its repayments currently exist in IPO.ONE PostgreSQL only; no Base Sepolia transaction exists for this lifecycle.
Developer detailsProtocol receipts and operation names
Authenticated protocol resultsOne server receipt per completed step
01
Authority preflightpilotReadHumanSelf
Waiting for server
02
Credit IntentpilotRequestCredit
Waiting for server
03
Application readpilotReadCreditApplication
Waiting for server
04
Decision & OfferpilotEvaluateCreditApplication
Waiting for server
05
Exact acceptancepilotAcceptCreditOffer
Waiting for server
06
No-funds executionpilotExecuteSandboxObligation
Waiting for server
PILOT-006 · public Beta feedback
Tell us where the product worked—or blocked you.
Choose structured signals only. This form has no comment box and accepts no name, contact detail, wallet address, KYC, or other PII.
Ready when Subject is loaded
Create or restore your Human Subject to submit one immutable categorical receipt.
Categorical only · actor-owned Subject · no third party · no underwriting effect · sandbox only
PILOT-008A · cases & corrections
Flag a record without rewriting it.
Select one record already visible in your workspace and a closed reason. The original remains immutable; any correction is an additive Evidence event.
Not loaded
Create or restore your Human Subject, then select one current record.
No free text or uploads · original record immutable · additive correction only · no automatic credit or balance change
Optional Agent pathNeed an Agent to act for you?Configure identity and bounded authority without sharing credentials or funds access.Principal controlled
Principal-controlled Agent setup
Create, review, and activate Agent authority
The authenticated Human Principal defines a bounded Mandate. The Agent receives IDs for the Agent API handoff, never permission to change or activate its own authority.
Not started
Principal authority checkVerifying Principal access
The Agent authority workflow remains locked until the authenticated workspace is verified.
Excluded from parityIdentity, authority IDs, transport
No lender or facility is liveNo capital provider, real disbursement, withdrawable balance, mainnet action, or production underwriting is enabled by this journey.
Private credit evidence
Checking server
Decision Passport sharing
This v1 artifact is a temporary, read-only view of the facts behind one current credit Decision—not a repayment-history Passport. You choose one authorized reviewer, how long access lasts, and exactly which facts are disclosed. Terminal repayment history appears separately in Credit Track Record.
Server-derived state
No Decision Passport loaded
Complete or restore an authenticated credit application. This view will not manufacture a score, Decision, or shareable proof.
Optional advanced sharing
Share the current Decision
Private · expiring
Normal credit and Passport review need no internal identifier. Open this only when an invited same-Tenant reviewer has supplied its exact Actor reference.
Advanced: share with an exact invited reviewer
Complete a current Decision first. The verifier is never discovered or suggested by the browser.
Current sharing status
Shared Passport
Not loaded
Recover an existing Passport by technical ID
Proof version
—
Issuer
—
Permitted use
Private credit review
Active period
—
Review access
One bound same-Tenant reviewer
Disclosed facts
—
Issue or read an authorized artifact to inspect its selected, evidenced disclosures.
Technical receipt and integrity digests
Source Decision Passport digest
—
Passport artifact digest
—
These hashes verify integrity. They are not blockchain transaction hashes; public-chain status is shown separately in the Obligation Evidence receipt.
No artifact is trusted until an authenticated server read succeeds.
Verifier toolVerify a received proof onlineNot verified
Verification requires the exact authenticated verifier, current same-Tenant Membership, purpose, hash, version, source, and trusted server time.
Real local
Private proof lifecycle
Four authenticated operations create, read, verify, and terminally revoke a versioned artifact.
Safety invariant
Evidence, not a score
Only selected factor grades, canonical reason codes, and exact Evidence lineage can be disclosed.
Prohibited
No bearer sharing
No public link, QR, download, credential, signature, cross-Tenant verifier, or production authority exists.
Principal-controlled Agent credit
Authorize once. Keep every limit visible.
A Human Principal approves identity and bounded authority before an Agent receives any application or runtime handoff.
IdentityPrincipal setup required
AuthorityNo Mandate
Funds modeNo real funds
Developer Agent integration
Versioned integration truth
One online Agent path. Thirteen protected operations.
Run the registered local reference Agent online or connect an external Agent through the protected HTTPS contract. Credentials remain server-side and every call is reauthorized.
One manifest. Fifteen local tools. No ambient authority.
Checking contract
Manifest—
Registry parity—
Transport—
Workflows—
Waiting for authenticated catalog and Principal state.
Principal-observable Agent lifecycle
Check authenticated Agent progress online
Waiting for Mandate
Create a verified Agent Subject and Draft Mandate first. The external Agent uses its own credential; this Principal browser reads only durable server truth.
ApplicationNot started
OfferNot loaded
ObligationNot created
Provider spendNot executed
Revenue → repaymentNot posted
EvidenceNot loaded
What “use credit” means: the Agent executes one Mandate-approved purpose through the non-withdrawable sandbox rail. It cannot transfer the credit to an arbitrary wallet. The external Agent uses its own durable, revocable credential; the Principal browser can only check sanitized, persisted workflow receipts.
Human-controlled authority
Principal binding
Waiting
Principal
—
Agent Subject
—
Subject state
—
Control
Principal only
Hash-only CAIP proof
Account proof
Waiting
Chain
—
Purpose
—
Verification
—
Proof hash
—
Raw accounts, signatures and reusable proofs never enter this presentation.
Exact sandbox scope
Mandate
Waiting
Mandate
—
Capabilities
—
Limit
—
Expires
—
Active Mandates cannot be edited in place.
Developer API and workflow details
agent_mcp_registry.v2
Approved Agent API operations
Checking
Catalog presence is not authorization. The Host rechecks Subject, Mandate, admission and policy on every call. Approved local stdio MCP tools remain available as an optional developer transport.
Typed SDK compositions
Three staged workflows
Local only
IdempotencyStable workflow + command IDs
ErrorsProblem Details + stable MCP codes
EvidenceOwned hash-only immutable reads
ConformanceRegistry · SDK · browser parity
Optional developer tooling
CLI reference runner
The CLI remains an optional integration and debugging tool. Normal product testing uses the online reference Agent above; external Agents call the protected HTTPS API with their own credential.
The document describes authentication requirements but contains no credential or production endpoint.
Exact unavailable capabilities
Not hidden. Not implied. Not enabled.
Disabled
Capital provider workspace
Checking private gateway
Capital Partners
Review an exact borrower-authorized Passport, set transparent sandbox terms, and monitor the resulting Obligation from execution through repayment and Evidence.
No funds authority
AccessSign-in required
Pre-provisioned operator with a dedicated least-privilege role.
Capital modeSynthetic bilateral
No deposit, custody, withdrawal, or production capital.
ReportingServer-derived
Offer, Obligation, servicing, repayment, and anchor coverage.
Sign in through the invited Capital Partner workspace to restore borrower-authorized applications from server truth.
Canonical Offer receipt
Terms and authority
credit_offer.v2
Partner
—
Validity
—
Technical Offer receipt
Profile
—
Offer ID
—
Offer hash
—
Terms hash
—
Borrower
—
Server-composed read model
Portfolio and Facility truth
Not loaded
Offers0
Committed$0.00
Outstanding$0.00
Repaid$0.00
Portfolio values come from canonical Offer, Obligation, servicing, repayment, and Evidence projections.
Explicit Phase 2 boundary
Bilateral terms are enabled; money movement is not
This workspace can review a bounded Passport, issue an exact synthetic Offer, and monitor canonical lifecycle truth. Public pools, deposits, custody, allocation, withdrawals, and real capital remain disabled.
DepositNo real-capital or custody railAllocate fundsSynthetic Offers create no balanceWithdrawNo withdrawable capital exists
Provider workspace · no funds
Checking server
Provider Network
Inspect one assigned sandbox intent from the authenticated Provider boundary. Exposure, delivery, and reconciliation remain server-derived, nonwithdrawable, and explicitly not deployed capital.
Use the exact TransferIntent ID from your Provider assignment or invitation. This page cannot search for assignments; missing, expired, denied, and cross-Provider resources are not enumerated.
Current server state
No Provider intent loaded
The browser does not infer Provider exposure, facility state, earnings, or reconciliation from prototype data.
Mandate-bound assignment
Provider mandate
Not loaded
Provider
Server required
Purpose
Server required
TransferIntent
Server required
Funding authority
No · presentation only
Assigned no-funds exposure
Facility presentation
Not deployed capital
No server amount
Asset unavailable until an exact intent is loaded.
Reconciliation receiptNot loadedNot a settlement or funds receipt
Delivery integrityNot loadedSigned local boundary only
Acknowledgement is not funding, settlement, custody, or withdrawal authority. Exact retries reuse one idempotency key.
Historical example only · unapproved
Earnings simulation
Not pricing policy
No simulation amount
Example rate: 1.25% of an exact loaded sandbox amount. It is nonbinding, unapproved, and cannot create Ledger, Evidence, or Provider entitlement.
Explicitly unavailable
Capital actions remain disabled
Human gate required
Join public poolPublic LP access is not enabledFund facilityNo Provider funding authorityWithdrawNo withdrawable balance existsSet production pricingPricing policy requires human approval
No TVL, public LP, remote Provider, mainnet, real capital, custody, or withdrawable balance is enabled.
Hyperliquid MVP · local no-funds
Checking contract
Trading Capital
Hyperliquid testnet is the only MVP venue for this authenticated Facility and canonical Obligation. This local screen inspects and closes an existing synthetic Facility and lets the accountable Principal create or revoke the exact pre-signing Agent authorization. Facility creation, matching, funding simulation, and execution setup remain role-scoped API/SDK workflows. Other venue adapters remain disabled; no nonce, signature, redeemable settlement, external execution, or remote MCP is implied.
0 / 28
catalog parity
Exact bound resource only
Load one synthetic Facility
Not loaded
Use the Facility ID returned by an authorized Trading Capital API/SDK workflow. This page does not create or discover Facilities; denied, missing, and cross-Tenant resources remain non-enumerating.
Principal-controlled · pre-signing only
Agent Facility authorization
Not checked
AuthorizationUnavailable
Valid untilUnavailable
AuthorityOpen / protective close
Signer / nonce / fundsNot granted
Load one exact Facility first. Creation and revocation require the authenticated Principal workspace; the Agent may only read the current authorization.
M2B-002 · read-only gate
Hyperliquid Testnet pre-write readiness
Blocked pre-write
CompositionNot available
External nonceNot allocated
SignatureNot created
Network submissionNot called
Exact launch profileDistinct reviewed profile is missingComposition and accountDurable binding and fresh reconciled read are requiredSigner and run approvalFresh non-exporting handoff and one-use Founder approval are required
This is a queryable STOP receipt, not an execution control. Load the exact Facility and authorization to recover current server truth.
M2B-003 · dual-risk recovery
Pool health + Venue margin recovery
STOP · no current incident
Combined riskUnknown
Current stageFreeze new risk
Protective authorityCannot expand risk
External writeNot authorized
1 · Freeze and cancelFreeze new risk before any reviewed protective action2 · Reduce / flatten and reconcileUnknown or stale truth stays at least reduce-only3 · Repay / liquidate and settleLoss remains outstanding until additive Evidence resolves it
Load the exact Facility and authorization to recover current dual-risk STOP truth.
Overview
Server contract availability
Catalog required
FacilityUnavailable
Canonical ObligationUnavailable
SettlementUnavailable
Performance ProofUnavailable
Deterministic close path
Settle & prove
Synthetic only
Run settlementWorker-controlled · synthetic onlyWithdrawNo withdrawal product path
The settlement worker accepts no caller-supplied PnL, fee, cost, or price. It conserves synthetic contributions, creates no second Ledger, and cannot move production funds.
Authentication + bounded execution
Checking server
Wallet & Permissions
IPO.ONE login identifies the Actor and workspace. A separate execution AccountBinding proves control of one external account; only canonical Mandate, CreditLine, Obligation, and risk state can derive bounded execution authority.
Current server session
Checking authentication
No wallet or server-session authority is assumed before verification.
Server authority matrix
Effective wallet permissions
Checking
Selected Provider
None selected
Wallet account
Not bound
Network
Not bound
Authority lifecycle
Unknown
CapabilityEffective stateEnabled
Only a current server session can authenticate a wallet. No catalog entry grants token approval, arbitrary transaction, withdrawal, or funds authority.
Execution account · not login
Connect & bind an account
Not connected
Choose a discovered wallet and approved network in the existing sign-in panel, then connect it here to the current authenticated Human or Agent Subject. The proof is one-use EIP-712 and creates neither a login session nor economic authority.
Authenticated Subject
Unavailable
Connected account
Not connected
Approved network
Not selected
AccountBinding
Not verified
Sign in to IPO.ONE first. Wallet connection and AccountBinding never replace authentication.
Canonical authority → exact execution
Prepare, simulate & preflight
No authority derived
The Gateway resolves the exact approved TransferIntent and constructs calldata and ExpectedEffects on the server. Browser-authored transaction payloads are never accepted.
DelegatedWalletGrant
Not prepared
Capacity
Zero until derived
Preflight
Not run
Submission
Disabled · local no-funds
Exact server references
These references are validated against current server projections. They do not let the browser choose an address, calldata, amount, asset, or effects.
Submit transactionUnavailable · local no-funds runtime
Connect and bind an execution account. Current local runtime can prepare Evidence but cannot submit a transaction or move funds.
Real local
Authentication remains separate
Existing OIDC/SIWE session, Tenant, Actor, Role, and recovery semantics are unchanged by execution account actions.
Real local
Human + Agent AccountBinding
One dual-native proof contract binds an execution account to an existing Subject and grants zero authority by itself.
Submission disabled
Exact resolver & Evidence
Gateway-owned atomic persistence records reservation, prepared execution, simulation, preflight, Events, Evidence, and outbox without moving funds.
Owned obligations
Every position, reconciled to server truth.
Review bounded owned references, exact current state, schedule, authority, sandbox rail, and immutable Evidence.
Selected shared position
Obligation status
Not loaded
Original principal—
Annual rate—
Maturity—
Outstanding total—
Refresh exact owner-authorized server state before relying on an amount or status.
Bounded owned-resource composition
My obligations
Not loaded
Current positions0/0
OutstandingHidden
Past dueHidden
Total repaidHidden
Sign in to recover bounded Actor-owned Obligation references.
Exact authorized references
Positions
Unrefreshed or denied references reveal no financial values.
Select a current position
Refresh server state, then select one exact Obligation. Browser state is never financial truth.
Shared obligation.v2
Current position
—
Entry authority—
Execution rail—
State freshness—
Servicing——
Technical references
Obligation
—
Execution receipt
—
State version
—
Outstanding principal—
Interest + fees—
Past due—
Total repaid—
Hosted synthetic Provider
Metered inference resource
Provider / resource
Not loaded
Authorization cap
Not loaded
Consumed / remaining
Load Evidence
Latest usage Evidence
Not loaded
No external Provider or real funds are enabled.
Canonical schedule
Payment plan
Append-only Evidence
Version history & corrections
Load Evidence to verify immutable state changes.
Read boundary
One state machine, exact owner reads
Human Consent and Agent Mandate change entry presentation only. List references come from the bounded authenticated workspace and every value is reauthorized by exact Obligation ID.
Human repayment
Repay with the schedule in view.
Post synthetic repayment against the exact shared Obligation and inspect deterministic allocation.
Shared servicing kernel
Servicing Case
No Obligation
Authenticated server truth
My positions
0/0 current
Refresh to load current balances and trusted-time servicing state for these authorized references.
Only Actor-bound opaque references are shown. Select one position to load its exact authorized state.
No active case
Accept and execute one exact sandbox Obligation to open its servicing view.
Exact Obligation—
Policysandbox-servicing-policy.v1
Trusted as of—
Past due$0.00No past-due amount
Outstanding$0.00Schedule v1
Days past due0Current
Next due—$0.00 repaid
Trusted-time progression
Case stage
Current
DPD is derived by the authenticated worker; this page cannot change time or classification.
Existing repayment operation
Cure or repay
Execute the sandbox Obligation before posting a repayment.
Past-due principal
$0.00
Past-due interest
$0.00
Past-due fees
$0.00
Fee → interest → principal. Cure is confirmed only by the returned Obligation.
Immutable schedule
Payment plan
ClockTrusted UTC only
PenaltyNone
DispositionOperations + Risk
FundsNo real funds
Provider sandbox
Signed Provider boundary verified
One fixed loopback Provider can receive an exact assigned intent, acknowledge it, and return a signed callback without duplicating canonical state.
DeliverySigned
AcknowledgementBound
CallbackVerified
ReplayExactly once
ReconciliationClean
Capability status only — this Obligation has no Provider execution. Loopback, synthetic, no-funds, nonwithdrawable; public or remote Provider access remains disabled.
Owner Evidence
Verify the lifecycle, not a screenshot.
Load redacted immutable events for the exact Obligation owned by this authenticated Human session.
Shared immutable timeline
Obligation Evidence
Not loaded
ObligationNot created
Events loaded0
Server Evidence stateWaiting
As ofNot queried
Session projection only. Durable Evidence is loaded through the already-approved owner or Agent Evidence operation; this page creates no new read permission.
EVIDENCE-001C · Base Sepolia
Checking operation
Public Registry Evidence
Verify one finalized, redacted testnet credit-registry lifecycle without treating it as the signed-in user’s own repayment record.
Synthetic only
Enter one exact public authorization hash. The authenticated Gateway returns only the bounded synthetic Base Sepolia observation.
Final stateNot queried
Registry contract—
FinalityWaiting
ObservedNot queried
Observation hash—
Finality proof hash—
Lifecycle eventTransactionBlockServer state
Auditor workspace
Obligation Evidence
Inspect the durable server lifecycle behind one shared Human or Agent Obligation.
Events loaded0
Server Evidence stateWaiting
Last recordedNot queried
EVIDENCE-001A
Durable audit timeline
Auditor access
Enter an exact Obligation ID. Access is verified by the private Gateway.
Read the durable Credit State rebuilt from finalized terminal Credit Outcomes. Browser history is not credit truth, and this qualitative record cannot authorize funds or change a limit automatically.
Current record
No verified lifecycle loaded
Restore an owned Subject and load its outcome-derived Credit State. No positive history is inferred from an empty browser state.
Finalized outcomes only
Durable Credit State
Not loaded
Decision Passport
Not loaded
Completed cycles
0
Latest terminal outcome
Not loaded
Repayment reliability
Not loaded
Total loss
$0.00
Server-backed
Outcome-derived record
Only finalized on-time, late or modified, and written-off Credit Outcomes can update this state.
Non-authorizing
Qualitative factors
No universal score, wallet-history inference, funds authority, or automatic limit change is created.
Server-backed
Generated report
Create a bounded JSON or formula-safe CSV artifact from the exact owned Obligation and its persisted Evidence.
Server-generated artifacts
Checking server
Reports & Exports
Create, inspect, retrieve, and revoke a bounded report derived from the current owned Obligation and its persisted Evidence. The browser transports exact verified bytes; it does not author official content.
Current artifact
No official report loaded
Load an owned Obligation first. Report content is generated and hashed by the server from bounded, redacted Evidence.
Authenticated command
Create official activity report
No funds
The server reauthorizes the exact owned Obligation and limits the source to 50 redacted Evidence events.
Authorization rechecked
Read or retrieve exact artifact
Not loaded
Every read and retrieval revalidates active same-Tenant ownership. Expired or revoked artifacts are unavailable.
Server metadata only
Artifact integrity
Not loaded
Content SHA-256
—
Artifact hash
—
Evidence source
—
Expires
—
Authorization
Rechecked on access
Production fee policy
Unavailable · principal and unrealized PnL excluded as fee bases
No HTML export, public link, bearer grant, PII, secret, raw transaction, signed URL, production fee calculation, mainnet authority, or real-funds authority is created.
Permissioned control plane · WEB-008
Portfolio risk, with protective action.
Read one exact tenant portfolio and freeze one exact Agent Subject through the authenticated Gateway. Every result is policy-bound and PII-free.
Not loaded
M2 Pool control view · aggregate only
Solvency, oracle, reconciliation
No account address, raw transaction, signer, or liquidation submission is exposed.
Not loaded
DeploymentNot loadedExact profile not yet checked
RPCNot loadedNo safe block observed
IndexerNot loadedProjection not yet checked
ReconciliationNot loadedNo comparison loaded
MarketBase Sepolia reference market
Positions0
Liquidatable0
Discrepancies0
Load the exact authorized Tenant risk portfolio first.
Aggregate exposure
Tenant portfolio posture
No verified query yet.
Restoring the authorized Tenant portfolio from server truth.
Technical details
Portfolio reference
Not recovered
Queue reference
Not recovered
Approved limits$0.000 credit lines
Utilized$0.000% utilization
Outstanding$0.000 open Obligations
Adverse states0Overdue + defaulted
Subjects
Identity posture
Credit lines
Capacity posture
Obligations
Servicing posture
Asset exposure
PII-free portfolio view
Not loaded
AssetLimits / utilizedOutstandingAdverse
PILOT-005 · privacy-safe product truth
Public Beta lifecycle health
Aggregate Human and Agent progress from durable protocol facts—without trackers, raw identifiers, KYC, or borrower PII.
Not loaded
Load the Tenant portfolio to verify the product funnel.
Applications00% offered
Accepted00% of applications
Executed00% of applications
Repaid00% started repayment
Fully repaid00% completed
Human entry0 applications
Agent entry0 applications
Dual-native proofWaiting
Positions0 total · 0 open
Read-only · aggregate only · PII excluded · no third-party analytics · sandbox only · no production funds.
PILOT-006 · privacy-safe feedback truth
Public Beta experience
Aggregate categorical signals from Human and Agent entry modes. No feedback, Subject, Actor, wallet, KYC, or Event identifier is returned.
Not loaded
Load the Tenant portfolio to aggregate feedback.
Total signals0
Human / Agent0 / 0
Completed0
Needs support0
Blocked0
Most common blockerNone
Aggregate only · identifiers and PII excluded · no third-party analytics · no underwriting effect.
PILOT-008A · remediation queue
Cases & additive corrections
Review closed-category Human and Agent cases. Assigning, upholding, and correcting are explicit actions; none changes balances, limits, or the original record.
Not loaded
Risk, Operations, or Auditor access with recent MFA is required to read this queue.
Closed categories · no free text or PII · immutable source · additive correction Event · sandbox only.
REQ-PILOT-002 · Public Beta readiness
Public no-funds Beta operating readiness
The Founder activation decision is already approved. This read-only view tracks exact release, authentication, recovery, reconciliation, abuse-control, and Beta-notice verification without granting another activation authority.
Not loaded
Risk, Operations, or Auditor access with recent MFA is required. This view verifies delivery state and cannot change the approved launch policy.
Required controls7
Authorized1
Verify release6
Unavailable0
Release policyEnabled · no funds
Current candidateUnverified
Read-only · no names or contact details · no new activation decision · no launch-policy mutation · no real funds.
SERVICING-002B · private work queue
Adverse Obligation review
Trusted-time delinquency and default cases, ordered by severity. This surface is read-only and contains no borrower PII.
Not loaded
Risk or Operations access and recent phishing-resistant MFA are verified on every read.
Visible cases0
Critical0
Past due$0.00
Verified—
ObligationStagePast dueOutstandingReview
Read-only · PII excluded · no disposition authority · synthetic obligations only · no real funds.
V9-008 · checked-in control evidence
Operational assurance, without invented runtime state
Policy and runbook facts are separated from live Tenant reads. A checked-in control never becomes a current alert, reconciliation result, incident, or approval merely because it is rendered here.
Checking catalog
AlertsUnavailable
No operator alert read has been verified.
Policy evidence only
ReconciliationUnavailable
No current reconciliation run has been loaded.
Worker evidence only
IncidentsUnconfigured
No incident acknowledgement or resolution authority is exposed.
Runbook baseline only
Dual controlUnavailable
A proposal locator is never approval authority.
Exact command required
Configuration evidence is not live stateLoading the versioned control boundary…
Policy ceilings · Gateway still decides
Borrower, Risk, Operations, and Auditor remain separate
These rows describe checked-in maximum authority when the matching operation exists. They do not describe the current session and cannot bypass Membership, capability, recent MFA, resource ownership, live state, admission, or audit.
Recent MFA
ActorPortfolioQueueFreezeResolution
Health and aggregate feedback use their own recent-MFA capabilities. Catalog discovery never grants either read.
Protective-only command
Freeze Agent Subject
Step-up control
Suspends one exact pending or active Agent Subject. This surface cannot unfreeze, increase limits, move funds, or expand authority.
Select an authorized queue case for protective review. Selecting a case does not freeze it.
Risk or Operations authority is verified only when the command is submitted.
Explicitly unavailable
Closed permissions by design
Portfolio readPoint-in-time aggregates, no raw KYC or PII.
FreezeProtective-only, reason-bound, idempotent, and evidenced.
No inverse controlUnfreeze, limit increase, and generic emergency mutation remain unavailable.
No automatic actionAlerts and runbooks cannot repair state, resolve an incident, or move funds.
No demo resetHistorical prototype reset behavior is not an authenticated product control.
Break glassProtective-only, disabled by default, and unavailable in this browser.
Agent integration
From approval to action. No hidden authority.
Use one Principal-approved handoff with the approved local Agent Host. Credentials and real funds never travel in the packet.
A Human Principal creates the Agent Subject and sets exact sandbox limits before any machine workflow is available.
1
AuthorizePrincipal + bounded Mandate
2
Prove identityOne-use CAIP-10 proof
3
Request termsCredential-free handoff
4
Run & verifyObligation, repayment, Evidence
Local baseCurrent loopback origin
Tenant protocolChecking catalog
Agent SDKChecking manifest
Protocol versionChecking catalog
Agent MCPChecking manifest
HandoffAwaiting Mandate
Checked-in catalog + runtime response
V9 capability contract
Checking
Catalog maturity
Checking
Enabled transports
Checking
V9 destinations
0/13 verified
Safety
Real funds disabled
DestinationRequired server operationsCatalog
No diagram, prototype export, marketing label, or browser counter can add a capability absent from the authenticated catalog.
Machine-readable integrationView handoff packet, 15 Agent operations, OpenAPI, and request logWaiting for authority
Non-authorizing manifest
Principal → Agent capability packet
This non-authorizing packet advertises thirteen local Agent operations and three staged workflows. The loopback OpenAPI describes the server boundary; credentials and funds authority never enter the packet.
Servicing CasepilotReadOwnObligation + repayment + EvidenceSame state
Dual-chain conformanceLocal receipt verification, no RPCReceipt input
Structured pilot feedbackpilotSubmitPilotFeedback · closed categories · no PIITenant SDK
Authenticated request telemetry
Request log
Session VerifyingLast None0 requests
Access IPO.ONE
Sign in. Connect.Stay in control.
Choose a familiar account, then connect one approved test network. Identity proves who you are; Principal and Mandate rules still decide what you can do.
Authenticated session
You are signed in
Your secure host-only session has been verified. Product permissions remain controlled by your server-side role, Consent, and Mandate.
1
Choose your active workspace
One verified Human identity may be enrolled in more than one role. This session receives only the role selected here.
2
Choose how to sign in
One secure session across the Human and Agent workspaces.
Checking available sign-in methods…
Sign-in check needs attention
Check the server again or share a privacy-safe diagnostic with IPO.ONE support.
No compatible wallet is open
Open or install a compatible EVM browser wallet, then ask IPO.ONE to check this page again.
Secure session reset needs attention
Protected actions remain blocked. Retry the same server-bound invalidation before starting a fresh wallet sign-in.
Need help signing in?
Copy a privacy-safe diagnostic and send it to IPO.ONE support. It excludes cookies, wallet addresses, tokens, and private resource IDs.
Error
authentication_unavailable
Request ID
unavailable
Observed
Available browser wallets
Discovering browser wallets…
Wallet names and icons are untrusted display metadata. Selection stays in memory and never requests an account, network, or signature by itself. Account, network, Provider, or disconnect changes invalidate the previous host session before protected work can continue.
Authentication is not credit authority. A wallet address or Google account cannot create a Mandate, approve an Offer, or move funds.
3
Connect an approved network
Both test networks use the same chain-agnostic Obligation kernel.
WalletNot connected
NetworkBase Sepolia selected
Funds modeNo real funds
Your wallet will ask for account access and, if needed, permission to add or switch the selected test network.
Explicit action confirmation
Confirm sandbox action
Review the exact no-funds action before IPO.ONE submits it to the authenticated server.
Action
—
Confirmation
Authenticated account
Resource
—
Amount / effect
—
Public chain
Not submitted
Funds mode
No real funds
This confirmation does not create a blockchain transaction. A BaseScan link appears only after a separately verified Base Sepolia anchor transaction exists.