Independent machine-transaction verification layer

Don't trust.
Verify.

Machine commerce needs more than a payment success flag. MachinaLedger binds request, payment and service-response evidence into deterministic economic records so agents, operators and auditors can see exactly what was presented, what was checked, and whether the evidence changed.

Verification boundary: MachinaLedger does not claim that a service response is objectively true. It verifies evidence, deterministic checks, commitments, signatures and explicit trust policy.

VERIFICATION TRACEDETERMINISTIC
01
Request evidenceintent · authority · policy · request bytes
BOUND
02
Payment evidenceauthorization · settlement · rail adapter
CHECKED
03
Service responseobserved bytes · delivery hash · provenance
OBSERVED
04
Economic recordMEE · deterministic derivation · audit links
REPLAYABLE
05
Signed receipt / verifieroffline verifier + test issuer integrated · persistence/export in progress
INTEGRATED DEV
A valid signature can establish authenticity relative to a key. It does not turn an AI-generated or remote service response into objective truth.
89%verified development · 39/44 gates
64%stable source · 28/44 gates
5quality gates to official launch model
PREpublic availability · no launch date claimed
Road to launch

Progress backed by gates, not a marketing number.

The percentage changes only when a named quality gate passes and is integrated into the verified development line. Stable status is stricter: the gate must also be promoted into the stable source line. Task branches and this launch branch do not count.

Development status89%

Current milestone: Signed Economic Receipt persistence / export. Contract, strict parser, offline verifier and bounded test issuer are integrated in development; production signing keys remain disabled.

Stable source64%

Last verified development update: . Public production availability remains off until edge/TLS and remaining launch gates pass.

Verification Core

INTEGRATED

Deterministic economic records, evidence bindings, rail re-verification and replayable audit paths.

5/5 development · 4/5 stable source

Receipt Contract

INTEGRATED

Strict signed economic receipt envelope, result model, trust pins and compatibility rules.

4/4 development · 0/4 stable source

Offline Verifier

INTEGRATED

Portable verification without a MachinaLedger login, database or live payment execution.

4/4 development · 0/4 stable source

Ed25519

IN_PROGRESS

Issuer-authenticated receipts with strict key encoding, domain separation and trust separation.

2/3 development · 0/3 stable source

x402 Integration

INTEGRATED

x402-first evidence ingestion and verification feeding the protocol-neutral economic model.

5/5 development · 5/5 stable source

Persistence / Export

INTEGRATED

Append-only evidence, deterministic ledger projections, audit drill-down and restore-tested exports.

4/4 development · 4/4 stable source

API / SDK

INTEGRATED

Versioned API plus developer integration surfaces for agents, services and payment rails.

5/5 development · 5/5 stable source

Client Integration

INTEGRATED

Self-service organization setup, scoped credentials, sandbox proof and diagnostics.

4/4 development · 4/4 stable source

Security / Hardening

IN_PROGRESS

Tenant isolation, secret controls, rate limiting, reproducible release and public-edge acceptance.

4/5 development · 4/5 stable source

Discovery / Launch

IN_PROGRESS

Human landing, machine discovery, technical SEO, dedicated HTTPS and external catalog discovery.

2/5 development · 2/5 stable source

Live project status

What is happening now.

This is the public-safe status surface you can use instead of interrupting development for routine checks. It shows only verified state and never exposes private repository paths, internal identifiers, secrets or diagnostic telemetry.

Signed Economic Receipt persistence / export

IN_PROGRESS

Append-only persisted receipt lifecycle and tenant-scoped exact-byte export.

Private Owner Control Plane

IN_REVIEW

Read-only owner observability is under review before integration; write controls remain locked behind immutable command audit.

Public root / status cutover

DONE

Dedicated Nginx/TLS cutover is live for root, www, app, api and docs hostnames. Public root/status surface is serving over a valid MachinaLedger certificate.

Human + agent directory distribution

READY_TO_SUBMIT

Canonical HTTPS and machine-discovery smoke tests are green. Tiered human + agent directory submissions can begin.

Security & trust

Integrated baseline · 18 tracked gates

Latest security review: NO_FINDINGS.

Partial 8 · in progress 4 · planned 4 · blocked by live cutover 0.

Verification snapshot

39/44 development gates · 28/44 stable

Last verified update: .

Machine-readable status →

What is MachinaLedger?

A verification layer between machine action and economic history.

Autonomous agents can request services, authorize spend, pay through machine-native rails and consume responses at software speed. MachinaLedger creates a deterministic evidence trail across that transaction so later systems do not have to trust an agent's memory, a payment rail's dashboard or a mutable application log.

Verify

Evidence before interpretation

Bind the exact request, payment and observed service-response evidence that reached the verifier.

Record

Deterministic economic state

Derive versioned Machine Economic Events and downstream ledger views from retained evidence.

Recheck

Independent verification path

Signed receipt architecture is being designed so a verifier can check authenticity and content without trusting mutable application state.

The machine-commerce problem

Payments prove movement of value. They do not prove the whole transaction.

A settlement can show that money moved, while leaving open which request caused it, what authority existed, which service response was returned, whether later records were altered, and which accounting transformation produced the final ledger entry.

Fragmented evidence

Intent, authorization, payment, fulfillment and accounting often live in different systems with different identifiers.

Protocol churn

x402, MPP and future rails can evolve independently. A ledger that mirrors one transport becomes brittle.

AI is not a truth oracle

Intelligence can classify or explain. Deterministic transaction truth must come from versioned evidence and rules, not model confidence.

How it works

One explicit chain from intent to independent verification.

Every layer has a different job. The architecture avoids collapsing authorization, payment, service observation, cryptographic authenticity and legal/accounting interpretation into one ambiguous “verified” flag.

01Agent Intentwhat the agent wants
02Authoritywho may act
03Policywhat rules allow
04Requestexact operation
05Paymentrail evidence
06Service Responseobserved output
07Signed Economic Receiptsigned economic claim
08Independent Verificationrecheck + trust policy
Core invariant

Protocols stay at the edge.

x402 is first, MPP is already represented through an adapter, and future rails should enter the same way. The canonical economic history must survive protocol replacement.

JEV can be used as a separate intelligence/provider layer for bounded judgment. It is not the deterministic source of transaction truth.

01 · EDGEx402 · MPP · MCP · webhooks · future payment adapters
02 · EVIDENCEversioned ingress · provenance · append-only references · idempotency
03 · MEEMachine Economic Events · deterministic economic record
04 · VERIFYreceipt contract · Ed25519 authenticity · offline verifier · trust policy
05 · LEDGERaggregation · double entry · audit · accounting/invoice compatibility
Signed Economic Receipts

Authenticity should be checkable without trusting the database that issued the receipt.

The development line now contains a strict candidate receipt contract, schemas, golden vectors, parser/binding evidence and explicit trust boundaries. Contract acceptance is still pending; Ed25519 signing and the independent offline verifier are not released.

What a receipt is meant to bind

MEE content, issuer scope, organization scope, signing key identity, issuance time and the retained economic-record reference — all under a versioned canonical byte contract.

What a receipt must not imply

A signature does not prove delivered content was truthful, a wallet is a legal identity, current chain finality was rechecked, or a tax/accounting conclusion is legally correct.

MEE

Machine Economic Events turn evidence into a durable economic record.

MEE is the deterministic bridge between raw protocol evidence and downstream aggregation, ledger, audit and accounting views. It preserves explicit unknowns rather than inferring legal identity, tax context or valuation from payment data alone.

evidence → deterministic rules → Machine Economic Event │ ┌─────────────────────────┼─────────────────────────┐ ↓ ↓ ↓ audit aggregation ledger │ │ └──────────── accounting / invoice compatibility ────┘
Payment protocols

x402 first. Adapter architecture after that.

The stable source already contains x402 and MPP integration paths. The strategy is not to make one payment protocol the internal truth model; every rail must map evidence into the same canonical economic spine.

Primary

x402

Authorization, settlement, amount/party bindings and delivery evidence feed deterministic economic records.

Adapter

MPP

MPP evidence follows a versioned adapter path while preserving protocol-neutral downstream behavior.

Future

New rails

Future payment rails should add adapters, not fork the ledger or rewrite canonical economic history.

Use cases

Built for agents, businesses and the systems that must explain them.

Agent operators

Trace why an agent acted, which policy allowed it, what it paid and which result was observed.

API and service sellers

Attach economic evidence to machine-delivered services without making the payment rail your accounting database.

Finance teams

Project verified events into deterministic ledger and export layers while keeping unknown identity/tax context explicit.

Auditors

Drill from ledger outputs back to economic records and retained source evidence.

Agent platforms

Use scoped credentials, policy checks and protocol-neutral transaction records across many agents.

AI agents

Discover capabilities, protocols, roadmap and updates directly through versioned machine-readable resources.

Accounting & audit layer

Evidence-linked accounting compatibility, not automated legal certainty.

The stable source includes deterministic ledger/audit exports and technical invoice compatibility work. Production accounting posting, real invoice issuance and tax determination are intentionally separate gates and are not implied by a verified machine payment.

Double-entry projections

Deterministic balanced projections can be rebuilt from accepted economic records.

Audit drill-down

Downstream outputs retain links back through MEE to source evidence and transformation rules.

Explicit blockers

Unknown business identity, valuation or tax context remains unknown until authoritative context exists.

Trust & security model

Fail closed. Separate integrity, authenticity and truth.

MachinaLedger treats cryptographic and deterministic guarantees as specific properties, not as a universal “trust score.”

Integrity

Hash commitments and deterministic replay detect changed content relative to an expected commitment.

Authenticity

Signed receipt architecture adds issuer authentication relative to a key; embedded keys are not automatically trusted.

Truth boundary

Objective truth of a remote service response is outside what a signature or receipt alone can establish.

Current build activity

Public-safe development updates.

This feed describes product milestones only. It intentionally excludes internal task branches, private commit identifiers, infrastructure paths and diagnostic telemetry.

Public status surface is live

machinaledger.com now serves the verified public status/discovery surface over a dedicated MachinaLedger TLS certificate. Root, www, app, api and docs hostnames are isolated under the MachinaLedger edge configuration.

Agent Security & Trust Program integrated

A versioned agent-commerce security program is now integrated in the verified development line, including per-interaction zero trust, authority-impersonation defense, threat-intelligence contracts and incident-response gates. Runtime enforcement work continues on explicitly open gates.

Signed Receipt verifier and test issuer integrated

The strict offline verifier and bounded test-only Signed Economic Receipt issuer are integrated in development. Receipt persistence/export is the current receipt milestone; production key custody remains disabled.

Signed receipt review package advanced

Versioned receipt contract, result/trust schemas, golden/parser/binding vectors and an explicit review decision worksheet are integrated in the verified development line. Contract acceptance remains pending.

Independent receipt gap analysis started

The development line separated integrity, authenticity, issuer trust, evidence replay and service-response truth into explicit verification boundaries.

Internal launch readiness passed

Self-service onboarding, sandbox first-event flow, diagnostics, isolation and release regression gates passed internally; external users were still blocked on public web and HTTPS readiness.

V1 release candidate gates passed

Reproducible build, dependency/security checks, PostgreSQL restore, SDK tests and machine acceptance passed with public deployment still disabled.

Protocol-neutral event core completed

x402 and MPP retained history replayed through a versioned canonical agent/economic event spine without rewriting accepted evidence.

For developers

Integration contracts are inspectable before public cutover.

These resources describe the promoted source and current pre-launch integration model. They do not claim that production public endpoints are already live.

Early access

Prepare the integration now. Activate after the gates are green.

MachinaLedger is not declaring public production availability yet. Early integrators can inspect the API shape, protocol adapters and machine-readable status, then watch the update feed or the Agent Watchlist contract for the public cutover.

PUBLIC API · NOT YET DECLARED LIVE
SIGNED RECEIPT RUNTIME · NOT RELEASED
OFFLINE VERIFIER · PLANNED
REAL BILLING / PRODUCTION POSTING · OFF
FAQ

Precise answers, no trust theatre.

Is MachinaLedger a payment processor or wallet?

No. The initial product is a verification, evidence and accounting-compatibility layer. Funds do not need to flow through MachinaLedger.

Does “verified” mean the service response is true?

No. It means specific evidence and deterministic checks reached a defined result. Authenticity, evidence replay, current-chain status and service-response truth are separate properties.

Is MachinaLedger open source?

No public open-source claim is made. The product repository is private. If an independent verifier is published separately later, that status will change only after it is actually public.

Is MachinaLedger only for x402?

No. x402 is the primary rail, MPP is already represented through an adapter, and future payment rails are expected to use the same adapter boundary.

Can I use the production service today?

Not from this pre-launch page. Stable-source contracts exist, but public production availability is a separate gate and is not declared live yet.

How is the progress percentage calculated?

By a versioned set of 44 pass/fail quality gates. Only integrated gates count for development; only promoted gates count for stable source. Commits, PRs and task branches do not count.