{"_id":"@bolyra/payment-protocols","_rev":"7-4246871abbe19834bb7560fc34cffb6b","name":"@bolyra/payment-protocols","dist-tags":{"latest":"0.9.0"},"versions":{"0.1.0":{"name":"@bolyra/payment-protocols","version":"0.1.0","keywords":["visa-tap","google-ap2","bolyra","zkp","agentic-commerce","agent-payments","zero-knowledge","privacy"],"license":"Apache-2.0","_id":"@bolyra/payment-protocols@0.1.0","maintainers":[{"name":"saneguy","email":"kondojuviswanadha@gmail.com"}],"homepage":"https://github.com/bolyra/bolyra#readme","bugs":{"url":"https://github.com/bolyra/bolyra/issues"},"dist":{"shasum":"a288c8782face725739e35a2633992998dc0a0af","tarball":"https://registry.npmjs.org/@bolyra/payment-protocols/-/payment-protocols-0.1.0.tgz","fileCount":26,"integrity":"sha512-CBWBGnURzFc0zu6Gx5JgbnXlgtLgKZy0ZqLgq8ltspfQmnaexRt2gXADgmvbCjk/7n7o08XA/+fwWthlG0v5sw==","signatures":[{"sig":"MEQCIFAlipzq0C8uHtcvF2rgnDdElXg3Fl0niO369RXGCGgAAiBF10y63FzZbhyQu5kd7ZZSI6Pq/hmfNaUHh5c9H5toZA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":185521},"main":"dist/index.js","types":"dist/index.d.ts","gitHead":"9c7b19b422af8e4977e3ca7bc6bc3fc2def8c1bf","scripts":{"test":"jest --passWithNoTests","build":"tsc","typecheck":"tsc --noEmit"},"_npmUser":{"name":"saneguy","email":"kondojuviswanadha@gmail.com"},"repository":{"url":"git+https://github.com/bolyra/bolyra.git","type":"git"},"_npmVersion":"11.6.2","description":"ZKP privacy layer for Visa TAP and Google AP2 — Bolyra as the identity backbone for agentic commerce","directories":{},"_nodeVersion":"24.13.0","dependencies":{"@bolyra/sdk":"^0.2.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^29.7.0","ts-jest":"^29.2.0","typescript":"^5.5.0","@types/jest":"^29.5.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/payment-protocols_0.1.0_1779429057060_0.271754293412801","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@bolyra/payment-protocols","version":"0.3.0","keywords":["visa-tap","google-ap2","bolyra","zkp","agentic-commerce","agent-payments","zero-knowledge","privacy"],"license":"Apache-2.0","_id":"@bolyra/payment-protocols@0.3.0","maintainers":[{"name":"saneguy","email":"kondojuviswanadha@gmail.com"}],"homepage":"https://github.com/bolyra/bolyra#readme","bugs":{"url":"https://github.com/bolyra/bolyra/issues"},"dist":{"shasum":"d3c2dc7c2f2ae27a3447cb128c80ceda4b212476","tarball":"https://registry.npmjs.org/@bolyra/payment-protocols/-/payment-protocols-0.3.0.tgz","fileCount":29,"integrity":"sha512-ESVxt8IQdAbyGtk3hCD5ViXtUmwQr7cN/QQsMQKFPXrv5eX3fafzl0w3cVPiPcgAIO0AmrBKPWGjmm7ukeXLqQ==","signatures":[{"sig":"MEUCIQCPaVQ+u0OZEPJG+6CyrVwuKytWrD/lT+AF3/DL8mlZ9QIgJWrR1uFGsF0eHAU/e9DEVor/1ohjHgkgOSIOpzfrzGY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":206602},"main":"dist/index.js","types":"dist/index.d.ts","gitHead":"cee2ff1b91fbec85cf4ace655a2565de57a11bcd","scripts":{"test":"jest --passWithNoTests","build":"tsc","typecheck":"tsc --noEmit"},"_npmUser":{"name":"saneguy","email":"kondojuviswanadha@gmail.com"},"repository":{"url":"git+https://github.com/bolyra/bolyra.git","type":"git"},"_npmVersion":"11.6.2","description":"ZKP privacy layer for Visa TAP and Google AP2 — Bolyra as the identity backbone for agentic commerce","directories":{},"_nodeVersion":"24.13.0","dependencies":{"@bolyra/sdk":"^0.3.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^29.7.0","ts-jest":"^29.2.0","typescript":"^5.5.0","@types/jest":"^29.5.0","@types/node":"^22.0.0"},"peerDependencies":{"@bolyra/sdk":">=0.3.0"},"_npmOperationalInternal":{"tmp":"tmp/payment-protocols_0.3.0_1780147674121_0.09011673222677063","host":"s3://npm-registry-packages-npm-production"}},"0.3.1":{"name":"@bolyra/payment-protocols","version":"0.3.1","keywords":["visa-tap","google-ap2","bolyra","zkp","agentic-commerce","agent-payments","zero-knowledge","privacy"],"license":"Apache-2.0","_id":"@bolyra/payment-protocols@0.3.1","maintainers":[{"name":"saneguy","email":"kondojuviswanadha@gmail.com"}],"homepage":"https://github.com/bolyra/bolyra#readme","bugs":{"url":"https://github.com/bolyra/bolyra/issues"},"dist":{"shasum":"2775669cc68d16cee42046ddb63b16e0cc9e6cd0","tarball":"https://registry.npmjs.org/@bolyra/payment-protocols/-/payment-protocols-0.3.1.tgz","fileCount":30,"integrity":"sha512-Uh9mHjSAIK0mUaqccfDvX+0VCwJmgiuI72AtpMSzf9AbWffdXjiP2O8HD6h/TMFpbKbRyZAxqigKfBq9xfgPtQ==","signatures":[{"sig":"MEQCICZn8x8aK+nqcFIssuVtg4pImsui178PK7gVjW1dO8W1AiA6VT/VBsAzmSPQeG4WQ0Ctfv78wdu071idT7966vjrdQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":214410},"main":"dist/index.js","types":"dist/index.d.ts","gitHead":"fe63968e7383e453105ba5012403960dc3909e69","scripts":{"test":"jest --passWithNoTests","build":"tsc","typecheck":"tsc --noEmit"},"_npmUser":{"name":"saneguy","email":"kondojuviswanadha@gmail.com"},"repository":{"url":"git+https://github.com/bolyra/bolyra.git","type":"git"},"_npmVersion":"11.6.2","description":"ZKP privacy layer for Visa TAP and Google AP2 — Bolyra as the identity backbone for agentic commerce","directories":{},"_nodeVersion":"24.13.0","dependencies":{"@bolyra/sdk":"^0.3.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^29.7.0","ts-jest":"^29.2.0","typescript":"^5.5.0","@types/jest":"^29.5.0","@types/node":"^22.0.0"},"peerDependencies":{"@bolyra/sdk":">=0.3.0"},"_npmOperationalInternal":{"tmp":"tmp/payment-protocols_0.3.1_1780171644055_0.4470665684720041","host":"s3://npm-registry-packages-npm-production"}},"0.5.0":{"name":"@bolyra/payment-protocols","version":"0.5.0","keywords":["visa-tap","google-ap2","bolyra","zkp","agentic-commerce","agent-payments","zero-knowledge","privacy"],"license":"Apache-2.0","_id":"@bolyra/payment-protocols@0.5.0","maintainers":[{"name":"saneguy","email":"kondojuviswanadha@gmail.com"}],"homepage":"https://github.com/bolyra/bolyra#readme","bugs":{"url":"https://github.com/bolyra/bolyra/issues"},"dist":{"shasum":"7c34a4bd45d52458874b35b4feee21eb2daa5107","tarball":"https://registry.npmjs.org/@bolyra/payment-protocols/-/payment-protocols-0.5.0.tgz","fileCount":33,"integrity":"sha512-ylcEthbLjJY2q0le6qNjLfyqO57wD5M3CPBjh0A7Wcb6ktcho+KDcLsUCyFh+HxPAQQiFouliO6zI7Zup+SnzA==","signatures":[{"sig":"MEUCIAcErdLkiXUpuVRz+GdhrQvfVWR/AXcU7xynF66tLpNRAiEA+6B18kLbatbz5pmRhtskUnD2H51WSS1C0T1XAL9knQU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@bolyra%2fpayment-protocols@0.5.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":232788},"main":"dist/index.js","types":"dist/index.d.ts","gitHead":"3482a7f2c8eed684e53dbf19b169cad8d4b50f3e","scripts":{"test":"jest --passWithNoTests","build":"tsc","typecheck":"tsc --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:e259cd6d-90cb-4870-b52c-e86a3c40712c"}},"overrides":{"ws":"8.21.0","tmp":"0.2.7","underscore":"1.13.8","circom_tester":{"snarkjs":"0.7.6"}},"repository":{"url":"git+https://github.com/bolyra/bolyra.git","type":"git"},"_npmVersion":"11.17.0","description":"ZKP privacy layer for Visa TAP and Google AP2 — Bolyra as the identity backbone for agentic commerce","directories":{},"_nodeVersion":"22.22.3","dependencies":{"@bolyra/sdk":"^0.4.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^30.4.2","ts-jest":"^29.2.0","typescript":"^5.5.0","@types/jest":"^30.0.0","@types/node":"^25.9.1"},"peerDependencies":{"@bolyra/sdk":">=0.4.0"},"_npmOperationalInternal":{"tmp":"tmp/payment-protocols_0.5.0_1781216849179_0.8990636908676517","host":"s3://npm-registry-packages-npm-production"}},"0.7.0":{"name":"@bolyra/payment-protocols","version":"0.7.0","keywords":["visa-tap","google-ap2","bolyra","zkp","agentic-commerce","agent-payments","zero-knowledge","privacy"],"license":"Apache-2.0","_id":"@bolyra/payment-protocols@0.7.0","maintainers":[{"name":"saneguy","email":"kondojuviswanadha@gmail.com"}],"homepage":"https://github.com/bolyra/bolyra#readme","bugs":{"url":"https://github.com/bolyra/bolyra/issues"},"dist":{"shasum":"41fba6032fdef36b6b14dbba824de24d6dfd9a2c","tarball":"https://registry.npmjs.org/@bolyra/payment-protocols/-/payment-protocols-0.7.0.tgz","fileCount":33,"integrity":"sha512-2kPSD+Iuqy9C6kyg0Cgb1hs6ckEHTRxPjKaE0mjWwFFVmG5DSyflR1UqDfTvynYkq0qxsdsS436ujQ8vbO3CvQ==","signatures":[{"sig":"MEUCIGqA84JU21GbfE4DleYcKn7o0dFDDOvKk3DoeDAOgGdbAiEAk2oxCGzCIhRDIyVPRP6hma/JscoPQdnREXJNJZ/ObUs=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@bolyra%2fpayment-protocols@0.7.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":241679},"main":"dist/index.js","types":"dist/index.d.ts","gitHead":"9aeaf1f3a681003267d70eb9d0eadc20605337ea","scripts":{"test":"jest --passWithNoTests","build":"tsc","typecheck":"tsc --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:e259cd6d-90cb-4870-b52c-e86a3c40712c"}},"overrides":{"ws":"8.21.0","tmp":"0.2.7","underscore":"1.13.8","circom_tester":{"snarkjs":"0.7.6"}},"repository":{"url":"git+https://github.com/bolyra/bolyra.git","type":"git"},"_npmVersion":"11.17.0","description":"ZKP privacy layer for Visa TAP and Google AP2 — Bolyra as the identity backbone for agentic commerce","directories":{},"_nodeVersion":"22.22.3","dependencies":{"@bolyra/sdk":"^0.4.0","@bolyra/receipts":"^0.7.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^30.4.2","ts-jest":"^29.2.0","typescript":"^5.5.0","@types/jest":"^30.0.0","@types/node":"^25.9.1"},"peerDependencies":{"@bolyra/sdk":">=0.4.0"},"_npmOperationalInternal":{"tmp":"tmp/payment-protocols_0.7.0_1781366360177_0.6142009785112015","host":"s3://npm-registry-packages-npm-production"}},"0.8.0":{"name":"@bolyra/payment-protocols","version":"0.8.0","keywords":["visa-tap","google-ap2","bolyra","zkp","agentic-commerce","agent-payments","zero-knowledge","privacy"],"license":"Apache-2.0","_id":"@bolyra/payment-protocols@0.8.0","maintainers":[{"name":"saneguy","email":"kondojuviswanadha@gmail.com"}],"homepage":"https://github.com/bolyra/bolyra#readme","bugs":{"url":"https://github.com/bolyra/bolyra/issues"},"dist":{"shasum":"a10d4591b1a22ab798011a6e62888bd12e5b85b5","tarball":"https://registry.npmjs.org/@bolyra/payment-protocols/-/payment-protocols-0.8.0.tgz","fileCount":36,"integrity":"sha512-kfgzOCSVyiZzgFsUytxUrt3M9jCW6hhnSCMFjd7+//j8mZFNF9gYiGxUyFVEL8jhVf4IK7mlzAdtZ1hF8bD9dQ==","signatures":[{"sig":"MEUCIQDWuIR7GuEA9mNxfHW33IfcH3V30NLwhTvIsKmNiAs+mQIgaF0DTNobFAfU4lbnBz2/AmBpl92wgbOBL90F8nUR7SE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@bolyra%2fpayment-protocols@0.8.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":274955},"main":"dist/index.js","types":"dist/index.d.ts","gitHead":"57b4c6703b0ce70c8c58924cc2f13e4876f142e6","scripts":{"test":"jest","build":"tsc","typecheck":"tsc --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:e259cd6d-90cb-4870-b52c-e86a3c40712c"}},"overrides":{"ws":"8.21.0","tmp":"0.2.7","underscore":"1.13.8","circom_tester":{"snarkjs":"0.7.6"},"brace-expansion":"5.0.9"},"repository":{"url":"git+https://github.com/bolyra/bolyra.git","type":"git"},"_npmVersion":"11.19.0","description":"ZKP privacy layer for Visa TAP and Google AP2 — Bolyra as the identity backbone for agentic commerce","directories":{},"_nodeVersion":"22.23.2","dependencies":{"@bolyra/mpp":"^0.4.0","@bolyra/sdk":"^0.6.1","@bolyra/receipts":"^0.11.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^30.4.2","ts-jest":"^29.2.0","typescript":"^5.5.0","@types/jest":"^30.0.0","@types/node":"^26.0.0"},"peerDependencies":{"@bolyra/sdk":">=0.4.0"},"_npmOperationalInternal":{"tmp":"tmp/payment-protocols_0.8.0_1787654431624_0.4243549705645384","host":"s3://npm-registry-packages-npm-production"}},"0.9.0":{"_id":"@bolyra/payment-protocols@0.9.0","bugs":{"url":"https://github.com/bolyra/bolyra/issues"},"dist":{"shasum":"c96aebd88717b5fe405ac1b5e4aafcef1cf591cf","tarball":"https://registry.npmjs.org/@bolyra/payment-protocols/-/payment-protocols-0.9.0.tgz","fileCount":45,"integrity":"sha512-5X5eFY6QZ0X8wpKvXQqXbmAGzLaY0pBbVuPwkvPSsYanjw7iUf3Y0qYUJrTM/VfBXDqmZW/m0OiP6XAyiFqC5A==","signatures":[{"sig":"MEYCIQCIzMIampfoQ/hhGoyq1MUoVGp3O82SEOw+3f3uxbFneAIhAMH234LuKRXhX/H0Sb8iOXVgNeDppAF0VdeP2h9iBvOC","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIEGg1XhdWhGH3265OXPT0CoSEXS+trK1LE7D93uXDHlrAiEAtk3mr/VtYGr/tmVIG9oYL8X4EL19LH+H9kVv0EBo8SU="}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@bolyra%2fpayment-protocols@0.9.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":382830},"main":"dist/index.js","name":"@bolyra/payment-protocols","types":"dist/index.d.ts","engines":{"node":"^20.19.0 || ^22.12.0 || >=23.0.0"},"gitHead":"c7991a9dfa0cf0ebc569b061cbaa6c95a3582f02","license":"Apache-2.0","scripts":{"test":"jest","build":"tsc","typecheck":"tsc --noEmit","typecheck:test":"tsc -p tsconfig.test.json"},"version":"0.9.0","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"e259cd6d-90cb-4870-b52c-e86a3c40712c"}},"homepage":"https://github.com/bolyra/bolyra#readme","keywords":["visa-tap","google-ap2","bolyra","zkp","agentic-commerce","agent-payments","zero-knowledge","privacy"],"overrides":{"ws":"8.21.0","tmp":"0.2.7","underscore":"1.13.8","circom_tester":{"snarkjs":"0.7.6"},"brace-expansion":"5.0.9"},"repository":{"url":"git+https://github.com/bolyra/bolyra.git","type":"git"},"_npmVersion":"11.20.0","description":"ZKP privacy layer for Visa TAP and Google AP2 — Bolyra as the identity backbone for agentic commerce","directories":{},"maintainers":[{"name":"saneguy","email":"kondojuviswanadha@gmail.com"}],"_nodeVersion":"22.23.2","dependencies":{"jose":"^6.2.12","@bolyra/mpp":"^0.4.0","@bolyra/sdk":"^0.6.1","@bolyra/receipts":"^0.11.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^30.4.2","ts-jest":"^29.2.0","typescript":"^5.5.0","@types/jest":"^30.0.0","@types/node":"^26.0.0"},"peerDependencies":{"@bolyra/sdk":">=0.4.0"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/payment-protocols_0.9.0_1790707641817_0.7074263561246843"}}},"time":{"created":"2026-05-22T05:50:56.860Z","modified":"2026-09-29T18:47:22.407Z","0.1.0":"2026-05-22T05:50:57.253Z","0.3.0":"2026-05-30T13:27:54.273Z","0.3.1":"2026-05-30T20:07:24.205Z","0.5.0":"2026-06-11T22:27:29.328Z","0.7.0":"2026-06-13T15:59:20.322Z","0.8.0":"2026-08-25T10:40:31.782Z","0.9.0":"2026-09-29T18:47:21.972Z"},"bugs":{"url":"https://github.com/bolyra/bolyra/issues"},"license":"Apache-2.0","homepage":"https://github.com/bolyra/bolyra#readme","keywords":["visa-tap","google-ap2","bolyra","zkp","agentic-commerce","agent-payments","zero-knowledge","privacy"],"repository":{"url":"git+https://github.com/bolyra/bolyra.git","type":"git"},"description":"ZKP privacy layer for Visa TAP and Google AP2 — Bolyra as the identity backbone for agentic commerce","maintainers":[{"name":"saneguy","email":"kondojuviswanadha@gmail.com"}],"readme":"# @bolyra/payment-protocols\n\n> ZKP privacy layer for agentic commerce payment protocols.\n> Open-source protocol research — not production software.\n\n## What This Does\n\nWhen AI agents make purchases on behalf of humans, payment networks need to verify:\n1. **Is this agent authorized?** (identity)\n2. **What can it spend?** (policy)\n3. **Did the human consent?** (authorization)\n\nToday, Visa's [Trusted Agent Protocol (TAP)](https://developer.visa.com/capabilities/trusted-agent-protocol) and Google's [Agent Payments Protocol (AP2)](https://github.com/google-agentic-commerce/AP2) answer these questions with centralized registries and plain-text mandates. The merchant sees everything — the user's identity, their exact budget, their full policy.\n\n**Bolyra replaces that with zero-knowledge proofs.** The merchant learns only:\n- \"This agent is authorized\" (yes/no)\n- \"The spend policy is sufficient for this transaction\" (yes/no)\n- A trust score (0–100)\n\nThe merchant never sees: the human's identity, the exact spend limit, the full vendor allowlist, or the delegation chain structure.\n\n## Architecture\n\n```\n┌──────────────┐     ┌──────────────────┐     ┌──────────────┐\n│  Human       │────▸│  Bolyra SDK      │────▸│  ZKP Proof   │\n│  (identity)  │     │  (handshake +    │     │  (public      │\n│              │     │   spend policy)  │     │   signals     │\n└──────────────┘     └──────────────────┘     │   only)       │\n                                              └──────┬───────┘\n                                                     │\n                              ┌───────────────────────┼───────────────────────┐\n                              ▼                       ▼                       ▼\n                     ┌────────────────┐     ┌────────────────┐     ┌─────────────────┐\n                     │  Visa TAP      │     │  Google AP2    │     │  Spend Policy   │\n                     │  Adapter       │     │  Adapter       │     │  Encoder        │\n                     │                │     │                │     │                 │\n                     │  TAP payment   │     │  AP2 mandate   │     │  Bitmask        │\n                     │  signal +      │     │  proof +       │     │  encoding +     │\n                     │  trust score   │     │  delegation    │     │  verification   │\n                     └────────────────┘     └────────────────┘     └─────────────────┘\n```\n\n## Protocol Mapping\n\n### Visa TAP\n\n| TAP Concept | Bolyra Equivalent |\n|---|---|\n| Agent registry lookup | ZKP proof of human authorization |\n| HTTP Message Signature (RFC 9421) | ZKP proof + scope commitment |\n| Payment Instructions API | Spend policy encoded in permission bitmask |\n| Payment Signals API | Scope commitment + agent nullifier |\n| Trust tier | Score-based grading (A/B/C/D/F) |\n\n### Google AP2\n\n| AP2 Concept | Bolyra Equivalent |\n|---|---|\n| Intent Mandate | Bolyra handshake proof (human → agent) |\n| Cart Mandate | Spend policy ZKP (covers specific transaction) |\n| Payment Mandate | Off-chain verified proof (batch mode) |\n| Agent-to-agent delegation | Bolyra delegation chain with hop tracking |\n| Mandate signature | ZKP proof (Groth16 for human, PLONK for agent) |\n\n### Stripe Agent Commerce Protocol (ACP)\n\n| Stripe ACP Concept | Bolyra Equivalent |\n|---|---|\n| Acting agent | Leaf delegatee in the v=2 bundle's `delegationChain` |\n| Originating agent | Root credential the human authorized at handshake |\n| Delegation depth | `chainDepth` from the verified context |\n| Spending cap | Collapsed from cumulative `FINANCIAL_*` bits (2/3/4) on the leaf scope |\n| `sign_on_behalf` flag | Bit 5 of the leaf scope (for `pi.confirm` flows) |\n\nThe narrowing wedge: a root agent with `FINANCIAL_UNLIMITED` can delegate down to a sub-agent with `FINANCIAL_SMALL` ($100 cap). Stripe ACP sees only the leaf's $100 cap, even though the root could have spent more.\n\n## Usage\n\n### Visa TAP Verification\n\n```typescript\nimport { createVisaTAPVerification } from '@bolyra/payment-protocols';\n\nconst result = await createVisaTAPVerification(\n  humanIdentity,\n  agentCredential,\n  {\n    maxTransactionAmount: 50_000, // $500\n    maxCumulativeAmount: 100_000, // $1,000\n    currency: 'USD',\n    timeWindow: { start: now, end: now + 86400 },\n  },\n  {\n    agentDid: 'did:bolyra:base-sepolia:...',\n    merchantId: 'visa-merchant-123',\n    amount: 5_000,\n    currency: 'USD',\n    transactionId: 'txn-abc-123',\n  },\n);\n\n// result.verified: boolean\n// result.score: 0-100\n// result.grade: 'A' | 'B' | 'C' | 'D' | 'F'\n// result.paymentSignal: opaque token for TAP Payment Signals API\n```\n\n### Google AP2 Agent Credential\n\n```typescript\nimport { createAP2AgentCredential, verifyAP2AgentCredential } from '@bolyra/payment-protocols';\n\n// Agent side: create credential\nconst credential = await createAP2AgentCredential(\n  humanIdentity,\n  agentCredential,\n  [\n    { name: 'purchase', maxAmount: 50_000, currency: 'USD' },\n    { name: 'price_compare', maxAmount: 0, currency: 'USD' },\n  ],\n);\n\n// Merchant side: verify credential\nconst verification = await verifyAP2AgentCredential(credential);\n// verification.verified: boolean\n// verification.score: 0-100\n```\n\n### Stripe ACP — narrowing wedge\n\n```typescript\nimport {\n  authContextToStripeACPContext,\n  verifyStripeACPSpend,\n} from '@bolyra/payment-protocols';\nimport { verifyBundle } from '@bolyra/mcp';\n\n// 1. Verify the v=2 bundle once (handshake + delegation chain).\nconst ctx = await verifyBundle(bundle, mcpConfig);\n\n// 2. Reshape into a Stripe ACP context. The leaf delegatee becomes the\n//    acting agent; the root credential the human authorized stays as the\n//    originating agent for audit.\n// rootAgentDid comes from ctx.did (set by verifyBundle from the verified\n// credential commitment) — no caller-supplied root, no chain rebinding.\nconst acp = authContextToStripeACPContext(\n  ctx,\n  'base-sepolia', // DID network for actingAgentDid (must match ctx.did's network)\n  'usd',          // ISO 4217 currency; lowercase per Stripe convention\n);\n\n// 3. Gate each PaymentIntent against the leaf-narrowed cap.\nconst decision = verifyStripeACPSpend(acp, 5_000, 'USD'); // $50\nif (!decision.allowed) {\n  throw new Error(`Stripe ACP denied: ${decision.reason}`);\n}\n\n// Example: root had FINANCIAL_UNLIMITED, but the chain narrowed the leaf\n// to FINANCIAL_SMALL. Stripe sees a $100 cap, not the root's authority.\n//   decision.tier === 'small'\n//   decision.capChecked === 10_000  // $100 in cents\n```\n\n### Spend Policy Encoding\n\n```typescript\nimport { encodeSpendPolicy, verifySpendPolicyProof } from '@bolyra/payment-protocols';\n\n// Encode for ZKP circuit\nconst bitmask = encodeSpendPolicy({\n  maxTransactionAmount: 50_000,\n  maxCumulativeAmount: 100_000,\n  currency: 'USD',\n  timeWindow: { start: now, end: now + 86400 },\n  categoryRestriction: { allowedMCCs: ['5411', '5812'] },\n});\n\n// Merchant-side verification (from ZKP public signals)\nconst { satisfied, reasons } = verifySpendPolicyProof(bitmask, {\n  minTransactionAmount: 10_000,\n  requiredMCCs: ['5411'],\n});\n```\n\n## x402 EVC profile — issuer-quoted payee binding (§4.2)\n\nThe x402 EVC authorization-evidence profile (`spec/x402-evc-profile-v0.md`)\ncarries \"who permitted this spend?\" through the 402/retry round-trip. Its\npayee check is byte equality `audience === payTo`. When a 402 leg names a\nplaceholder `payTo` and carries an issuer-signed quote, an agent-side host\ncan bind the payee to the quote issuer instead:\n\n```ts\nimport {\n  createIssuerQuotePayeeResolver,\n  verifyX402EvcAuthorization,\n  x402LocalChallenge,\n} from '@bolyra/payment-protocols';\n\nconst resolvePayee = await createIssuerQuotePayeeResolver({\n  issuers: new Map([['https://x402.tavily.com', {\n    payTo: 'urn:x402:agent-pay:see-quote', scheme: 'agent-pay', network: 'aws:base',\n    audience: 'aws:marketplace', payToRole: 'seller',\n    keys: new Map([['tavily-agentpay-x402-signing-key', { alg: 'ES384', jwk /* provisioned out of band */ }]]),\n    products: new Map([['https://x402.tavily.com/search', {\n      reference: 'tavily-search-advanced', 'settlement.product_id': 'prod-maeet6sajeg42',\n    }]]),\n    settlementFields: [\n      { challenge: 'extra.reference', claim: 'reference' },\n      { challenge: 'extra.settlement.product_id', claim: 'settlement.product_id' },\n    ],\n    unboundExtraFields: ['tier'], // present on the leg, unverified, never reaches checkedLeg\n  }]]),\n});\n\nconst local = x402LocalChallenge({\n  headerValue: response.headers.get('payment-required')!, // exactly as received\n  resource: 'https://x402.tavily.com/search',             // host-known outbound URL\n  legIndex: 1, now: Math.floor(Date.now() / 1000), maxSeconds: 300,\n});\n\nconst decision = await verifyX402EvcAuthorization(presentation, {\n  localChallenge: local, audience: 'https://x402.tavily.com', resolvePayee,\n  verifier: { kind: 'classical', trustedOperators }, nonceStore /* shared, durable */,\n});\nif (decision.allowed) settle(decision.checkedLeg); // the ONLY leg to settle\n```\n\nWhat a successful binding proves: the holder of the issuer's key quoted this\nproduct at this price within this window, and the challenge's settlement\nfields match that quote. What it does NOT prove: ownership of any derived\non-chain address (an unbound derived `payTo` still denies), that the quote\nwas addressed to this host, who ultimately receives funds, or delivery.\n`x402_evc.payee_binding` is a host assertion for audit; `payee` stays the\nliteral placeholder, and receipts under spec §4.1 do not commit to the\nbinding. `token_sha256` is an audit handle, not a unique quote identifier\n(ECDSA signatures are malleable); replay identity is `(issuer, jti)`. Keys\nare never discovered; a resolver never touches the network. Any leaf under\n`extra` that is not the token, a bound settlement field, or a declared\n`unboundExtraFields` entry denies, and `checkedLeg.extra` carries only the\nverified paths.\n\nThe issuer, key id and product identifiers above are the shape observed on\na public 402 on 2026-09-29 and are used as an example only; no endorsement\nis implied.\n\n## Design Principles\n\n1. **Thin glue** — all cryptographic work delegates to `@bolyra/sdk`\n2. **Lazy SDK import** — heavy crypto deps load only when needed\n3. **Score-based results** — consistent with the OpenClaw adapter pattern\n4. **Off-chain by default** — batch verification for high-throughput commerce\n5. **Privacy-preserving** — merchant never learns more than necessary\n6. **Protocol-agnostic core** — spend policy encoding works with any payment protocol\n\n## License\n\nApache-2.0 — open-source protocol research.\n","readmeFilename":"README.md"}