Deterministic, cryptographically verifiable policy decision point (PDP) and constrained signer for autonomous AI agents on Solana devnet.
AI agents operating on public blockchains traditionally require hot wallet custody, exposing operators to total fund drainage or compromised subagents. CredaVer decouples spending authorization from custodial keys through a zero-custody proxy pattern:
Operator signs an Ed25519 mandate defining allowed merchants, permitted tokens, per-transaction caps, and expiry.
Agent generates an in-memory keypair. It signs only single-use payment intent proofs bound to the mandate hash and nonce.
CredaVer PDP evaluates all 12 deterministic gates. If ALLOWed, it signs the transaction with server-held keys and issues a signed receipt.
| Gate | Name | Verification Check | Rejection Code |
|---|---|---|---|
| 1 | Schema Conformance | Zod structural parse of signed mandate & proof | SCHEMA_VALIDATION_FAILED |
| 2 | Operator Signature | Ed25519 verification over RFC 8785 canonical mandate bytes | INVALID_OPERATOR_SIGNATURE |
| 3 | Agent Signature | Ed25519 mutual counter-signature over canonical mandate | INVALID_AGENT_COUNTER_SIGNATURE |
| 4 | Revocation Check | Store query for explicit operator emergency revocation flag | REVOKED_MANDATE |
| 5 | Temporal Window | validFrom <= now <= expiresAt boundary validation | EXPIRED_MANDATE |
| 6 | Network Match | Exact CAIP-2 genesis match (solana:EtWTRABZaYq...) | NETWORK_MISMATCH |
| 7 | Merchant Whitelist | Destination merchant pubkey in allowed whitelist or wildcard | MERCHANT_NOT_ALLOWED |
| 8 | Asset Whitelist | Token mint in mandate allowedAssets list (Devnet USDC) | ASSET_NOT_ALLOWED |
| 9 | Proof Integrity | Agent signature over request-bound canonical payment proof | INVALID_PROOF_SIGNATURE |
| 10 | Per-Tx Limit | amount <= maxPerTx integer comparison | AMOUNT_EXCEEDS_PER_TX |
| 11 | Cumulative Cap | currentSpend + amount <= totalCap in store | AMOUNT_EXCEEDS_CAP |
| 12 | Atomic Replay Protection | Atomic Redis SET NX EX consumes proof nonce | REPLAY_DETECTED |
Every policy evaluation produces an immutable Signed Decision Receipt. The receipt body is serialized using RFC 8785 JSON Canonicalization Scheme (JCS), SHA-256 hashed, and signed with the configured CredaVer Authority Ed25519 secret key (CREDAVER_AUTHORITY_SECRET_KEY).
credav:1:<mandateHashFirst8>:<receiptHash>:<decision>Anchored transactions write the memo to Solana Devnet via the SPL Memo Program (MemoSq4gqABAXKb96qnH8TysNcWxMyWCqXgDLGmfcHr). Anyone can verify the memo block time, slot, and hash match without trusting CredaVer servers.
Execute simulated or live scenarios: ALLOW, OVER_CAP, REVOKED, EXPIRED, REPLAY, REVIEW, REAL_DEVNET.
Verifies any stored receipt by ID or on-chain memo transaction signature globally.
Lists operator mandates belonging to visitor session. Defaults to active only; supports ?showAll=true.
Submits a co-signed operator and agent mandate for verification and storage.
Constructs the canonical RFC 8785 mandate core and readable text message for Phantom signing.
Emergency revocation endpoint setting the mandate status to revoked.
Lists signed decision receipts for the current visitor session, newest first.
Returns single stored receipt record by receipt ID.
Operator review queue actions: approve or reject high-value transactions held in REVIEW status.
System health and devnet connectivity check returning cluster status and timestamp.
CredaVer rejects misleading "trustless" buzzwords. Security relies on deterministic code execution and asymmetric cryptography: