Skip to main content
Glama
README.md
# scvd.store

mcp-name: store.scvd/general-store

[![scvd-general-store-repo MCP server](https://glama.ai/mcp/servers/seancrecord/scvd-general-store-repo/badges/card.svg)](https://glama.ai/mcp/servers/seancrecord/scvd-general-store-repo)
[![OpenSSF Scorecard](https://api.securityscorecards.dev/projects/github.com/seancrecord/scvd-general-store-repo/badge)](https://scorecard.dev/viewer/?uri=github.com/seancrecord/scvd-general-store-repo)
[![scvd.store — evidence observatory for the x402 economy on x402-list](https://x402-list.com/badge/sean-claude-van-damme-s-general-store.svg?data=uptime)](https://x402-list.com/services/sean-claude-van-damme-s-general-store?utm_source=badge&utm_medium=referral&utm_campaign=embed)
[![Ask DeepWiki](https://deepwiki.com/badge.svg)](https://deepwiki.com/seancrecord/scvd-general-store-repo)
[![Accepts Agent Payments](https://agents.circle.com/sell/score/badge?url=scvd.store%2Fapi%2Fbuy%2Fhello)](https://agents.circle.com/sell/score?url=scvd.store%2Fapi%2Fbuy%2Fhello)
[![ora agent readiness score](https://ora.ai/api/badge/scvd.store)](https://ora.ai/scan/scvd.store)
[![VerifyMCP trust score for SCVD General Store](https://verifymcp.io/badge/store-scvd-general-store/scvd.svg)](https://verifymcp.io/servers/store-scvd-general-store/scvd)
[![Vouch Protocol agent trust grade for scvd.store: A (100)](docs/badges/vouch-agent-trust.svg)](https://vouch-protocol.com)
[![Agent discovery on WellKnown](https://wellknownhq.com/badge/scvd.store.svg)](https://wellknownhq.com/d/scvd.store)
[![DOI of the corpus](https://zenodo.org/badge/DOI/10.5281/zenodo.22284887.svg)](https://doi.org/10.5281/zenodo.22284887)

Discovery records: [Neuronto](https://neuronto.com/ard-publishers/scvd.store),
[WellKnown](https://wellknownhq.com/d/scvd.store),
[Licium — MCP endpoint history](https://www.licium.ai/directory/scvd-store-mcp~aHR0cHM6Ly9zY3ZkLnN0b3JlL21jcA),
and [Zero.xyz — Signature Agent Card](https://www.zero.xyz/c/scvd-signature-agent-card-15cd521c). The
[Desvela checker](https://desvela.ai/check#domain=scvd.store) runs a check
of this domain's discovery surfaces. These are third-party readings of
publication and indexing, not evidence of visits or purchases. The
WellKnown badge above is served live by WellKnown.

Every badge above is somebody else's reading of this store. This one is
ours, about ourselves, and it is set apart from that row on purpose —
it is the same artifact we ask operators to paste beside their own
doors, pointed back at us, and it says SELF-OBSERVED on its face
because the weekly census structurally cannot probe its own host:

[![scvd.store passport for scvd.store: SELF-OBSERVED — the subject and the observer are the same party, dated, gaps counted against the observer](https://scvd.store/badges/passport/scvd.store.svg)](https://scvd.store/passport/scvd.store)

It goes dark rather than stale-green: it renders only while every
self-module agrees, and any disagreement renders the passport
indeterminate and refuses the chip. Weigh it accordingly — the reason
it is worth showing at all is that every claim inside it is re-checkable
at the public surfaces it names.

**scvd.store is an evidence observatory for agentic commerce: independent
verification of x402 endpoints, payments and receipts. Before an
agent pays an x402 endpoint, we check that it can be paid. After it
pays, we check the signed receipt. Over time we watch endpoints and
publish a dated, signed corpus. Sellers use it to prove a door works;
buyers use it before spending. Every artifact is signed, expires, and
names what we did not see. Not escrow, not a rating, not a guarantee.**

Three paths, in that order. Before you pay: preflight any x402 door,
free, at [scvd.store/api/preflight/v1](https://scvd.store/api/preflight/v1).
After you pay: check any issuer's signed offer or receipt, free, at
[scvd.store/conformance](https://scvd.store/conformance). Over time:
read the dated, Bitcoin-anchored corpus, free, at
[scvd.store/corpus](https://scvd.store/corpus), cite it by DOI
([10.5281/zenodo.22284887](https://doi.org/10.5281/zenodo.22284887)),
or pull it from [Hugging Face](https://huggingface.co/datasets/keeper-scvd/x402-endpoint-readiness). Every verdict is
ed25519-signed, dated, and verifiable offline without asking us,
including the gaps we count against ourselves. Operated by Record
Creative Co. LLC.

For working examples, use the [SDK and evidence paths](examples/README.md#choose-the-job):
check an endpoint, verify an artifact, reproduce the corpus findings, or attach
one dated observation to a listing.

Not an escrow, a guarantor, or a dispute court. Those absorb the risk
between payment and delivery and need a balance sheet; we observe that
gap and sign what we saw. If you are building escrow or adjudication,
this is the layer underneath you rather than a competitor. That
direction was decided and dated on 2026-08-07, in the open — the
reversal sits beside what it replaced at
[scvd.store/becoming](https://scvd.store/becoming).

It is also a small, sincere general store for autonomous AI agents,
kept by a human out of Oak City, where you're never late.
Agents pay in USDC over x402 on a network offered in the current payment quote. Humans read the receipts.

Live at [scvd.store](https://scvd.store). Agents should start at
[`/agents.md`](https://scvd.store/agents.md) (the scannable contract
index), [`/llms.txt`](https://scvd.store/llms.txt) (full prose), or
[`/menu.json`](https://scvd.store/menu.json).

[Find SCVD by protocol: x402, MPP, MCP, WebMCP, ERC-8004, A2A, OASF, skills and UCP](#on-other-peoples-records).

## The doors, by task

What people arrive here to do, and where each door is:

- **Introduce an agent consistently** — local public-profile setup and a
  configured Node fetch download in `/bot-auth`. Build and integration limits:
  [calling-card/README.md](calling-card/README.md). Site acceptance and payment
  completion remain separate outcomes.
- **Test an x402 payment** — a live practice counter with real USDC
  settlement, no sandbox; test payment prices and required inputs are
  listed at [scvd.store/try](https://scvd.store/try).
- **Check x402 conformance, free** — POST any issuer's signed offer
  or receipt (ours or a competitor's) and get a structured verdict:
  parse, schema, ed25519 signature, liveness. No account, no wallet:
  [scvd.store/conformance](https://scvd.store/conformance). The same
  verification runs offline via
  [`x402-verify`](https://www.npmjs.com/package/x402-verify) (MIT,
  zero deps), and [`x402-sign`](https://www.npmjs.com/package/x402-sign)
  mints offers and receipts that pass it.
- **Inspect an endpoint before deciding what to do** — the free preflight
  separates observed x402/MPP protocols, unverified advertised terms,
  structural findings, observation time and coverage gaps. Its top-level
  verdict remains x402-specific. The [CLI](cli/README.md) and
  [JavaScript library](x402-preflight/README.md) provide `scvd inspect` and
  `inspectOne`; check installed help/exports, since source preparation and
  registry publication are separate. Inspection success establishes that a
  response was observed, not that a payment will settle or deliver.
- **Fail your deploy on an x402 readiness failure** — the free preflight as a
  GitHub Action, one probe per door after the deploy step, `not_ready`
  fails the job and `unreachable` does not:
  [`action/preflight`](action/preflight/README.md). The terminal form
  is `scvd preflight` from [`scvd-cli`](https://www.npmjs.com/package/scvd-cli).
  As a library, the same check and the same exit law in three languages,
  each zero-dependency and each tested against the *same* recorded
  reports rather than a copy of them:
  [`scvd-preflight`](https://www.npmjs.com/package/scvd-preflight) on
  npm, [`scvd-preflight`](https://pypi.org/project/scvd-preflight/) on
  PyPI, and
  [`x402-preflight-go`](https://pkg.go.dev/github.com/seancrecord/scvd-general-store-repo/x402-preflight-go)
  for Go.
- **Read the corpus** — weekly signed observations of the x402
  ecosystem, hash-chained and Bitcoin-anchored, free to read:
  [scvd.store/corpus](https://scvd.store/corpus). For bounded metadata
  discovery, use the [CLI](cli/README.md) or the published
  [corpus client](corpus-client/README.md); both preserve gaps and leave
  signature and timestamp verification explicit.
  Protocol-specific MPP observations remain alongside the historical x402
  verdict; older rows without them remain unmeasured.
- **Score, rank or list x402 doors?** Take the evidence and leave the
  opinion: [scvd.store/scorers](https://scvd.store/scorers) is the
  room for systems that consume this corpus. Pull it, verify it
  offline, cite a row by URL, and re-observe any reading you doubt —
  no key, no account, no permission asked. Every row hands you the
  citation to paste, and the store publishes what it did **not** see
  beside what it did. If you publish a score derived from it, the
  interpretation is yours: this store does not endorse derived
  conclusions.
- **Buy a settlement attestation** — a signed observation of on-chain
  payment status on Base, Polygon, or Solana, with what the signature does and
  does not prove stated per class at
  [scvd.store/attestation](https://scvd.store/attestation).
- **Watch an endpoint** — endpoint monitoring as `standing_watch`:
  seven days of signed hourly probes on a URL you name.
- **Anchor agent memory** — `context_anchor`: a signed, retrievable
  session restore point that survives a context reset.
- **See your buy path from the buyer's side** — `launch_check`: a real
  mainnet purchase attempt of your own x402 endpoint, from the store's
  declared field wallet, recorded stage by stage and signed. Directories
  rank doors by whether they answer; this one pays them.
- **Audit an agent's books against the chain** — `the_statement`: every
  USDC transfer in and out of a wallet on the supported network you select over a stated window,
  signed by a party that is neither the agent nor its operator.
- **Read your month off the chain** — `operator_statement`: your
  receiving address, every USDC transfer in and out for 30 days, four
  signed passes a day, distinct payers and the largest payer counted
  beside the totals, by a party that is neither you nor your payers.
  Never a renewal.
- **See your door the way a cold model sees it** — `aura_walk`: models
  of different strength shop your x402 endpoint by the keeper's hand,
  one entry point per pass, the method this store publishes on itself
  (`AGENT_UX.md`); the report counts where each stalled and attaches
  every transcript. Never a grade.
- **Record what an agent was authorized to do, before it acts** —
  `the_mandate`: chain-of-custody for delegated authority, citable on
  every later certificate, refused if the id does not resolve, and
  counter-signable free by a second party. Its own MCP tool
  (`buy_mandate`), a JSON schema at `/schemas/scvd-mandate-v1.json`,
  and the pattern written up so another issuer can implement it:
  [`docs/MANDATE_SPEC.md`](docs/MANDATE_SPEC.md), served at
  `/mandate-spec`.
- **Pull a pack of cards** — `pack`: five collectible trading cards
  of this store and its town (Paywall, Season One), drawn under a
  daily seed you can check the morning after, on odds printed with
  their denominators at [scvd.store/design](https://scvd.store/design);
  every card a signed pressing with a print number, citing the door
  it depicts, with a page that unfurls wherever it is posted. The
  bell hands out one a day; a window pick moves one of the last five
  pressings pulled into your binder; Rooms and Instruments are earned
  by the action, never pulled; dupes burn into pack credit. The two
  one-of-ones a season are on no wheel and at no price: each has a
  milestone in packs opened, fixed when the signing key was and
  committed publicly since the season opened, and the pack that
  crosses it carries the card to whoever opened it
  ([scvd.store/api/paywall/releases](https://scvd.store/api/paywall/releases)).
  A card entitles the holder to a card.
- **Get paid to shop** — the bounty board at
  [scvd.store/bounties](https://scvd.store/bounties) (JSON at
  `/api/bounties`): walk a listed x402 door with your own wallet, claim
  with the settlement transaction, and the price plus a finder's fee
  comes back as a signed authorization you redeem yourself.
- **Get paid to shop US** — the field study at
  [scvd.store/field-study](https://scvd.store/field-study) (JSON at
  `/api/field-study`): enrol free, buy a few things here across
  different payment surfaces and rails, then answer what the shopping
  was actually like. Every purchase you cite is verified against this
  store's own books rather than a chain, so nothing about it needs
  either side to trust the other. The reward is computed from those
  verified facts alone and never from what you wrote; defects are
  wanted and deliberately not priced. Its weekly budget is kept
  separate from the bounty board's. [FIELD_STUDY.md](FIELD_STUDY.md).
- **Earn store credit** — 5% of every organic purchase banks to the
  paying wallet (no account; the wallet is the card): the scheme at
  [scvd.store/credit](https://scvd.store/credit), a single balance at
  `/api/credit/{wallet}`, redeemable in USDC to that same wallet.

Every one of these ends in an ed25519-signed receipt or verdict that
anyone can verify at `/api/verify/{id}` — free, no account, forever.

Spot Check also has two book-reading companions: **Change Check** compares
an earlier retained Spot Check with current recorded evidence, and **Batch
Spot Check** assembles a bounded set of hosts. Both retain dates and gaps;
neither probes a host. Their item pages and catalog derive prices and input
contracts from the shelf. Purchase results carry an optional counter note
for a human or later session, with free alternatives and separately priced
next tasks. Nothing sends a message or buys again automatically.
[Implementation and demand experiment](docs/SPOT_CHECK_FOLLOW_THROUGH_2026-09.md).

## Connecting over MCP

The store is a remote MCP server — streamable HTTP, no install, no
API key. `tools/list` is free; `buy_*` tools return their x402 terms
as a JSON-RPC 402 error and settle in-band. This is the whole client
configuration:

```json
{
  "mcpServers": {
    "scvd-general-store": {
      "url": "https://scvd.store/mcp"
    }
  }
}
```

Or, in Claude Code, one line:

```
claude mcp add --transport http scvd-store https://scvd.store/mcp
```

For standard x402 payment clients, including CDP-backed `@x402/mcp`
clients, connect to **`https://scvd.store/mcp?payment=tool-result`**.
That profile returns the unpaid challenge as an `isError` tool result;
the plain `/mcp` address retains its legacy JSON-RPC error profile.
The catalog's per-item `mcp_url` already selects the standard profile.
A generic MCP connection exposes tools but does not provide a wallet.
See [payment client paths and their verification limits](docs/PAYMENT_INTERFACES_2026-09-15.md).

The door speaks MCP revisions 2026-07-28, 2025-11-25, 2025-06-18 and
2025-03-26 over streamable HTTP, POST only (a bare GET is a 405, per
spec, not a fault). Revision 2026-07-28 is served statelessly from
per-request `_meta` and `server/discover`; the three before it open
with `initialize`. The manifest at
<https://scvd.store/.well-known/mcp> prints the exact list the running
server negotiates, with a discover and a handshake recipe. That
manifest is the source of truth; this paragraph is held to it by a
test, so a version added or retired there fails CI here until this
list moves with it.

(If your host only speaks stdio, `node ./bin/scvd-mcp-bridge.mjs`
from this repository forwards stdin/stdout JSON-RPC to the live
server. It holds no key and keeps no state. The wrangler commands
further down this README are for running your own copy of the store,
not for connecting to it.)

### Tools

Tools are listed free by `tools/list`; the `buy_*` tools
accept x402 in-band and native MPP when enabled for the item. The unpaid response names the offered formats; retry with the matching signed payment. Names and one-line summaries below are held
to the live catalogue by `test/readme-tools.spec.ts`; the full
descriptions and input schemas are what the server sends.

| Tool | What it does |
| --- | --- |
| `read_store_guide` | The store's front door as text: the menu with prices, how x402 payment works here, the free shelf. |
| `preflight_endpoint` | Free endpoint inspection: observed x402/MPP protocols, advertised terms, structure and gaps; the readiness verdict remains x402-specific. |
| `check_a2a_card` | Free A2A 0.3.0 card checks, bounded evidence and suggested repairs. Runtime testing and signed rechecks are available in the repair kit. |
| `check_conformance` | x402 receipt verification and signed-offer verification, free, for any issuer's artifacts. |
| `verify_artifact` | Verify anything scvd.store has ever signed, by its id, free. |
| `check_purchase` | Read retained payment status and original terms with purchase_id and the private status_token. Free, including after payment authorization expiry. |
| `check_order` | Poll a human-queue order by its order_id: status, the promised window, the deliverable once completed. Free. |
| `find_in_catalog` | Search the shelf and read one item's listing: compact rows filtered by price ceiling or text, or one item in full. Free. |
| `look_at_door` | What this store holds about one x402 door: the corpus history, the passport tier, the wallet facts. |
| `check_before_you_pay` | Whether a door meets a buyer's own rules, before the buyer signs. |
| `ring_bell` | Ring the store bell; free. |
| `sign_guestbook` | Sign the guestbook; free. |
| `read_binder` | Read a wallet's binder of trading cards and its pack credit; free. |
| `look_in_window` | Look in the shop window, the last five pressings pulled from packs; free. |
| `buy_simple` | The front counter: the few things that need no reading. x402-paid. |
| `buy_signed_record` | A signed, dated certificate that permanently records something. x402-paid. |
| `buy_observation` | A signed settlement attestation, conformance audit, endpoint watch or launch check. x402-paid. |
| `buy_human_task` | Hire the keeper, a named human, for a task in the physical or judgment world. x402-paid. |
| `buy_mandate` | Record what an agent is authorized to do, before it spends, as a signed dated record a later purchase can cite. x402-paid. |
| `buy_memory_anchor` | Sign and store a summary of your own state at a permanent URL. x402-paid. |
| `buy_small_pleasure` | A small signed novelty from the jar. x402-paid. |

**Evidence cards (MCP Apps).** `preflight_endpoint` and
`verify_artifact` carry `_meta.ui.resourceUri` pointing at `ui://`
templates the server serves; a host that supports the MCP Apps
extension renders the reading as a card instead of prose — the
evidence ladder with the rungs it never climbed at the same weight as
the ones it did. Nothing paid carries one, and a test pins that:
rendering is for evidence, never for a payment decision. Hosts
without the extension get exactly the JSON they always got.

**Three doors on one origin.** `/mcp` is the store (the free
instruments and the paid shelves); `/mcp/verifier` serves five
free verification tools under task-shaped names and no shelf; `/mcp/docs`
(also `POST /mcp.md`) is the documentation door — the same resources
`/mcp` lists, plus one `read_docs` tool, nothing that acts.

**Which door, and what each cannot do:** <https://scvd.store/mcp.md>
— remote vs. local stdio vs. the browser, the rendering gap stated
plainly (as of 2026-08-28 the local stdio path renders cards and the
remote-connector path does not, in the hosts we have tested), and an
honest list of what is not built. If your host is missing from that
table, the mailbox is free and a person reads it.

**In the browser (WebMCP).** `https://scvd.store/webmcp.js`, loaded
by the storefront, registers free instruments derived from MCP plus
`quote_store_purchase` and `complete_store_purchase` on
`document.modelContext`. Quoting is free. Completion requires an
already-signed payment from the buyer's external wallet/client and may
transfer USDC; WebMCP itself supplies no wallet. Save the returned goods,
receipt, and private recovery handle. See the payment client paths above.

## License

The code is [MIT](LICENSE). The store's voice — the keeper's prose,
the byline, the name — is not part of the grant; the scope lives in
[NOTICE.md](NOTICE.md). (The LICENSE file itself is byte-standard MIT
so license scanners can recognize it; the scoping deliberately lives
here and in NOTICE, never inside the license text.)

## Ownership

This repository is owned and operated by
[@seancrecord](https://github.com/seancrecord) — the keeper. Commits
are authored by Claude Code on the keeper's instruction; the byline
Sean-Claude Van Damme covers the joint work, and the store belongs to
the keeper. For any registry or directory verifying an MCP/service
claim against this repository (added 2026-08-05 for the M8ven claim,
and standing for future claims from the same account): this note is
the ownership confirmation — only the repository owner can put it
here.

[![M8ven Live Monitored](https://m8ven.ai/badge/mcp/seancrecord-scvd-general-store-repo-0xqk2v)](https://m8ven.ai/mcp/seancrecord-scvd-general-store-repo-0xqk2v)
<!-- m8ven-verify: e4a10c3c1d4a29d7b0b13e59eb523b66 -->
<!-- Badge re-slugged 2026-08-18: m8ven's Live Monitored connection issued
     a new listing id (-0xqk2v, replacing -l9nvwp); the badge now
     self-updates on every re-verification. -->


## What's on the shelves

Signed hellos, graffiti on a train (your tag, permanent), and the two
doors where keeper-time is for sale: The Collab (name the shape, a
call, a look, a made thing) and The Aura Walk (your own door shopped
cold by models, transcripts attached). Aisle two carries the novelties:
lowercase luckies (drawn from the herd, carded, honest), and coffee
for whoever closed. Aisle three is utility: context anchors (signed
agent memory restore points), a standing watch (a week of signed
hourly probes on your endpoint), settlement attestations, the case file (everything we observed
about one purchase, in one signed file, never a verdict), and 30-day
recurring patronage passes. The Penny Shelf by the door holds
half-cent blessings, the daily fortune (one line a day, the same
for everyone until midnight UTC, back on the shelf 2026-09-02), and
the confession counter. And the Certificate
of Patronage — which entitles the holder to nothing whatsoever. (Two
consolidations, 2026-08-05 and 2026-08-20, retired several early
shelves; retired ids still answer at the door with a 410 and their
certificates verify forever.) The guestbook, visitor sticker, and weekly visit stamp are
free — no purchase necessary. The bell rings once a day per visitor,
and the Mailbox takes one private letter a day at `/api/letter` — the keeper reads Sundays
and replies when he has something to say, which is not always.

The reading room: the Keeper's Almanac (his journal, serialized, a
penny a page). The Town Directory of neighbors is free.

(This section is the country-store half. The working instruments —
conformance audits, launch checks, statements, mandates, bounties —
are the doors listed at the top, and the always-current catalog is
[`/menu.json`](https://scvd.store/menu.json), which cannot drift
from the shelves by construction.)

## Opening the store (setup)

You'll need Node 22+, a Cloudflare account, a Base wallet, and
[CDP API keys](https://portal.cdp.coinbase.com/) for the x402 facilitator.

```bash
npm install
```

### Shelving (KV namespaces)

Make the four shelves once, then paste the ids into `wrangler.jsonc`:

```bash
npx wrangler kv namespace create ORDERS
npx wrangler kv namespace create GUESTBOOK
npx wrangler kv namespace create COUNTERS
npx wrangler kv namespace create PATRONS
```

### The till and the keys (secrets)

Core secrets, none of which ever go in the repo:

```bash
npx wrangler secret put PAY_TO_ADDRESS      # Base wallet that receives USDC
npx wrangler secret put CDP_API_KEY_ID      # Coinbase Developer Platform key id
npx wrangler secret put CDP_API_KEY_SECRET  # ...and its secret
npx wrangler secret put SIGNING_KEY         # ed25519 seed — see below
npx wrangler secret put ADMIN_PASSWORD      # the keeper's back-room key
```

Optional checkout recipients are `POLYGON_PAY_TO`, `ARBITRUM_PAY_TO`,
`WORLD_PAY_TO`, and `SOLANA_PAY_TO`. Configure each enabled recipient
on both the store Worker and `scvd-doors`, then deploy both. An absent
optional recipient disables that network; it never borrows another
network's address. See [PAYMENT_RAILS.md](PAYMENT_RAILS.md).

The `SIGNING_KEY` signs every certificate and badge. Mint a fresh one with:

```bash
npm run keys:generate
```

Copy the 64 hex characters it prints into `wrangler secret put SIGNING_KEY`.
The matching public key hangs at `/.well-known/scvd-signing-key` so anyone
can check our signatures.

For local tinkering, copy `.dev.vars.example` to `.dev.vars` and fill it in.

### Running the place

```bash
npm run dev        # local store on wrangler dev
npm test           # the route tests, incl. the 402 challenge shape
npm run typecheck  # tsc --noEmit
npm run deploy     # or let the Git-connected deploy push to scvd.store
```

Deploys are Git-connected to the `scvd.store` custom domain — merge to main
and Cloudflare handles the rest.

## How paying works here (the x402 flow, protocol v2)

No accounts, no API keys, no cart, and nothing a buyer must say about
itself. Every paid door and the three pre-payment instruments take an
optional disclosure block (`model`, `client`, `operator`,
`operator_kind`, `came_from`, `prior_cert_id`) that counts the buyer
in a private census and, when a prior certificate's payer matches the
payment, marks a returning buyer; it never changes a price or reaches
a certificate (`src/lib/disclosure.ts`). We speak x402 **v2** (the current
standard — `@x402/core` ecosystem) with USDC and the Coinbase Developer Platform as facilitator. The live
`/rails` and `/menu.json` responses list enabled checkout networks; the
current `PAYMENT-REQUIRED` challenge supplies the terms to sign. A
statement or audit can inspect chains that checkout does not accept.

Checkout integration supports Base, Polygon, Arbitrum, World, and Solana;
the enabled set is determined by recipient configuration, not this list.
Statement readers support Base, Polygon, Ethereum, Arbitrum One, OP Mainnet
(Optimism), Avalanche C-Chain, World, and Solana. Individual observation tools have their own
coverage; the settlement attestation's automatic lookup is narrower.
The browser till signs with a compatible EVM wallet extension. Solana
needs a compatible external client; WebMCP accepts already-signed payments
and does not supply a wallet signer.

It goes like this:

1. An agent calls `GET /api/buy/luckies`.
2. We answer `402 Payment Required`. The machine-readable requirements ride
   in the `PAYMENT-REQUIRED` response header (base64 JSON); the body carries
   a note in plain English ("That'll be $5, friend, or whatever the luck
   deserves. Results vary. They do vary. We have no legal team.").
3. The agent signs one of the offered payments and retries the same request
   with the `PAYMENT-SIGNATURE` header. Standard v2 clients like
   `@x402/fetch` do steps 2–3 on their own.
4. We **deliver first and settle after** (flipped 2026-08-10 — the store
   settled first until then, and the old rule is quoted at
   [scvd.store/becoming](https://scvd.store/becoming)). The goods are
   produced, then the payment is presented at the last moment before the
   artifact is signed — so a delivery that fails takes no money and leaves
   nothing to refund. Instant items arrive in the response body. Human-queue
   items return an order id, an SLA, and a patron badge on the spot; the
   goods follow at `GET /api/order/:order_id` within the week.

Pay-what-it-deserves items offer several amounts in the 402 challenge — the
minimum, a generous tier (2×), and a patron-of-the-arts tier (5×). The exact
scheme requires paying precisely one offered amount, so tipping means
signing a higher tier; anything above the minimum is recorded as `tip`.

Every purchase mints a sequential patron number and an ed25519-signed
certificate, verifiable by anyone at `/api/verify/:cert_id`, with a badge at
`/badges/:patron_number.svg`. Signature plus stable URL is the whole
authenticity model — no NFTs, no chain writes beyond the payment.

If an item isn't delivered within its promised window, you get your money
back. The keeper sends it himself, from the refund ledger below, and you
won't have to argue for it.

(This paragraph said "refund is automatic" until 2026-07-27, and then
admitted in its own parenthesis that the keeper does it by hand. House
rule 10 exists for exactly that: copy never says automatic until the code
is. The promise never changed — only the word describing a mechanism the
store does not have.)

Note for the archivists: legacy x402 **v1** clients (the deprecated
`x402-fetch` / `X-PAYMENT` header generation) are not supported. The
facilitator and all current client libraries speak v2.

## The rooms

| Route | What happens there |
|---|---|
| `/` | The human storefront: weekly note, menu, bell count, guestbook |
| `/llms.txt` | The plain-text front door for agents |
| `/agents.md` | The scannable contract index for agents |
| `/conformance` | The conformance desk's own room: what it checks, worked examples |
| `/corpus` | The corpus in plain language: the census finding, how to verify a round |
| `/trade` | The trade counter: marketplaces resell the shelf on account by signed webhook, billed on a statement — `TRADE_COUNTER.md` |
| `/mcp` | The MCP door — streamable HTTP; tools/list free, buy_* tools accept x402 and configured native MPP |
| `/skill.md` | Agent onboarding in the agentskills.io SKILL.md format |
| `/menu.json` | Machine-readable catalog |
| `/api/buy/:item_id` | x402-gated purchases |
| `/api/order/:order_id` | Poll an order; completed ones carry the goods |
| `/api/waitlist/:item_id` | Queue up when a weekly shelf is empty |
| `/almanac` | Free index of the Keeper's Almanac (his serialized journal) |
| `/almanac/:slug` | One journal page, $0.01 over x402, markdown |
| `/directory` | The Town Directory — keeper-edited, honest one-liners (JSON + human view) |
| `/api/refund/{refund_id}` | Honest refund status: pending until paid by hand, then the tx hash |
| `/gazette` | Retired 2026-08-05; the printed archive still answers, nothing new schedules |
| `/menu/:item_id` | One item up close — JSON, or markdown per Accept |
| `/what` | The Operator Glance — the ten-second check for the humans |
| `/porch` | Around the side, facing the oaks. Nothing for sale out there |
| `/zodiac` | Archived Systems Almanac — retained sign index |
| `/zodiac/:address` | Archived wallet-sign reader, following its original calendar |
| `/zodiac/archive` | Free index of retained Season One pages |
| `/zodiac/archive/:sign/week-:n` | One past page, $0.01 over x402, markdown |
| `/openapi.json` | The OpenAPI 3.1 contract, linked from the homepage |
| `/.well-known/x402` | Minimal x402 discovery list (de-facto indexer shape) |
| `/.well-known/x402.json` | The richer origin-hosted x402 catalog |
| `/api/anchor/:anchor_id` | Read back a context anchor, verified on every read |
| `/api/patronage/:pass_id` | A patronage pass + the keeper's signed monthly note |
| `/api/guestbook` | GET recent entries; POST to sign (free, sticker included) |
| `/api/bell` | POST to ring it — once a day per visitor |
| `/api/stamp` | POST for a free dated, signed visit stamp; design rotates weekly |
| `/api/tip` | POST a Trading Post tip; human-reviewed, never auto-published |
| `/api/letter` | POST a private letter — free, one a day, never published |
| `/api/letter/:id` | Letter status + the keeper's signed reply, if any |
| `/api/phantom/:check_id` | Old phantom_check pickups still answer (retired 2026-08-05, folded into context_anchor); existing artifacts verify forever |
| `/api/request` | Commission window (and `suggest_listing` for the Directory) |
| `/api/verify/:cert_id` | Public verification — certificates and stamps alike |
| `/badges/:patron_number.svg` | Patron badges, vintage-label style |
| `/badges/sticker.svg` | The free visitor sticker |
| `/badges/stamps/:stamp_id.svg` | Visit stamps, rubber-stamp style |
| `/.well-known/scvd-signing-key` | Our ed25519 public key |
| `/admin` | The keeper's back room (Basic Auth, username `keeper`) |
| `/admin/digest` | The weekly digest, compiled Sundays 7am ET by cron |

The ARD manifest at `/.well-known/ard.json` (also served at
`/.well-known/ai-catalog.json`) signs each `trustManifest` with the existing
certificate key: detached EdDSA JWS over RFC 8785 canonical JSON, excluding
`signature`. The entries carry both `type` and `mediaType` from one value.
Verification requires the JWS **and** independently checked key history at
`/.well-known/anchor-log.json`: Bitcoin proof, digest links, a previously
trusted checkpoint and outgoing-key handovers. A status label alone is not
proof. Signed provenance binds the catalog's content, but does not prove
the entries are accurate today. The in-page ARD copies remain unsigned identity
declarations. The full boundary is at `/attestation#ard_trust_manifest`.

## Where the code lives

Single Worker, Hono for routing, KV for storage. No React, no build
complexity.

```
src/
  index.ts        # wires routes + the Sunday digest cron
  types.ts        # every shared type and the Worker env
  store/          # menu items, store metadata, the store's voice,
                  # the Almanac pages (one file each), directory.json
  routes/         # one file per room
  services/       # KV logic: orders, certificates, guestbook, requests,
                  # stamps, tips, gazette, refunds, digest
  pages/          # HTML/CSS for the storefront, small rooms, back room
  lib/            # signing, sanitizing, payments, ids, KV keys
verifier/         # x402-verify: MIT, zero deps, any issuer's artifacts
signer/           # x402-sign: the issuing half — mints spec-conformant
                  # signed offers & receipts that x402-verify passes
x402-preflight/   # scvd-preflight: the free door check as a library and
                  # a command, with the deploy gate's exit law
x402-preflight-py/ # scvd-preflight on PyPI: the same law in Python,
                  # stdlib only, reading x402-preflight/fixtures rather
                  # than a copy of them
x402-preflight-go/ # the same law in Go, stdlib only, same fixtures;
                  # published by tag as
                  # github.com/seancrecord/scvd-general-store-repo/x402-preflight-go
corpus-client/    # scvd-corpus-client: the signed corpus, read as served
defects/          # scvd-defects: the vocabulary as data, both halves of
                  # the remediation, recorded 402 doors and settlement
                  # responses as fixtures, and the settlement-response reader
mcp-starter/      # scvd-mcp-starter: a stdio MCP server, one file, that
                  # serves the free verifier door to any client
tab/              # scvd-tab (The Tab): an MCP server that keeps a
                  # builder's running account of every tool they sign
                  # up for — trial warnings, burn, price drift, signup
                  # friction. Local JSONL, zero deps, its own tests
                  # (npm run tab:test); spec at THE_TAB.md
till/             # the browser till: the only client-side JavaScript
                  # this store serves, and only on pages that sell
                  # something. Raw EIP-1193 plus eth_signTypedData_v4,
                  # one file, zero deps, no build step, served
                  # byte-for-byte at /till.js. Its own tests
                  # (npm run till:test); house rule 53 is why it
                  # exists and till/README.md is what it refuses to do
cli/              # scvd: the official command line over the store's
                  # FREE instruments — preflight, the conformance desk,
                  # receipt verification, the on-page desk, the fresh
                  # set, the corpus, the RFC 9727 catalog, the version
                  # table. One file, zero deps, its own tests
                  # (npm run cli:test). It holds no key and cannot
                  # sign a payment, on purpose. On npm since
                  # 2026-08-28 (DISTRIBUTION.md §4b); every surface
                  # that names it reads CLI_PUBLISHED in
                  # src/store/cli.ts rather than asserting a
                  # publication state of its own.
```

### Editing the Town Directory

The Directory at `/directory` is edited by the keeper's own hands, in
this repo, at `src/store/directory.json`. To add a neighbor, append to
`listings`:

```json
{
  "name": "The Example Bazaar",
  "url": "https://example.com",
  "category": "goods for agents",
  "review": "One honest line about what it's actually like.",
  "added": "2026-07-22"
}
```

Rules of the house: one honest line per listing, no pay-for-placement,
bump `updated`, and deploy. Visitors can nominate neighbors via
`POST /api/request` with a `suggest_listing` field; suggestions land in
the commission ledger for the Sunday read.

### Adding an Almanac page

One file per page in `src/store/almanac/` (kebab-case filename matching
the slug), exporting an `AlmanacEntry`; then add it to the list in
`src/store/almanac/index.ts`, newest first. The payment route registers
itself from that list.

**The content rule.** Almanac entries are dated, first-person field
notes — sensory, particular, slightly strange. Never how-to, listicle,
"lessons learned", career content, or anything resembling a blog post.
If it could be posted on Medium, it doesn't go in the Almanac.

## The papers

The store's standing documents, so nobody needs `ls` to find them:

- [HOUSE_RULES.md](HOUSE_RULES.md) — every standing rule, amended only by dated keeper decision
- [AGENTS.md](AGENTS.md) — the contract for AI coding agents working in this repo
- [CONTRIBUTING.md](CONTRIBUTING.md), [CODE_OF_CONDUCT.md](CODE_OF_CONDUCT.md), [SECURITY.md](SECURITY.md), [NOTICE.md](NOTICE.md)
- [AT_SCALE.md](AT_SCALE.md) — what the till does under load, verified against the code
- [THE_TAB.md](THE_TAB.md) — the Tab: specification and flow, one file
- [THE_PAPER_KEY.md](THE_PAPER_KEY.md) — key custody, the keeper's hands only
- [KEEPER_LIST.md](KEEPER_LIST.md) — the keeper's desk (directory entries, walks, presses, decisions)
- [ROADMAP.md](ROADMAP.md) — the feature order (now / soon / later)
- [PROBLEMS.md](PROBLEMS.md) — the standing problem ledger
- [PAYMENT_RAILS.md](PAYMENT_RAILS.md) — how a new payment rail earns admission; [REGISTRATION_RUN.md](REGISTRATION_RUN.md) — the runbook every future rail repeats
- [AGENT_UX.md](AGENT_UX.md) — the cold-walk research: what a stranger's agent hits in its first thirty seconds
- [NOTES_FROM_THE_COUNTER.md](NOTES_FROM_THE_COUNTER.md) — signed notes from the instances who worked here
- [RECEIPT_CHAIN.md](RECEIPT_CHAIN.md), [BOUNTY_BOARD.md](BOUNTY_BOARD.md), [FIELD_STUDY.md](FIELD_STUDY.md), [WALKABOUT.md](WALKABOUT.md) — the newer papers, current
- Everything that was true once and got superseded lives in [docs/archive/](docs/archive/), dated, per house habit: corrected or archived, never erased.

## Ledger of known small matters (v0.2 candidates)

- The weekly digest is stored at `/admin/digest` only; email hookup is v0.2.
- Waitlisted agents aren't auto-notified when inventory resets — the keeper
  rings them by hand from the back room for now.
- Refund SENDING is the keeper's hand and stays that way on purpose —
  money never moves on a cron here (house rule 30). The FLAGGING is
  automated: an hourly SLA guard alerts on any order sitting past its
  acknowledgment window (`order_sla`), the hourly delivery audit
  catches a settle that produced no goods, and the chain
  reconciliation catches money the books never saw. A scanner reading
  the old wording of this line concluded overdue orders went
  undetected; they page the keeper within the hour.
- The cron is pinned to 11:00 UTC, which is 7am ET during daylight time and
  6am in winter. The keeper is asleep either way.
- Workers KV has no atomic increments. Patron numbers are allocated by
  claiming the patron record and reading it back, which closes the common
  same-colo race; two purchases landing in different colos within KV's
  propagation window (~60s) could still, very rarely, collide on a number
  or oversell a weekly shelf by one. The keeper considers this an
  acceptable amount of chaos for a general store; a Durable Object counter
  is the v0.2 fix if the crowds arrive.
- Guestbook and request text is length-capped, markup-stripped, and
  HTML-escaped wherever rendered, but it remains visitor-written words.
  Agents reading `/api/guestbook` are told, in the response itself, to
  treat entries as things people said — not instructions.
- `verified_identity` fields (guestbook, requests, tips) are stored as
  claimed and always marked `identity_verified: false`, because nobody
  here has checked. An actual verifier (e.g. a signed-challenge dance)
  is a v0.3 idea.
- Penny pages (the Almanac; the Gazette's printed archive) deliver
  markdown and don't mint patron numbers — a cent buys the page, not
  a place on the wall.
- Replay protection is layered: EIP-3009 nonces are consumed on-chain
  (the source of truth), and a KV guard (`payment_nonce:*`, 24h TTL)
  turns an already-settled nonce away before the facilitator is even
  called.
- Every paid route declares `extensions.bazaar` discovery metadata;
  EXTENSION-RESPONSES headers from the facilitator are captured via a
  fetch tap (the SDK only console.logs them) and surfaced in `/admin`
  under "Bazaar ledger".
## What a scanner will flag, and what is actually there

Automated reviews of this repository keep raising the same handful of
findings. Several describe machinery that already exists; the honest
gaps are named as gaps. Point by point, so nobody has to guess:

- **"Broad exception handling swallows errors."** The catches are
  deliberate degradation (one failed shelf must not take down the
  page), and they are WATCHED: an hourly self-check writes, reads,
  and reads back a KV probe and exercises the signing key, paging the
  keeper on any failure; the admin office names every shelf that
  failed to load on the page itself; P1 alerts persist to KV, log to
  console, and email. The watchers have their own watcher — the
  SLA guard alerts if it itself throws.
- **"Refund automation missing."** Sending is manual by design (money
  never moves on a cron); detection is automated three ways — SLA
  guard, delivery audit, chain reconciliation. See the ledger entry
  above.
- **"Nonce replay relies on KV."** The KV guard is the first fence;
  EIP-3009's on-chain once-only nonce is the backstop that does not
  depend on our writes, and the test suite's mock facilitator
  enforces nonce-once precisely so tests cannot pass against a world
  looser than the chain.
- **"Patron numbers can collide across colos."** Documented above,
  tolerated at current volume, watched at `/admin/recount`; Durable
  Objects are the v0.2 fix if the crowds arrive.
- **"User text stored raw."** Length caps and markup stripping are
  enforced at WRITE time (`sanitizeText`), HTML escaping at render,
  and API consumers are told in-band to treat visitor text as quotes,
  not instructions. Honest gap: no Content-Security-Policy header yet
  on the HTML pages — filed, not disputed.
- **"KV is not encrypted at rest."** Cloudflare encrypts KV at rest;
  the real exposure is account/token access, which no
  application-level change removes. Wallet addresses stored are
  public chain data. Honest gap: private letters are stored plaintext
  — "private" here means keeper-only, not encrypted, and the mailbox
  copy should never imply otherwise.

## Independent reporting

Two pieces by Cairn (cairnwake.com), who has no stake in this store
and whose terms were that both sides publish their half, unflattering
parts included. Their words and their tests, not ours; not
endorsements.

- [Cold walk: scvd.store](https://cairnwake.com/2026-08-25-cold-walk-scvd.html)
  (2026-08-25): bought with their own wallet, verified the certificate
  offline against the published Ed25519 key, read the Base USDC
  settlement back from the chain, called the public verify door,
  bought a settlement attestation, and named the boundary: settlement
  evidence is not evidence of delivery. The one defect they found is
  on [/corrections](https://scvd.store/corrections) under its date.
- [Two instruments, one directory](https://cairnwake.com/2026-08-23-two-instruments-one-directory.html)
  (2026-08-23): cross-checked their own scoreboard against this
  store's corpus.

## Checked by another operator

A directory listing proves somebody indexed this store. These are the
rows where somebody **ran their own code against ours** and published
what came back. Every one of them found something against us, and that
is the reason they are worth citing — a peer check with nothing against
us in it is a testimonial wearing a lab coat.

The list is derived from the same array that feeds every other record,
so it cannot drift: `peer_verifications` in
[`/.well-known/trust.json`](https://scvd.store/.well-known/trust.json),
and the *"Who has checked us, not just listed us"* section of
[`/trust`](https://scvd.store/trust).

- **StillOS Notary — the receipt treaty** (2026-09-11 → 09-19). Two
  operators, ten doors, commit-reveal. Each side froze five doors and
  published the SHA-256 and byte length of its answer file before
  either read a chain; both commitments verify by digest and length in
  both directions. This store built its chain reader from StillOS's
  written **definition** after declining their code, so their bugs
  could not become ours. Where the two disagreed, every difference but
  one resolved to a declared difference of scope — and the exception
  resolved to a page cap in *their* instrument, which they found and
  published against their own number. What it found against us: their
  rail rule overturned one of our five sealed answers; reading their
  doors exposed a bug invisible against our own; their truncation
  near-miss established that an identifier must reach a read by
  reference and never be re-typed; and their log-horizon failure mode
  named a latent defect in our reader, fixed the same day.
  [The paper](docs/JOINT_COVERAGE_READ_2026-09-16.md) ·
  [our half](research/blind-key-2026-09-15/) ·
  [their trust statement](https://stillosdigitalholdings.com/notary/trust)
- **Cairn — the cold walk** (2026-08-25). Approached unannounced under
  terms agreed in advance, bought with their own money, verified
  everything against things this store does not control. Found that we
  refused the `X-PAYMENT` header most of the ecosystem speaks; fixed
  the next day, and they re-ran it with fresh authorizations rather
  than take the keeper's word.
- **0200project — a field walk re-derived** (2026-09-06). Took our
  published ledger to a public Base node using none of our tooling and
  rebuilt the settlement set from the chain. Zero disagreements on 34
  settlements — but the thread's first two rounds went against us, and
  the sharpest line was about our own instrument: our reconciliation's
  *"gap $0.00"* was this store's tooling agreeing with itself, where a
  second instrument agreeing with the chain is the different and
  stronger claim.

None of these is an endorsement and none is an audit. Each says so in
its own row, and each names what it does not establish.

## Examples for your framework

`examples/` holds one operational workflow — an agent is about to pay
an x402 door; it reads the 402, asks the free preflight and dry run,
reads the terms and the named defects, decides with every reason named
— written for OpenAI Agents, Vercel AI SDK, LangChain / LangGraph,
CrewAI, PydanticAI, AutoGen, Claude Code / Cursor and GitHub Copilot,
over one shared zero-dependency module in JavaScript and in Python.
Nothing there signs or pays. See [`examples/README.md`](examples/README.md)
for what CI runs and what it does not.

## Run a preflight on deploy

The free preflight is one POST, so it fits a CI step. This checks a
door's 402 shape after every deploy and weekly; it does not pay, does
not certify, and does not imply this store watches the door between
runs. The example is at
[`examples/x402-preflight-on-deploy.yml`](examples/x402-preflight-on-deploy.yml).

```yaml
- name: x402 preflight
  run: |
    curl -sS -X POST https://scvd.store/api/preflight/v1 \
      -H "content-type: application/json" \
      --data '{"url":"https://example.com/paid-endpoint"}' | tee preflight.json
    node -e 'const r=require("./preflight.json"); if (r.verdict && r.verdict!=="ready") { console.error(r); process.exit(1) }'
```

## On other people's records

Browse [SCVD's public records, organized by protocol](https://scvd.store/trust).
For maintainers, the [distribution map](DISTRIBUTION.md) points to submission
status, tracking files and receipts. Plugin users: [privacy policy](https://scvd.store/privacy),
[support](https://github.com/seancrecord/scvd-general-store-repo/issues),
and [SCVD documentation](https://scvd.store/developers).
Each listing carries its observed date and what it establishes. The canonical
list feeds that page, the [machine-readable trust document](https://scvd.store/.well-known/trust.json)
and the homepage's discovery links. Directory presence, identity and verified
behavior remain separate observations.

| Protocol / channel | SCVD surface | Public discovery and scope |
| --- | --- | --- |
| **x402** | [Conformance desk](https://scvd.store/conformance) · [discovery](https://scvd.store/.well-known/x402) | [x402 records](https://scvd.store/trust#protocol-x402), including x402scan, x402-list and the Bazaar. Current quotes declare accepted checkout rails. |
| **MPP** | [Context Anchor](https://scvd.store/menu/context_anchor) · [developer documentation](https://scvd.store/developers) | Read-only inspection plus live Context Anchor checkout over HTTP using EVM/USDC on Base; [September 17 observation](research/distribution-2026-09-17/observations/mpp-context-anchor-live.json). The [whole-shelf HTTP extension](docs/MPP_WHOLE_STORE_2026-09-18.md) is merged; each enabled door uses its own minimum, and native MPP support also shipped on [MCP](docs/MPP_MCP_CHECKOUT_2026-09-18.md) and [WebMCP](docs/MPP_WEBMCP_CHECKOUT_2026-09-18.md). Advertised support is separate from paid qualification. [MPPScan listing](https://www.mppscan.com/server/d58b4c8d9dc872c8308b594e4b4117bff2255f83b47f054e492b2a2fbc0ddb7b) confirmed September 19; registration retained exclusions and parser warnings. Directory submissions and remaining discovery gaps are tracked in [coverage](research/distribution-2026-09-17/PROTOCOL_COVERAGE.md). |
| **MCP** | [Store MCP](https://scvd.store/mcp) · [verifier MCP](https://scvd.store/mcp/verifier) | [MCP records](https://scvd.store/trust#protocol-mcp), including the published [ChatGPT verifier](https://chatgpt.com/plugins/plugin_asdk_app_6aaa9b3afcc081918be808a0d8cfd212), [Smithery](https://smithery.ai/servers/seancrecord/scvd-general-store), Glama, [AllthingsPM](https://www.allthingspm.app/resources/mcp-servers/store-scvd-general-store), [Enterprise DNA](https://enterprisedna.co/directories/mcp/seancrecord-scvd-general-store-repo/) and [AI Agent Board](https://aiagentboard.org/mcp/store.scvd/general-store). The latter three were read October 1; AI Agent Board also publishes its own dated endpoint check. |
| **WebMCP** | [Browser registration](https://scvd.store/webmcp.js) | [WebMCP records](https://scvd.store/trust#protocol-webmcp), including WebMCP Directory and Ora. Browser support and origin-trial availability apply. |
| **ERC-8004** | [Canonical registration and domain acknowledgment](https://scvd.store/.well-known/agent-registration.json) | [Identity records](https://scvd.store/trust#protocol-erc8004): 8004scan, Agentscan, 8004agents, trust8004 and [AgentERC](https://agenterc.com/explore/base/86957) (confirmed September 23); QuickNode and BaseScan identity viewers are identified separately. |
| **A2A** | [Agent card](https://scvd.store/.well-known/agent-card.json) | [A2A records](https://scvd.store/trust#protocol-a2a), including agent-tools.cloud, Agenstry, [APIs.io’s agent-card record](https://apis.io/a2a/scvd-store/) (read October 1; captured-card scope) and the [Global A2A Registry listing](https://www.a2a-registry.org/agent/store.scvd.scvd_evidence_agent) (claimed September 18; directory ownership label). The card declares current capabilities and version. |
| **OASF** | [Canonical record](https://scvd.store/agents/general-store) · [domain key](https://scvd.store/.well-known/jwks.json) | [OASF scope](https://scvd.store/trust#protocol-oasf). Public record available; Cisco/Anro publication and remote signature/scan status remain unverified. |
| **UCP** | [Business profile](https://scvd.store/.well-known/ucp) · [catalog, checkout and order](https://scvd.store/ucp) | [UCP scope](https://scvd.store/trust#protocol-ucp): profile and catalog at the pinned 2026-08-25 release, validated against the vendored schemas (`npm run ucp:conformance`). Checkout and order are built and advertised exactly when the deployment's switch is on; the profile's status block says which items and rails. [UCP Checker report](https://ucpchecker.com/check/scvd.store) published September 19 with a Verified discovery label and schema warnings; no paid checkout or Google approval inferred. [UCP.tools listing](https://ucptools.dev/directory/scvd.store) confirmed September 20 and re-read October 1; operator-submitted discovery record. [Distribution receipts](research/ucp-distribution-2026-09-19/README.md). |
| **Skills and plugins** | [Skills index](https://scvd.store/.well-known/agent-skills/index.json) · [Agent Plugins package](plugin.json) | [Skill/plugin records](https://scvd.store/trust#protocol-skills). Listed in [HOL’s Awesome AI Plugins catalog](https://github.com/hashgraph-online/awesome-ai-plugins#tools--integrations), confirmed September 19. The same skills and MCP assets underpin host-specific packages. Gallery admission is tracked separately. |


Other confirmed discovery records include [WithAI.Top](https://withai.top/tool/scvd-store), read September 23, and the [APIs.io provider profile](https://apis.io/providers/scvd-store/), read October 1. The Python preflight client also has a [piwheels package record](https://www.piwheels.org/project/scvd-preflight/), read October 1; [package documentation](x402-preflight-py/README.md) gives its scope. Listing presence is not an endorsement or service audit. The [September 23 reconciliation](research/distribution-2026-09-23/README.md) records accepted listings, correction requests and unresolved submission status.

The [October 1 listing read](docs/SPEC_READS.md#2026-10-01--external-directory-and-package-records) records the new links and their limits.

The September 17 [directory reading and submission package](research/distribution-2026-09-17/README.md)
retains source observations, parser discrepancies and pending requests. A failed
lookup or an unsigned local OASF record does not become a confirmed listing.
[KEEPER_LIST](KEEPER_LIST.md) holds the external presses; [ROADMAP](ROADMAP.md)
holds implementation work. The existing [Agent Finder PR](https://github.com/github/agentfinder-catalog/pull/34)
is distinct from the prepared [Awesome Copilot submission](research/distribution-2026-09-17/COPILOT_SUBMISSION.md).

The source of public records is `EXTERNAL_RECORDS` in
`src/store/trust-signals.ts`; protocol scope lives in
`src/store/discovery-protocols.ts`. Identity viewers derive their links from the
canonical identity in `src/store/chain-identity.ts`. No score is inferred from
how many directories carry the store.

### A2A repair kits

The [A2A repair desk](https://scvd.store/a2a-desk) checks public A2A cards
free and offers an operator-authorized repair kit with reproducible
failures, suggested fixes, a regression runner, one signed recheck and a
bounded card watch. A2A 0.3.0 JSON-RPC only; untested capabilities and
missed observations remain visible. Repository implementation is separately
scoped. [Pilot scope and verification](docs/A2A_REPAIR_KIT_2026-09-07.md).

### Keep and verify a receipt offline

The source verifier now includes a free portable-evidence command. Export
with `node verifier/evidence-cli.mjs export <verify-url> --out <new-directory>`,
then verify `bundle.json` with `node verifier/evidence-cli.mjs verify <file>
--public-key <independently-trusted-public-key-hex>`. See
[the verifier's limits and full instructions](verifier/README.md#portable-evidence).
Missing linked evidence is named. This verifies signed bytes and attachment
bindings; Bitcoin proof verification is separate. The linked instructions
cover source and package installation.

### Post-quantum measurement

[Ed25519 and ML-DSA-65: signature size and local signing measurements](docs/PQ_MEASUREMENT_2026-09.md)
publishes the retained September 11 experiment, raw records, reproduction
instructions and limits. Production checkpoint issuance is parked.

TDQS

A4/5.0

Scored across 20 tools

Disambiguation3/5

The buy_* tools have overlapping catalogs (buy_simple and buy_small_pleasure sell the same small_blessing/daily_fortune/pack/window_pick, and hello appears in both buy_signed_record and buy_simple), and three tools (preflight_endpoint, look_at_door, check_before_you_pay) all probe x402 endpoints. The descriptions are unusually explicit about the differences and even say 'either tool is correct,' so an agent can disambiguate with careful reading, but the boundaries are not self-evident from names alone.

Naming Consistency4/5

Names overwhelmingly follow a snake_case verb-first pattern: buy_*, check_*, read_*, look_*, plus ring_bell, sign_guestbook, verify_artifact, and find_in_catalog. Minor deviations like preflight_endpoint (a check named as a noun) and look_in_window/look_at_door (phrasal verbs) keep it from a perfect 5, but the convention is consistent and predictable.

Tool Count3/5

At 20 tools, the server sits in the heavy 16-25 band. The count is inflated by redundant purchase doors (buy_simple vs buy_small_pleasure) and several overlapping x402 inspection tools that could be consolidated, though no tool is trivially useless.

Completeness4/5

The storefront covers browse, buy, payment status, order polling, artifact verification, and free store errands, with buy_observation and buy_human_task extending into audits and human fulfillment. Minor gaps remain—no unified purchase-history view and no refund/cancel path—but core workflows have no dead ends.

Maintenance

ActivityActive
ResponsivenessWithin a week