{"core_checks":["status-402","payment-required-header","x402-version","accepts"],"conditional_checks":["bazaar-extension","signed-offers"],"verdict_fold_checks":["payto-payable","amount-atomic","network-mainnet","transfer-method-signable","solana-rail-receivable"],"advisories":["nonstandard-scheme","testnet-network","payto-is-a-name","payto-wrong-rail","payto-not-an-address","amount-not-atomic","missing-eip712-domain-extra","nonstandard-transfer-method","conflicting-amounts","above-default-client-cap","placement-mismatch","resource-host-mismatch","discovery-info-fails-schema","resource-description-absent","offer-contradicts-challenge","no-bazaar-extension","inputs-declared","no-input-contract","retry-key-declared","retry-key-not-in-challenge","signed-offers-not-in-challenge","large-body"],"batteries":{"v1":{"adds":[]},"v2":{"adds":["payto-payable","amount-atomic","network-mainnet","transfer-method-signable","solana-rail-receivable"]}},"changelog":[{"date":"2026-08-03","battery":"v1","change":"v1 ships and freezes: the structural core (status-402, payment-required-header, x402-version, accepts) and nothing else, so a ready recorded under it means the same thing forever."},{"date":"2026-08-23","battery":"v2","change":"v2 begins, folding solana-rail-receivable into the verdict: a door whose payTo cannot be credited is not ready by any reading a buyer would accept. v1 keeps serving; both verdicts render from one probe."},{"date":"2026-08-26","battery":"v2","change":"v2 folds the L3b consistency trio (payto-payable, amount-atomic, network-mainnet): an unpayable 402 stops reading ready. The same observations ride v1 as advisories, outside its verdict."},{"date":"2026-08-28","battery":"v1","change":"The signed-offers conditional check reads BOTH placements — the PAYMENT-REQUIRED header and the 402 body — where it had read the header only and told issuers placing offers where the offer-receipt convention says (the body) that they served nothing. Conditional and outside the verdict, so a v1 ready is unchanged; reports and advisories now name the placements actually read."},{"date":"2026-08-28","battery":"v2","change":"Same placement widening as v1's entry of this date: signed-offers reads the header and the body. Conditional, outside the v2 verdict."},{"date":"2026-08-28","battery":"v2","change":"The depth pass, two deepenings of checks v2 already folds. amount-atomic covers the whole grammar: an amount that is not a non-negative integer string (negative, exponent, hex, empty) now fails beside the decimal case — no client can sign an authorization for any of them. solana-rail-receivable reads the account state the RPC always returned: an owner whose every USDC token account is explicitly FROZEN cannot be credited and now fails; an account whose state the ledger omitted still passes, because an unknown state read as frozen would fabricate a defect. Advisory-side, outside every verdict, five new readings ship the same day: missing-eip712-domain-extra, conflicting-amounts, placement-mismatch, resource-host-mismatch, and the EVM USDC blacklist read (payto-usdc-blacklisted / evm-rail-receivable / evm-rail-unread) on the PAID single-door audit only — the free preflight keeps its one-outbound-request promise and the census cannot afford one eth_call per EVM door, so folding what they cannot run would split the v2 citation."},{"date":"2026-08-28","battery":"v1","change":"The advisory `no-signed-offers` is renamed `signed-offers-not-in-challenge`, and its detail now names the three readings one absent-from-the-challenge observation cannot separate, with a falsifier. NOTHING ABOUT THE MEASUREMENT CHANGED — the same bytes are read at the same placements and the same doors are flagged. What changed is the claim: the old name asserted a fact about the endpoint that this probe never established. Rows sealed before this date carry the old name and stand as history; the market desk joins both."},{"date":"2026-08-29","battery":"v2","change":"accepts[].extra.assetTransferMethod is read, on every rail, in both batteries: nonstandard-transfer-method when a door asks for a recognized method that is not eip3009 (permit2, erc7710), unrecognized-transfer-method when it asks for something no published client can build. NO VERDICT MOVED — both are advisories, neither battery folds them, and every ready recorded before this date means exactly what it meant. The field decides whether a buyer's signature is acceptable at all, and this battery had read extra.name and extra.version out of the same object while stepping over it. The paid launch check began refusing to sign at such a door on 2026-08-29; this is the same reading, free, before anybody spends. Whether either verdict ever folds it is a battery decision and stays unmade."},{"date":"2026-08-29","battery":"v2","change":"The input contract is read for a retry key: retry-key-declared when a declared input names a field a buyer can hold steady across a retry (idempotency key, order id, request id, client reference, purchase id), retry-key-not-in-challenge when inputs are declared and none of them is one. Advisory in both batteries, folded by neither, and read ONLY where inputs are declared — a door declaring no input contract already draws that advisory, and counting one silence twice would inflate a finding. The absent case names the three readings it cannot separate and carries a falsifier, the same discipline signed-offers-not-in-challenge took on 08-28: a door may key idempotency on a header this probe never sees. Occasioned by an outside reading (CV, 2026-08-28) that the ecosystem absorbed the double-charge lesson at the SDK layer, leaving hand-rolled authorization paths — where a retry signs a fresh nonce, which the x402 nonce rule does not protect."},{"date":"2026-08-30","battery":"v2","change":"v2 FOLDS a new check: transfer-method-signable. An accepts entry naming an authorization standard in extra.assetTransferMethod that no published client can build is unsignable in exactly the sense amount-atomic is unsignable, so it now costs a door its ready under v2 instead of riding as an advisory. THIS MOVES READY on doors this battery has already published rows about, which is why it took a keeper's ruling rather than a build decision — rows sealed before this date were scored under the battery as it stood and stand as history, and v1 is frozen and unaffected. The advisory `unrecognized-transfer-method` is retired from ADVISORY_NAMES the same day: one observation gets one voice, and carrying both would double-count it. What is NOT folded: a door asking for permit2 or erc7710 still passes and still draws only the advisory `nonstandard-transfer-method`. Those are real standards that real clients build, named in the place the spec provides, and counting them against a door would be scoring an operator for telling the truth about themselves. Absence passes too — the field is optional and eip3009 is the settled default."},{"date":"2026-09-02","battery":"v2","change":"S8 Tier A, advisory-side and outside every verdict: three readings of a door disagreeing with itself inside one 402. discovery-info-fails-schema applies the catalog's own listing rule (the bazaar info block must satisfy the schema beside it) over type, const, enum, required, properties and items; offer-contradicts-challenge decodes each signed offer's payload and looks for the accepts entry it commits to by network, asset, payTo and amount, so a signed promise of one price beside a challenge for another is named; resource-description-absent notes a bazaar block with no top-level resource description, the field the catalog indexes. placement-mismatch now names which fields differ between the header and body challenges. No verdict moved; the fold into v3 is the keeper's call after a month of rows."}],"ruleset_digest_covers":"core_checks, conditional_checks, verdict_fold_checks, advisories, batteries, changelog","ruleset_digest":"3a10558d465c8f4eda842d501a56e3e83715f304524809de3d7ec9aa730d3e33","how_to_recompute":"JSON.stringify an object holding the fields ruleset_digest_covers names, in that order, exactly as served; SHA-256 the UTF-8 bytes; hex-encode. No canonicalizer beyond field order — the served bytes are the canonical form.","note":"Derived from the same registries the battery runs. A criteria page and a verdict can no longer disagree, because both read this."}