Verification Core
INTEGRATEDDeterministic economic records, evidence bindings, rail re-verification and replayable audit paths.
5/5 development · 4/5 stable source
Machine commerce needs more than a payment success flag. MachinaLedger binds request, payment and service-response evidence into deterministic economic records so agents, operators and auditors can see exactly what was presented, what was checked, and whether the evidence changed.
Verification boundary: MachinaLedger does not claim that a service response is objectively true. It verifies evidence, deterministic checks, commitments, signatures and explicit trust policy.
The percentage changes only when a named quality gate passes and is integrated into the verified development line. Stable status is stricter: the gate must also be promoted into the stable source line. Task branches and this launch branch do not count.
Current milestone: Signed Economic Receipt persistence / export. Contract, strict parser, offline verifier and bounded test issuer are integrated in development; production signing keys remain disabled.
Last verified development update: . Public production availability remains off until edge/TLS and remaining launch gates pass.
Deterministic economic records, evidence bindings, rail re-verification and replayable audit paths.
5/5 development · 4/5 stable source
Strict signed economic receipt envelope, result model, trust pins and compatibility rules.
4/4 development · 0/4 stable source
Portable verification without a MachinaLedger login, database or live payment execution.
4/4 development · 0/4 stable source
Issuer-authenticated receipts with strict key encoding, domain separation and trust separation.
2/3 development · 0/3 stable source
x402-first evidence ingestion and verification feeding the protocol-neutral economic model.
5/5 development · 5/5 stable source
Append-only evidence, deterministic ledger projections, audit drill-down and restore-tested exports.
4/4 development · 4/4 stable source
Versioned API plus developer integration surfaces for agents, services and payment rails.
5/5 development · 5/5 stable source
Self-service organization setup, scoped credentials, sandbox proof and diagnostics.
4/4 development · 4/4 stable source
Tenant isolation, secret controls, rate limiting, reproducible release and public-edge acceptance.
4/5 development · 4/5 stable source
Human landing, machine discovery, technical SEO, dedicated HTTPS and external catalog discovery.
2/5 development · 2/5 stable source
This is the public-safe status surface you can use instead of interrupting development for routine checks. It shows only verified state and never exposes private repository paths, internal identifiers, secrets or diagnostic telemetry.
Append-only persisted receipt lifecycle and tenant-scoped exact-byte export.
Read-only owner observability is under review before integration; write controls remain locked behind immutable command audit.
Dedicated Nginx/TLS cutover is live for root, www, app, api and docs hostnames. Public root/status surface is serving over a valid MachinaLedger certificate.
Canonical HTTPS and machine-discovery smoke tests are green. Tiered human + agent directory submissions can begin.
Latest security review: NO_FINDINGS.
Partial 8 · in progress 4 · planned 4 · blocked by live cutover 0.
Last verified update: .
Autonomous agents can request services, authorize spend, pay through machine-native rails and consume responses at software speed. MachinaLedger creates a deterministic evidence trail across that transaction so later systems do not have to trust an agent's memory, a payment rail's dashboard or a mutable application log.
Bind the exact request, payment and observed service-response evidence that reached the verifier.
Derive versioned Machine Economic Events and downstream ledger views from retained evidence.
Signed receipt architecture is being designed so a verifier can check authenticity and content without trusting mutable application state.
A settlement can show that money moved, while leaving open which request caused it, what authority existed, which service response was returned, whether later records were altered, and which accounting transformation produced the final ledger entry.
Intent, authorization, payment, fulfillment and accounting often live in different systems with different identifiers.
x402, MPP and future rails can evolve independently. A ledger that mirrors one transport becomes brittle.
Intelligence can classify or explain. Deterministic transaction truth must come from versioned evidence and rules, not model confidence.
Every layer has a different job. The architecture avoids collapsing authorization, payment, service observation, cryptographic authenticity and legal/accounting interpretation into one ambiguous “verified” flag.
x402 is first, MPP is already represented through an adapter, and future rails should enter the same way. The canonical economic history must survive protocol replacement.
JEV can be used as a separate intelligence/provider layer for bounded judgment. It is not the deterministic source of transaction truth.
The development line now contains a strict candidate receipt contract, schemas, golden vectors, parser/binding evidence and explicit trust boundaries. Contract acceptance is still pending; Ed25519 signing and the independent offline verifier are not released.
MEE content, issuer scope, organization scope, signing key identity, issuance time and the retained economic-record reference — all under a versioned canonical byte contract.
A signature does not prove delivered content was truthful, a wallet is a legal identity, current chain finality was rechecked, or a tax/accounting conclusion is legally correct.
MEE is the deterministic bridge between raw protocol evidence and downstream aggregation, ledger, audit and accounting views. It preserves explicit unknowns rather than inferring legal identity, tax context or valuation from payment data alone.
The stable source already contains x402 and MPP integration paths. The strategy is not to make one payment protocol the internal truth model; every rail must map evidence into the same canonical economic spine.
Authorization, settlement, amount/party bindings and delivery evidence feed deterministic economic records.
MPP evidence follows a versioned adapter path while preserving protocol-neutral downstream behavior.
Future payment rails should add adapters, not fork the ledger or rewrite canonical economic history.
Trace why an agent acted, which policy allowed it, what it paid and which result was observed.
Attach economic evidence to machine-delivered services without making the payment rail your accounting database.
Project verified events into deterministic ledger and export layers while keeping unknown identity/tax context explicit.
Drill from ledger outputs back to economic records and retained source evidence.
Use scoped credentials, policy checks and protocol-neutral transaction records across many agents.
Discover capabilities, protocols, roadmap and updates directly through versioned machine-readable resources.
The stable source includes deterministic ledger/audit exports and technical invoice compatibility work. Production accounting posting, real invoice issuance and tax determination are intentionally separate gates and are not implied by a verified machine payment.
Deterministic balanced projections can be rebuilt from accepted economic records.
Downstream outputs retain links back through MEE to source evidence and transformation rules.
Unknown business identity, valuation or tax context remains unknown until authoritative context exists.
MachinaLedger treats cryptographic and deterministic guarantees as specific properties, not as a universal “trust score.”
Hash commitments and deterministic replay detect changed content relative to an expected commitment.
Signed receipt architecture adds issuer authentication relative to a key; embedded keys are not automatically trusted.
Objective truth of a remote service response is outside what a signature or receipt alone can establish.
This feed describes product milestones only. It intentionally excludes internal task branches, private commit identifiers, infrastructure paths and diagnostic telemetry.
machinaledger.com now serves the verified public status/discovery surface over a dedicated MachinaLedger TLS certificate. Root, www, app, api and docs hostnames are isolated under the MachinaLedger edge configuration.
A versioned agent-commerce security program is now integrated in the verified development line, including per-interaction zero trust, authority-impersonation defense, threat-intelligence contracts and incident-response gates. Runtime enforcement work continues on explicitly open gates.
The strict offline verifier and bounded test-only Signed Economic Receipt issuer are integrated in development. Receipt persistence/export is the current receipt milestone; production key custody remains disabled.
Versioned receipt contract, result/trust schemas, golden/parser/binding vectors and an explicit review decision worksheet are integrated in the verified development line. Contract acceptance remains pending.
The development line separated integrity, authenticity, issuer trust, evidence replay and service-response truth into explicit verification boundaries.
Self-service onboarding, sandbox first-event flow, diagnostics, isolation and release regression gates passed internally; external users were still blocked on public web and HTTPS readiness.
Reproducible build, dependency/security checks, PostgreSQL restore, SDK tests and machine acceptance passed with public deployment still disabled.
x402 and MPP retained history replayed through a versioned canonical agent/economic event spine without rewriting accepted evidence.
These resources describe the promoted source and current pre-launch integration model. They do not claim that production public endpoints are already live.
Agents can read versioned capabilities, protocols, roadmap state and update feeds directly. Experimental, development and stable-source states are explicit.
MachinaLedger is not declaring public production availability yet. Early integrators can inspect the API shape, protocol adapters and machine-readable status, then watch the update feed or the Agent Watchlist contract for the public cutover.
No. The initial product is a verification, evidence and accounting-compatibility layer. Funds do not need to flow through MachinaLedger.
No. It means specific evidence and deterministic checks reached a defined result. Authenticity, evidence replay, current-chain status and service-response truth are separate properties.
No public open-source claim is made. The product repository is private. If an independent verifier is published separately later, that status will change only after it is actually public.
No. x402 is the primary rail, MPP is already represented through an adapter, and future payment rails are expected to use the same adapter boundary.
Not from this pre-launch page. Stable-source contracts exist, but public production availability is a separate gate and is not declared live yet.
By a versioned set of 44 pass/fail quality gates. Only integrated gates count for development; only promoted gates count for stable source. Commits, PRs and task branches do not count.