{
  "assurance_vocabulary": {
    "APPEND_ONLY_COUNTING": "append-only observation and immutable snapshots",
    "CRYPTOGRAPHIC_SIGNATURE": "Ed25519 signature over a canonical document",
    "DETERMINISTIC_EVALUATION": "same inputs, same verdict, no model, no heuristic",
    "GOVERNED_IMMUTABLE_POLICY": "immutable policy under an append-only lifecycle",
    "IMMUTABLE_PUBLISHED_ARTIFACT": "content-addressed and insert-only",
    "MERKLE_PROOF_LEDGER_BOUND": "Merkle membership bound to a ledger transaction",
    "RECOMPUTED_MEASUREMENT": "a measurement redone at use time rather than read back",
    "SHARED_SECRET_OVER_TLS": "a bearer credential over TLS; not proof of key possession",
    "SIGNED_RESOLVER_RECORD": "a signed record produced by a resolver",
    "STATIC_ANALYSIS_OF_INSTALLED_CODE": "derived from the code that is installed"
  },
  "builder_version": "nomos-capability-manifest-builder/1.0.0",
  "canonical_url": "https://agentnomos.com/.well-known/nomos-capabilities.json",
  "content_digest": "sha256:08047ce7a212fe900c19be5dce146e50d67b12769b108988f42bb71bee31b502",
  "description": "The eleven-stage trust chain NOMOS actually runs in production, from anchor freshness (S0) to governed shadow policy (S10). Each stage states what happened to it, how strong that statement is, and whether an outside party can check it. No stage is called VERIFIED merely because it ran, and no score is derived anywhere in this model.",
  "digest_rule": {
    "canonical_json": "json.dumps(obj, sort_keys=True, separators=(\",\",\":\"), ensure_ascii=False).encode(\"utf-8\")",
    "content_digest": "sha256 of canonical JSON of this document with the members generated_at, content_digest and manifest_digest removed",
    "manifest_digest": "sha256 of canonical JSON of this document with the member manifest_digest removed"
  },
  "discovery": {
    "compatibility_map": "https://agentnomos.com/.well-known/nomos-compatibility.json",
    "compatibility_map_note": "How the S0-S10 model relates to external agent, commerce and ledger technologies. Relationships only: the map states which are actually used, which merely overlap in subject, and which are not implemented at all.",
    "extension_field_names": {
      "agent_card": "x-nomos-trust-chain",
      "openapi": "x-nomos-trust-chain",
      "openapi_operation": "x-nomos-governed-action"
    },
    "extension_uri": "https://agentnomos.com/extensions/nomos-trust-chain-v1",
    "linked_from": [
      {
        "mechanism": "extensions[] entry with the NOMOS extension uri, plus the top-level x-nomos-trust-chain member",
        "url": "https://agentnomos.com/.well-known/agent-card.json"
      },
      {
        "mechanism": "extensions[] entry with the NOMOS extension uri, plus the top-level x-nomos-trust-chain member",
        "url": "https://agentnomos.com/.well-known/agent.json"
      },
      {
        "mechanism": "extensions[] entry with the NOMOS extension uri, plus the top-level x-nomos-trust-chain member",
        "url": "https://agentnomos.network/.well-known/agent-card.json"
      },
      {
        "mechanism": "Discovery section entry",
        "url": "https://agentnomos.com/llms.txt"
      },
      {
        "mechanism": "top-level x-nomos-trust-chain vendor extension, plus x-nomos-governed-action on the cohort operations",
        "url": "https://feedoracle.io/.well-known/openapi.json"
      },
      {
        "mechanism": "top-level x-nomos-trust-chain member",
        "url": "https://feedoracle.io/.well-known/agent-card.json"
      },
      {
        "mechanism": "Discovery section entry",
        "url": "https://feedoracle.io/llms.txt"
      }
    ],
    "manifest": "https://agentnomos.com/.well-known/nomos-capabilities.json",
    "namespace_note": "The links below are NOMOS-namespaced vendor extensions. They are not part of the A2A specification, the OpenAPI specification or any llms.txt convention, and must not be read as conformance to those standards.",
    "public_x402_capability": {
      "action_class": "read_only",
      "discovery_protocol": "A2A agent cards / ai-catalog / llms.txt / compatibility map (discovery only — an A2A message/send call does NOT invoke this capability)",
      "id": "nomos_full_chain_verification",
      "invocation": "https://tooloracle.io/v2/nomos_full_chain_verification",
      "invocation_method": "POST",
      "invocation_protocol": "x402 HTTP",
      "namespace_note": "NOMOS vendor extension, not part of the S0-S10 stage model: maps the publicly offered paid capability onto the governed capability this manifest already covers. Added 2026-08-11 (MACHINE_TRUTH_SURFACE_R2).",
      "payment_network": "eip155:8453",
      "payment_required": true,
      "price_usdc": "0.001",
      "proof_model": "EXECUTION_BOUND_PROOF",
      "reproducibility": "https://agentnomos.com/.well-known/nomos-reproducibility.json",
      "settlement_direction": "inbound only: the operator accepts x402 payment for this service. No autonomous outbound wallet settlement authority is stated or implied by this capability.",
      "underlying_capability": "RWA_REGISTRY_STATS_READ",
      "underlying_route": "/v1/rwa/registry/stats",
      "underlying_route_note": "member of scope.production_route_cohort in this manifest; the paid call traverses intent, offer/match, admission (including current OracleNet security-freshness evidence), execution, Ed25519-signed receipt, outcome and S10 shadow exactly as the stages describe",
      "underlying_subject": "feedoracle.io"
    }
  },
  "generated_at": "2026-08-11T07:43:08Z",
  "manifest_digest": "sha256:64c36d3b5e0fe13f33a0e9d7a267c4e37f03e6e72cf3714c507513e5c2be632c",
  "model_version": "1.0.0",
  "name": "NOMOS Machine Economy Trust Chain",
  "not_claimed": [
    "ToolOracle does not have FULL S8. The S8 assurance stated here is scoped to the subject and cohort named in scope, and to nothing else.",
    "S9 is not a public reputation score, not a ranking and not a cross-party comparison.",
    "S10 does not block, delay or alter any production request. It is observational only.",
    "Not every NOMOS service runs through all eleven stages. The full S0-S10 chain is proven for the route cohort named in scope, not for the product portfolio.",
    "Not every route is under admission enforcement. Only the routes listed in scope.production_route_cohort are.",
    "Not every execution is blockchain-anchored. Anchoring is periodic and per subject, not per request.",
    "NOMOS is not a certification body, a registrar or an accreditation authority.",
    "Nothing here establishes regulatory compliance. No compliance status is determined automatically by this manifest or by the chain it describes.",
    "This manifest is a description of implemented mechanism, not a warranty, an audit opinion or a guarantee of future behaviour."
  ],
  "publisher": {
    "identity_document": "https://agentnomos.com/.well-known/nomos-identity.json",
    "name": "NOMOS",
    "operator": "FeedOracle Technologies",
    "url": "https://agentnomos.com"
  },
  "runtime_vocabulary": {
    "ENFORCING": "this stage can refuse a live production request",
    "ENFORCING_INPUT": "computed before the decision and able to refuse it, but it is not itself the refusing check",
    "OBSERVING_ONLY": "no return path into admission, execution or enforcement",
    "POST_HOC_OBSERVATION": "runs after the response and cannot affect it",
    "RECORDING": "produces an artefact as part of serving the request"
  },
  "s8_assurance_not_implied": {
    "EXECUTION_BOUND_PROOF": [
      "does not prove the factual correctness of the provider's output",
      "does not prove the provider itself signed or attested the result",
      "does not prove any independent or external source confirms the result"
    ],
    "INDEPENDENT_EXTERNAL_PROOF": [
      "does not prove the factual correctness of the provider's output"
    ],
    "PROVIDER_ORIGIN_PROOF": [
      "does not prove the factual correctness of the provider's output",
      "does not replace the NOMOS execution receipt"
    ]
  },
  "s8_assurance_vocabulary": {
    "EXECUTION_BOUND_PROOF": "A cryptographically signed execution receipt binds the decision, the intent, the offer, the execution, the sha256 of the exact response bytes, the subject, the capability, the route and method, and the authoritative consumer identity; an outside party can verify that signature against a published key.",
    "INDEPENDENT_EXTERNAL_PROOF": "A source outside this system can separately check a relevant claim, for example a ledger anchor or an attestation this system did not produce.",
    "MULTI_SOURCE_PROOF": "Two or more mutually independent proof sources exist for the same claim.",
    "PROVIDER_ORIGIN_PROOF": "The provider itself produces a cryptographically verifiable artefact over its own result or a canonical projection of it, signed with a provider key that the execution gate cannot sign with."
  },
  "schema": "nomos.machine-economy-trust-chain.capabilities.v1",
  "scope": {
    "cohorts": [
      {
        "claim": "These routes, and only these, run through NOMOS admission with S0-S10 as described. No other route of this subject is covered by this document, and the number of routes the subject serves in total is not stated here.",
        "route_count": 5,
        "routes": [
          "/v1/rwa/history",
          "/v1/rwa/legal-state",
          "/v1/rwa/legal-state/stats",
          "/v1/rwa/registry",
          "/v1/rwa/registry/stats"
        ],
        "subject_id": "feedoracle.io"
      },
      {
        "claim": "These routes, and only these, run through NOMOS admission with S0-S10 as described. No other route of this subject is covered by this document, and the number of routes the subject serves in total is not stated here.",
        "route_count": 3,
        "routes": [
          "/handshake-stats",
          "/nomos/handshake",
          "/nomos/regulatory-gap"
        ],
        "subject_id": "tooloracle.io"
      }
    ],
    "enforcement": {
      "admission": "ENFORCING",
      "admission_policy_version": "2026-08-10.r2.oraclenet-secfresh",
      "capability_derivation_method": "ast",
      "capability_map_digest": "sha256:6bfb17db543d28260da1050dfa99f7b3b4f023c6f0dfc17162f7388e068a3589",
      "decision_ttl_seconds": 30,
      "intent_header": "X-NOMOS-Intent",
      "intent_policy_version": "2026-08-08.r23.tooloracle-route3",
      "intent_task_fit": "ENFORCING",
      "max_intent_bytes": 4096,
      "max_intent_ttl_seconds": 300,
      "offer_catalog_digest": "sha256:c3398427e7006cb852f427fc877c6f76d8679a21197347f0f8d21aae4d3afb83"
    },
    "limitations": [
      "The complete S0-S10 chain is proven for the read-only routes listed in production_route_cohort, on the subjects named in scope.subjects, and for a controlled consumer path. It is not a portfolio-wide statement.",
      "The two subjects are NOT at the same assurance. feedoracle.io has an independent ledger anchor and its admission decisions carry S8 anchor evidence. tooloracle.io has NO independent anchor: its decisions are issued under the observed_presence_v1 evidence profile and record s8_anchor=false explicitly. For that subject the proof of a call is the signed execution receipt, not a ledger anchor, and a reader must not treat the two as interchangeable.",
      "S2 authenticates with a shared secret over TLS. No consumer holds a signing key, so identity at S2 is not cryptographic proof of possession.",
      "S6 decisions and S7 receipts are signed; the decision document itself is not published. An outside party verifies the receipt and the bindings it carries.",
      "S8 assurance is stated for subject anchor proofs. It is not a claim that every individual execution carries its own on-ledger proof.",
      "S9 and S10 are observational. Neither has a return path into admission or execution.",
      "The cohort routes are read-only and free: price is declared as amount 0, currency NONE, settlement_required false. Declared free is not the same as price unknown.",
      "feedoracle.io is IN SCOPE FOR EXACTLY 5 ROUTES: /v1/rwa/history, /v1/rwa/legal-state, /v1/rwa/legal-state/stats, /v1/rwa/registry, /v1/rwa/registry/stats. That subject serves other endpoints; none of them is governed by NOMOS and none of them is covered by this document. A statement of the form 'feedoracle.io is S0-S10 governed' would be false. The governed set for that subject is scope.cohorts[subject_id=feedoracle.io].routes and nothing else.",
      "tooloracle.io is IN SCOPE FOR EXACTLY 3 ROUTES: /handshake-stats, /nomos/handshake, /nomos/regulatory-gap. That subject serves other endpoints; none of them is governed by NOMOS and none of them is covered by this document. A statement of the form 'tooloracle.io is S0-S10 governed' would be false. The governed set for that subject is scope.cohorts[subject_id=tooloracle.io].routes and nothing else."
    ],
    "production_route_cohort": [
      {
        "access_scope": "tooloracle:read",
        "capability_id": "HANDSHAKE_ROUTING_STATS_READ",
        "external_network_dependency": false,
        "methods": [
          "GET",
          "HEAD"
        ],
        "offer_digest": "sha256:d79d25830a61c231bf1361a7d391a4f88ce56177fae0108bb6753c613cb39c28",
        "persistent_side_effects": false,
        "price": {
          "amount": "0",
          "currency": "NONE",
          "settlement_required": false
        },
        "public_url": "https://tooloracle.io/handshake-stats",
        "read_only": true,
        "route": "/handshake-stats",
        "s8": {
          "assurance_basis": {
            "execution_recorded_for_route": true,
            "missing_receipt_bindings": [],
            "provider_proof_surface_configured": false,
            "receipt_binds_all_required_fields": true,
            "receipt_binds_provider_proof": false,
            "receipt_key_published_anonymously": true,
            "subject_evidence_anchor": false,
            "subject_evidence_anchor_note": "this subject has no independent ledger anchor; its decisions are issued under evidence profile 'observed_presence_v1' and record s8_anchor=false"
          },
          "assurance_profile": [
            "EXECUTION_BOUND_PROOF"
          ],
          "limitations": [
            "does not prove the factual correctness of the provider's output",
            "does not prove the provider itself signed or attested the result",
            "does not prove any independent or external source confirms the result",
            "the provider does not separately sign this result: the response digest is measured and signed by the NOMOS execution path, not by the provider",
            "no independent external source confirms this result; the subject anchor, where present, binds subject evidence and not this response"
          ],
          "status": "PROVEN"
        },
        "subject_id": "tooloracle.io"
      },
      {
        "access_scope": "tooloracle:read",
        "capability_id": "NOMOS_HANDSHAKE_READ",
        "external_network_dependency": false,
        "methods": [
          "POST"
        ],
        "offer_digest": "sha256:26e89c44e206db7840dc964e77fc6d546ed8bc4c26c4f39be6e4c3fa9502cdec",
        "persistent_side_effects": false,
        "price": {
          "amount": "0",
          "currency": "NONE",
          "settlement_required": false
        },
        "public_url": "https://tooloracle.io/nomos/handshake",
        "read_only": true,
        "route": "/nomos/handshake",
        "s8": {
          "assurance_basis": {
            "execution_recorded_for_route": true,
            "missing_receipt_bindings": [],
            "provider_proof_surface_configured": false,
            "receipt_binds_all_required_fields": true,
            "receipt_binds_provider_proof": false,
            "receipt_key_published_anonymously": true,
            "subject_evidence_anchor": false,
            "subject_evidence_anchor_note": "this subject has no independent ledger anchor; its decisions are issued under evidence profile 'observed_presence_v1' and record s8_anchor=false"
          },
          "assurance_profile": [
            "EXECUTION_BOUND_PROOF"
          ],
          "limitations": [
            "does not prove the factual correctness of the provider's output",
            "does not prove the provider itself signed or attested the result",
            "does not prove any independent or external source confirms the result",
            "the provider does not separately sign this result: the response digest is measured and signed by the NOMOS execution path, not by the provider",
            "no independent external source confirms this result; the subject anchor, where present, binds subject evidence and not this response"
          ],
          "status": "PROVEN"
        },
        "subject_id": "tooloracle.io"
      },
      {
        "access_scope": "tooloracle:read",
        "capability_id": "CROSSBORDER_REGULATORY_GAP_READ",
        "external_network_dependency": false,
        "methods": [
          "POST"
        ],
        "offer_digest": "sha256:9720f182f419ec255a03864e8da5242ea086350a957882f5e0a129810f912b1f",
        "persistent_side_effects": false,
        "price": {
          "amount": "0",
          "currency": "NONE",
          "settlement_required": false
        },
        "public_url": "https://tooloracle.io/nomos/regulatory-gap",
        "read_only": true,
        "route": "/nomos/regulatory-gap",
        "s8": {
          "assurance_basis": {
            "execution_recorded_for_route": true,
            "missing_receipt_bindings": [],
            "provider_proof_surface_configured": false,
            "receipt_binds_all_required_fields": true,
            "receipt_binds_provider_proof": false,
            "receipt_key_published_anonymously": true,
            "subject_evidence_anchor": false,
            "subject_evidence_anchor_note": "this subject has no independent ledger anchor; its decisions are issued under evidence profile 'observed_presence_v1' and record s8_anchor=false"
          },
          "assurance_profile": [
            "EXECUTION_BOUND_PROOF"
          ],
          "limitations": [
            "does not prove the factual correctness of the provider's output",
            "does not prove the provider itself signed or attested the result",
            "does not prove any independent or external source confirms the result",
            "the provider does not separately sign this result: the response digest is measured and signed by the NOMOS execution path, not by the provider",
            "no independent external source confirms this result; the subject anchor, where present, binds subject evidence and not this response"
          ],
          "status": "PROVEN"
        },
        "subject_id": "tooloracle.io"
      },
      {
        "access_scope": "rwa:read",
        "capability_id": "RWA_HISTORY_READ",
        "external_network_dependency": false,
        "methods": [
          "GET",
          "HEAD"
        ],
        "offer_digest": "sha256:2b2e598d5d59a0e84c3cd4176235c3a20356d03f8182a57b92cc1f57a3a3ffc3",
        "persistent_side_effects": false,
        "price": {
          "amount": "0",
          "currency": "NONE",
          "settlement_required": false
        },
        "public_url": "https://feedoracle.io/api/v1/rwa/history",
        "read_only": true,
        "route": "/v1/rwa/history",
        "s8": {
          "assurance_basis": {
            "execution_recorded_for_route": true,
            "missing_receipt_bindings": [],
            "provider_proof_surface_configured": false,
            "receipt_binds_all_required_fields": true,
            "receipt_binds_provider_proof": false,
            "receipt_key_published_anonymously": true,
            "subject_evidence_anchor": true,
            "subject_evidence_anchor_note": "this subject's admission evidence is anchor-backed; the anchor binds the subject's scan evidence, not the bytes of this call"
          },
          "assurance_profile": [
            "EXECUTION_BOUND_PROOF"
          ],
          "limitations": [
            "does not prove the factual correctness of the provider's output",
            "does not prove the provider itself signed or attested the result",
            "does not prove any independent or external source confirms the result",
            "the provider does not separately sign this result: the response digest is measured and signed by the NOMOS execution path, not by the provider",
            "no independent external source confirms this result; the subject anchor, where present, binds subject evidence and not this response"
          ],
          "status": "PROVEN"
        },
        "subject_id": "feedoracle.io"
      },
      {
        "access_scope": "rwa:read",
        "capability_id": "RWA_LEGAL_STATE_READ",
        "external_network_dependency": false,
        "methods": [
          "GET",
          "HEAD"
        ],
        "offer_digest": "sha256:3e4807f5c5a75f13251d87b4997fc4abdc23a5830627225308df1e5bcfc4cfa9",
        "persistent_side_effects": false,
        "price": {
          "amount": "0",
          "currency": "NONE",
          "settlement_required": false
        },
        "public_url": "https://feedoracle.io/api/v1/rwa/legal-state",
        "read_only": true,
        "route": "/v1/rwa/legal-state",
        "s8": {
          "assurance_basis": {
            "execution_recorded_for_route": true,
            "missing_receipt_bindings": [],
            "provider_proof_surface_configured": false,
            "receipt_binds_all_required_fields": true,
            "receipt_binds_provider_proof": false,
            "receipt_key_published_anonymously": true,
            "subject_evidence_anchor": true,
            "subject_evidence_anchor_note": "this subject's admission evidence is anchor-backed; the anchor binds the subject's scan evidence, not the bytes of this call"
          },
          "assurance_profile": [
            "EXECUTION_BOUND_PROOF"
          ],
          "limitations": [
            "does not prove the factual correctness of the provider's output",
            "does not prove the provider itself signed or attested the result",
            "does not prove any independent or external source confirms the result",
            "the provider does not separately sign this result: the response digest is measured and signed by the NOMOS execution path, not by the provider",
            "no independent external source confirms this result; the subject anchor, where present, binds subject evidence and not this response"
          ],
          "status": "PROVEN"
        },
        "subject_id": "feedoracle.io"
      },
      {
        "access_scope": "rwa:read",
        "capability_id": "RWA_LEGAL_STATE_STATS_READ",
        "external_network_dependency": false,
        "methods": [
          "GET",
          "HEAD"
        ],
        "offer_digest": "sha256:74e17a186cfb3fb947d73bc4384c3dc4fb8c85a94d33d0951eb2ba552f8498a6",
        "persistent_side_effects": false,
        "price": {
          "amount": "0",
          "currency": "NONE",
          "settlement_required": false
        },
        "public_url": "https://feedoracle.io/api/v1/rwa/legal-state/stats",
        "read_only": true,
        "route": "/v1/rwa/legal-state/stats",
        "s8": {
          "assurance_basis": {
            "execution_recorded_for_route": true,
            "missing_receipt_bindings": [],
            "provider_proof_surface_configured": false,
            "receipt_binds_all_required_fields": true,
            "receipt_binds_provider_proof": false,
            "receipt_key_published_anonymously": true,
            "subject_evidence_anchor": true,
            "subject_evidence_anchor_note": "this subject's admission evidence is anchor-backed; the anchor binds the subject's scan evidence, not the bytes of this call"
          },
          "assurance_profile": [
            "EXECUTION_BOUND_PROOF"
          ],
          "limitations": [
            "does not prove the factual correctness of the provider's output",
            "does not prove the provider itself signed or attested the result",
            "does not prove any independent or external source confirms the result",
            "the provider does not separately sign this result: the response digest is measured and signed by the NOMOS execution path, not by the provider",
            "no independent external source confirms this result; the subject anchor, where present, binds subject evidence and not this response"
          ],
          "status": "PROVEN"
        },
        "subject_id": "feedoracle.io"
      },
      {
        "access_scope": "rwa:read",
        "capability_id": "RWA_REGISTRY_READ",
        "external_network_dependency": false,
        "methods": [
          "GET",
          "HEAD"
        ],
        "offer_digest": "sha256:046b6a20b831928f82f0be1ad25863dbb948b7032122649f4b98c80b70fb7202",
        "persistent_side_effects": false,
        "price": {
          "amount": "0",
          "currency": "NONE",
          "settlement_required": false
        },
        "public_url": "https://feedoracle.io/api/v1/rwa/registry",
        "read_only": true,
        "route": "/v1/rwa/registry",
        "s8": {
          "assurance_basis": {
            "execution_recorded_for_route": true,
            "missing_receipt_bindings": [],
            "provider_proof_surface_configured": false,
            "receipt_binds_all_required_fields": true,
            "receipt_binds_provider_proof": false,
            "receipt_key_published_anonymously": true,
            "subject_evidence_anchor": true,
            "subject_evidence_anchor_note": "this subject's admission evidence is anchor-backed; the anchor binds the subject's scan evidence, not the bytes of this call"
          },
          "assurance_profile": [
            "EXECUTION_BOUND_PROOF"
          ],
          "limitations": [
            "does not prove the factual correctness of the provider's output",
            "does not prove the provider itself signed or attested the result",
            "does not prove any independent or external source confirms the result",
            "the provider does not separately sign this result: the response digest is measured and signed by the NOMOS execution path, not by the provider",
            "no independent external source confirms this result; the subject anchor, where present, binds subject evidence and not this response"
          ],
          "status": "PROVEN"
        },
        "subject_id": "feedoracle.io"
      },
      {
        "access_scope": "rwa:read",
        "capability_id": "RWA_REGISTRY_STATS_READ",
        "external_network_dependency": false,
        "methods": [
          "GET",
          "HEAD"
        ],
        "offer_digest": "sha256:8f9d15087622e89473509cd46c094e184edb48aa48641e2c5ecc4221549b1b62",
        "persistent_side_effects": false,
        "price": {
          "amount": "0",
          "currency": "NONE",
          "settlement_required": false
        },
        "public_url": "https://feedoracle.io/api/v1/rwa/registry/stats",
        "read_only": true,
        "route": "/v1/rwa/registry/stats",
        "s8": {
          "assurance_basis": {
            "execution_recorded_for_route": true,
            "missing_receipt_bindings": [],
            "provider_proof_surface_configured": false,
            "receipt_binds_all_required_fields": true,
            "receipt_binds_provider_proof": false,
            "receipt_key_published_anonymously": true,
            "subject_evidence_anchor": true,
            "subject_evidence_anchor_note": "this subject's admission evidence is anchor-backed; the anchor binds the subject's scan evidence, not the bytes of this call"
          },
          "assurance_profile": [
            "EXECUTION_BOUND_PROOF"
          ],
          "limitations": [
            "does not prove the factual correctness of the provider's output",
            "does not prove the provider itself signed or attested the result",
            "does not prove any independent or external source confirms the result",
            "the provider does not separately sign this result: the response digest is measured and signed by the NOMOS execution path, not by the provider",
            "no independent external source confirms this result; the subject anchor, where present, binds subject evidence and not this response"
          ],
          "status": "PROVEN"
        },
        "subject_id": "feedoracle.io"
      }
    ],
    "s8_assurance_by_subject": {
      "feedoracle.io": {
        "assurance": "MERKLE_PROOF_LEDGER_BOUND",
        "evidence_profile": "anchor_backed_default",
        "means": "this subject's admission evidence is backed by an independent ledger anchor; the anchor binds the subject's scan evidence and NOT the response bytes of any individual call",
        "subject_evidence_anchor": true
      },
      "tooloracle.io": {
        "assurance": "CRYPTOGRAPHIC_SIGNATURE",
        "evidence_profile": "observed_presence_v1",
        "means": "this subject has no independent ledger anchor and none is claimed; proof for a call is the signed execution receipt",
        "subject_evidence_anchor": false
      }
    },
    "subjects": [
      "feedoracle.io",
      "tooloracle.io"
    ]
  },
  "stage_count": 11,
  "stage_range": "S0-S10",
  "stages": [
    {
      "assurance": "RECOMPUTED_MEASUREMENT",
      "assurance_basis": "the age of the subject's newest ledger anchor is recomputed against the clock at decision time; the stored freshness class is never read back",
      "evidence_retrieval": "OPERATOR_ONLY",
      "evidence_types": [
        "anchor_run_reference",
        "ledger_transaction_hash",
        "recomputed_age_seconds",
        "freshness_class"
      ],
      "id": "S0",
      "name": "Frequency / Freshness",
      "publicly_verifiable": false,
      "runtime": "ENFORCING_INPUT",
      "runtime_note": "an anchor older than the configured window refuses the request at admission; it does not merely annotate it",
      "scope": "subject anchor freshness, per admission decision",
      "status": "OBSERVED"
    },
    {
      "assurance": "SIGNED_RESOLVER_RECORD",
      "assurance_basis": "the subject identifier resolves through a resolver to a signed scan receipt; an unsigned or missing scan is a refusal, not a default",
      "evidence_retrieval": "OPERATOR_ONLY",
      "evidence_types": [
        "scan_reference",
        "scan_receipt_hash",
        "signal_decision_reference"
      ],
      "id": "S1",
      "name": "Presence",
      "publicly_verifiable": false,
      "runtime": "ENFORCING_INPUT",
      "scope": "subject identifier resolution, per admission decision",
      "status": "RESOLVED"
    },
    {
      "assurance": "SHARED_SECRET_OVER_TLS",
      "assurance_basis": "the caller presents a credential the keystore recognises. This is NOT proof of possession of a private key: the consumer signs nothing, and no holder signature exists to re-verify later",
      "evidence_retrieval": "OPERATOR_ONLY",
      "evidence_types": [
        "consumer_reference",
        "key_reference",
        "authentication_method"
      ],
      "id": "S2",
      "limitation": "holder_key_signature is false at this stage. Treating it as cryptographic proof of identity would be an overstatement.",
      "name": "Identity",
      "publicly_verifiable": false,
      "runtime": "ENFORCING",
      "scope": "caller authentication on the cohort routes",
      "status": "AUTHENTICATED"
    },
    {
      "assurance": "STATIC_ANALYSIS_OF_INSTALLED_CODE",
      "assurance_basis": "the capability of a route is read out of the installed handler by AST -- which loaders it calls, which top-level keys its response carries, which effects it can have -- then matched against an explicit rule table. A route that matches no rule is CAPABILITY_UNKNOWN, never a guess from its name",
      "evidence_retrieval": "AUTHENTICATED_CONSUMER",
      "evidence_types": [
        "capability_id",
        "capability_map_digest",
        "handler_fingerprint"
      ],
      "id": "S3",
      "name": "Capability",
      "public_verification": "the capability_id is bound inside the Ed25519-signed execution receipt and verifies against the public execution JWKS",
      "publicly_verifiable": true,
      "runtime": "ENFORCING_INPUT",
      "scope": "cohort routes of the subject",
      "status": "DERIVED"
    },
    {
      "assurance": "DETERMINISTIC_EVALUATION",
      "assurance_basis": "a typed, digest-sealed intent document is compared with the offer in force by a deterministic evaluator. Free-text fields decide nothing: the evaluator's source contains no reference to them",
      "evidence_retrieval": "AUTHENTICATED_CONSUMER",
      "evidence_types": [
        "intent_id",
        "intent_digest",
        "match_id",
        "match_digest",
        "task_fit_result"
      ],
      "id": "S4",
      "name": "Intent / Task Fit",
      "public_verification": "the consumer builds the intent itself, reconstructs the match document locally and compares its digest with the one inside the signed receipt",
      "publicly_verifiable": true,
      "runtime": "ENFORCING",
      "scope": "cohort routes of the subject",
      "status": "MATCHED"
    },
    {
      "assurance": "IMMUTABLE_PUBLISHED_ARTIFACT",
      "assurance_basis": "content-addressed, insert-only offer documents, one per route. The lifecycle status is the fold of an append-only event chain, not a field in the document; RETIRED is final",
      "evidence_retrieval": "AUTHENTICATED_CONSUMER",
      "evidence_types": [
        "offer_id",
        "offer_digest",
        "offer_catalog_digest",
        "lifecycle_status"
      ],
      "id": "S5",
      "name": "Offer",
      "public_verification": "offer_id and offer_digest are bound inside the signed receipt and can be compared with the offer_digest published per route in this manifest",
      "publicly_verifiable": true,
      "runtime": "ENFORCING",
      "scope": "cohort routes of the subject",
      "status": "OFFERED"
    },
    {
      "assurance": "CRYPTOGRAPHIC_SIGNATURE",
      "assurance_basis": "an Ed25519-signed, short-lived admission decision issued by a process separate from the enforcing gate. Every binding is recomputed by the issuer from the primary artefacts; the gate's own claim is not taken as input",
      "evidence_retrieval": "AUTHENTICATED_CONSUMER",
      "evidence_types": [
        "decision_id",
        "decision_digest",
        "action_context_digest",
        "policy_version",
        "expiry"
      ],
      "id": "S6",
      "name": "Deal / Authorization",
      "public_verification": "decision_id and decision_digest are bound inside the signed receipt. The decision document itself is not published, so a third party verifies the BINDING, not the decision's own signature",
      "publicly_verifiable": true,
      "runtime": "ENFORCING",
      "runtime_note": "fail-closed. Refusals were measured at the kernel socket table, not inferred from the status code the gate returns",
      "scope": "cohort routes of the subject",
      "status": "AUTHORIZED"
    },
    {
      "assurance": "CRYPTOGRAPHIC_SIGNATURE",
      "assurance_basis": "an Ed25519-signed execution receipt in a hash-chained, append-only store, carrying the sha256 of the exact response bytes",
      "evidence_retrieval": "AUTHENTICATED_CONSUMER",
      "evidence_types": [
        "execution_id",
        "receipt_digest",
        "response_sha256",
        "signature_kid",
        "previous_receipt_digest"
      ],
      "id": "S7",
      "limitation": "EXECUTION_COMPLETED means the gate received the backend response in full. It says nothing about client satisfaction, compliance or settlement.",
      "name": "Execution / Delivery",
      "public_verification": "the receipt verifies against the public execution JWKS with no NOMOS credential; retrieving the receipt requires the consumer's",
      "publicly_verifiable": true,
      "runtime": "RECORDING",
      "scope": "cohort routes of the subject",
      "status": "EXECUTED"
    },
    {
      "assurance": "CRYPTOGRAPHIC_SIGNATURE",
      "assurance_basis": "every route in scope is covered by an Ed25519-signed execution receipt that binds the exact response bytes to the decision, intent and offer behind them. Where a subject additionally has an independent XRP Ledger anchor, that is stated per subject in s8_assurance_by_subject and never folded into a route's proof classes: the anchor binds that subject's scan evidence, not the bytes of any individual call",
      "evidence_retrieval": "AUTHENTICATED_CONSUMER",
      "evidence_types": [
        "execution_id",
        "receipt_digest",
        "response_sha256",
        "signature_kid",
        "previous_receipt_digest",
        "membership_proof_reference",
        "anchor_run_reference",
        "ledger_transaction_hash",
        "coverage_flags"
      ],
      "id": "S8",
      "limitation": "the subject anchor's membership proof is not published, so the ledger transaction alone does not let an outside party bind it to a specific execution. An outside party verifies the receipt, not the anchor.",
      "name": "Proof / Verifiability",
      "per_route_assurance": "scope.production_route_cohort[].s8",
      "public_verification": "the execution receipt for a call verifies against the public execution JWKS with no NOMOS credential. The SUBJECT anchor does not: see the limitation below.",
      "publicly_verifiable": true,
      "runtime": "ENFORCING_INPUT",
      "runtime_note": "two distinct roles. The SUBJECT's anchor proof is checked before a decision is issued and incomplete coverage refuses the request. The anchoring of an individual execution receipt happens after the response and cannot affect it.",
      "scope": "two things that must not be read as one. For the CALL, S8 is the signed execution receipt, and that holds for every route in scope. For the SUBJECT, some subjects additionally have an independent ledger anchor behind their admission evidence and some do not; which is which is derived per subject in s8_assurance_by_subject rather than left to be inferred. Neither is a blanket property of every NOMOS product, and neither is a claim that every execution is individually anchored",
      "status": "PROVEN"
    },
    {
      "assurance": "APPEND_ONLY_COUNTING",
      "assurance_basis": "exactly one append-only outcome observation per signed receipt, counted into immutable reliability snapshots over fixed windows. Counting, not judging: no score is derived",
      "evidence_retrieval": "OPERATOR_ONLY",
      "evidence_types": [
        "observation_id",
        "observation_digest",
        "profile_snapshot_digest",
        "sample_status",
        "window_type"
      ],
      "id": "S9",
      "limitation": "this is NOT a public reputation score. There is no number, no ranking, no cross-party comparison, and nothing here is published per consumer.",
      "name": "Reliability / Outcomes",
      "publicly_verifiable": false,
      "runtime": "POST_HOC_OBSERVATION",
      "runtime_note": "runs after the response. No result of this stage reaches admission or execution.",
      "scope": "observations and reliability snapshots for the subject and the cohort",
      "status": "OBSERVED_AND_PROFILED"
    },
    {
      "assurance": "GOVERNED_IMMUTABLE_POLICY",
      "assurance_basis": "immutable policy artefacts under an append-only lifecycle (DRAFT -> VALIDATED -> APPROVED -> ACTIVE_SHADOW -> RETIRED), exactly one active shadow policy at a time, RETIRED final",
      "evidence_retrieval": "OPERATOR_ONLY",
      "evidence_types": [
        "policy_version",
        "policy_digest",
        "rules_digest",
        "shadow_recommendation"
      ],
      "id": "S10",
      "limitation": "shadow recommendations do not block, throttle or alter any production request.",
      "name": "Governance / Immune Control",
      "publicly_verifiable": false,
      "runtime": "OBSERVING_ONLY",
      "runtime_note": "there is NO return path from this stage into admission, execution or enforcement. A shadow recommendation has never changed, and cannot change, a production decision.",
      "scope": "shadow evaluation of the cohort's observations",
      "status": "GOVERNED_SHADOW"
    }
  ],
  "status_vocabulary": {
    "AUTHENTICATED": "a credential was checked, by shared secret, not by a key the holder signs with",
    "AUTHORIZED": "a signed decision existed and every binding checked out",
    "DERIVED": "read out of the installed implementation by static analysis",
    "EXECUTED": "the backend was contacted exactly once and the response recorded",
    "GOVERNED_SHADOW": "evaluated under a governed policy that cannot affect production",
    "MATCHED": "two typed documents were compared under a deterministic evaluator",
    "OBSERVED": "a fact was read and recomputed against the clock now",
    "OBSERVED_AND_PROFILED": "counted into immutable reliability snapshots, no judgement",
    "OFFERED": "an immutable published artefact was in force at the time",
    "PROVEN": "a Merkle proof was verified against a real ledger transaction",
    "RESOLVED": "an identifier was resolved through a resolver, not assumed"
  },
  "verification": {
    "anonymous_public_artifacts": [
      "https://agentnomos.com/.well-known/nomos-capabilities.json",
      "https://feedoracle.io/.well-known/nomos-execution-jwks.json",
      "https://feedoracle.io/.well-known/openapi.json",
      "https://agentnomos.com/.well-known/agent-card.json"
    ],
    "contract": {
      "agent_card": {
        "canonical_copy": "https://agentnomos.network/.well-known/agent-card.json",
        "expect": "200",
        "media_type": "application/json",
        "role": "A2A agent card for the publisher. Carries a NOMOS-namespaced pointer back to this manifest.",
        "url": "https://agentnomos.com/.well-known/agent-card.json"
      },
      "openapi": {
        "carries_trust_chain_extension": true,
        "expect": "200",
        "media_type": "application/json",
        "role": "Canonical machine-readable API contract for the subject, including the governed route cohort and the execution receipt response headers.",
        "url": "https://feedoracle.io/.well-known/openapi.json"
      },
      "subject_agent_card": {
        "expect": "200",
        "media_type": "application/json",
        "role": "Agent card for the subject whose routes are in scope.",
        "url": "https://feedoracle.io/.well-known/agent-card.json"
      }
    },
    "execution_receipts": {
      "jwks": {
        "algorithm": "EdDSA",
        "expect": "200",
        "key_type": "OKP / Ed25519",
        "media_type": "application/json",
        "role": "Public Ed25519 keys that execution receipts are signed with. Fetchable anonymously; no credential needed to verify a receipt you already hold.",
        "url": "https://feedoracle.io/.well-known/nomos-execution-jwks.json"
      },
      "receipt_read": {
        "authentication": "required",
        "expect": "401 without a credential",
        "probe_url": "https://feedoracle.io/api/v1/nomos/execution-receipts/probe-unauthenticated",
        "role": "Authenticated retrieval of the signed execution receipt for one call.",
        "url_template": "https://feedoracle.io/api/v1/nomos/execution-receipts/{execution_id}",
        "usage": "Read the exact URL from the x-nomos-receipt-url response header of the call you want to verify. Do not construct it."
      },
      "response_headers": [
        "x-request-id",
        "x-content-hash",
        "x-nomos-execution-id",
        "x-nomos-receipt-digest",
        "x-nomos-receipt-kid",
        "x-nomos-receipt-url"
      ],
      "self_verification_procedure": [
        "Call a cohort route with your credential and a typed intent.",
        "Compute sha256 over the exact response bytes you received.",
        "Read x-nomos-receipt-url from the response headers and fetch the receipt with your credential.",
        "Verify the receipt's Ed25519 signature against the anonymous public JWKS above.",
        "Check that the receipt's response hash equals the hash you computed.",
        "Reconstruct your intent digest and the match document locally and compare them with the values bound inside the signed receipt.",
        "Compare the receipt's offer_digest and capability_id with the values published per route in this manifest."
      ]
    },
    "not_this_chain": {
      "disambiguation": "This key set does not contain the execution receipt key id. Verifying an execution receipt against it will fail, and it should not be used for that purpose.",
      "expect": "200",
      "must_not_contain_execution_kid": true,
      "role": "A separate, pre-existing key set of the subject, used for evidence packs. It is NOT the execution receipt key surface.",
      "url": "https://feedoracle.io/.well-known/jwks.json"
    },
    "note": "Every URL below was retrieved over HTTPS and behaved as described before it was published here. A URL that only looks plausible is not a verification surface."
  }
}
