Cross-Ecosystem Trust Graph

Different ecosystems. Same governance boundary. Verifiable execution.

NOT ONE SERIAL STACK. These proofs are NOT one serial transaction through NANDA, SLIM, x402 and AgentBeats. Each proof isolates ONE surrounding ecosystem role against the same AgentNOMOS governance model, in a separate run.

The surrounding ecosystem role changed (external operator context, evaluation, transport, economics). The NOMOS governance boundary — authority semantics, decision source, execution signer, receipt verification model — did not. A role in an ecosystem does not automatically become authority over actions.

Why this exists

Each experiment varies exactly one surrounding ecosystem role — external operator context, evaluation, transport, economics — and measures whether the AgentNOMOS governance boundary (decision source, authority semantics, execution signer, receipt verification) changed. It did not. Role never became authority.

Proof matrix

Proof levels are different dimensions, not ranks. Values are exact evidence states — no undifferentiated checkmarks.

EcosystemRoleProof levelAuthority effectSame NOMOS coreGoverned executionReceiptExternal operator
Independent external operatorEXTERNAL_OPERATOR_CONTEXTEXTERNAL_CROSS_OPERATORNONEVERIFIED_SAME_RUNTIME_PATHTRUESIGNED_VERIFIEDTRUE
AgentBeatsINDEPENDENT_EVALUATIONLOCAL_GOVERNED_REALPATHNONEVERIFIED_BYTE_IDENTICALTRUESIGNED_VERIFIEDFALSE
AGNTCY / SLIMTRANSPORTLOCAL_REAL_TRANSPORTNONEVERIFIED_BYTE_IDENTICALTRUESIGNED_VERIFIEDFALSE
x402ECONOMICSECONOMIC_FULL_CHAINNONE_CLAIMED_NOT_TESTEDNOT_PROVENNOT_APPLICABLE_DIFFERENT_LANESIGNED_VERIFIEDTRUE
AgentNOMOSACTION_GOVERNANCEREFERENCE_ONLYSOLE_ACTION_AUTHORITY (admission decision + execution + signed receipt)VERIFIED_BYTE_IDENTICALTRUESIGNED_VERIFIEDNOT_APPLICABLE

Independent external operator (arranged cross-operator test)

Role in this experiment: EXTERNAL_OPERATOR_CONTEXT — Role assigned within the NOMOS experiment, not by NANDA or CodeMinder.

Proof level: EXTERNAL_CROSS_OPERATOR · Verdict: PASS_ARRANGED_CROSS_OPERATOR_GOVERNED_INTEROP · Run: 2026-08-16T15:48:37Z

What changed: A2A JSON-RPC over public HTTPS (POST /a2a/jsonrpc)

What stayed constant: governance core match = VERIFIED_SAME_RUNTIME_PATH; decision ALLOW_READ_ONLY; receipt kid exr1_40c4bc9a9f61988b.

Evidence: sealed checkpoint cp_nomos_codeminder_cross_operator_pass_2c2_20260816T160416Z (operator-local sealed evidence unless marked public).

Limitations (read these — they are part of the claim)

AgentBeats (protocol-faithful Green stand-in + shipped Purple adapter)

Role in this experiment: INDEPENDENT_EVALUATION — Role assigned within the NOMOS experiment, not by AgentBeats.

Proof level: LOCAL_GOVERNED_REALPATH · Verdict: PASS_LOCAL_AGENTBEATS_CREDENTIALED_GOVERNED_REALPATH · Run: 2026-08-16T16:17:52Z

What changed: Real A2A Green→Purple, then public HTTPS A2A JSON-RPC to https://tooloracle.io/a2a/jsonrpc

What stayed constant: governance core match = VERIFIED_BYTE_IDENTICAL; decision ALLOW (ALLOW_READ_ONLY path; lane record decision=ALLOW); receipt kid exr1_40c4bc9a9f61988b.

Evidence: sealed checkpoint cp_nomos_agentbeats_ab26_realpath_20260816T161702Z (operator-local sealed evidence unless marked public).

Limitations (read these — they are part of the claim)

AGNTCY / SLIM (real SLIM node ghcr.io/agntcy/slim:2.3.0)

Role in this experiment: TRANSPORT — Role assigned within the NOMOS experiment, not by AGNTCY, Cisco or the Linux Foundation.

Proof level: LOCAL_REAL_TRANSPORT · Verdict: PASS_LOCAL_AGNTCY_SLIM_REAL_TRANSPORT_GOVERNED_EXECUTION · Run: 2026-08-16T16:48:32Z

What changed: SlimRPC (lf.a2a.v1.A2AService over slim_bindings.Channel) across a real SLIM node, bridged to public HTTPS A2A JSON-RPC

What stayed constant: governance core match = VERIFIED_BYTE_IDENTICAL; decision ALLOW_READ_ONLY; receipt kid exr1_40c4bc9a9f61988b.

Evidence: sealed checkpoint cp_nomos_agntcy_slim_realpath_20260816T163302Z (operator-local sealed evidence unless marked public).

Limitations (read these — they are part of the claim)

x402 (HTTP 402 payment protocol; Base USDC 'exact' rail, EIP-3009)

Role in this experiment: ECONOMICS — Role assigned within the NOMOS experiment, not by the x402 ecosystem or the provider.

Proof level: ECONOMIC_FULL_CHAIN · Verdict: PASS_R12_2_REAL_EXTERNAL_X402_PURCHASE_EXECUTED_DELIVERED_RECONCILED · Run: 2026-08-14 (sealed 2026-08-14T16:25Z; publication state sealed R13.5 2026-08-14T18:25Z)

What changed: x402 over HTTPS; settlement on Base (USDC, EIP-3009 transferWithAuthorization via relayer)

What stayed constant: governance core match = NOT_PROVEN; decision OPERATOR_AUTHORIZED_SINGLE_SHOT (outbound buyer ceremony with fail-closed pre-signature gates; two aborts before signing moved zero value); receipt kid x402r1_b8d21e5c8d689e6d.

Evidence: sealed checkpoint cp_agentnomos_r12_2_first_real_x402_purchase_20260814T162500Z (operator-local sealed evidence unless marked public).

Limitations (read these — they are part of the claim)

Standards conformance evidence

The conformance node below sits OUTSIDE the shared-governance star. The four ecosystem proofs vary one surrounding role around a constant AgentNOMOS governance boundary; this node measures something different — an isolated lab verifier against an external standard, with no admission decision, no governed execution, no signed receipt and no shared governance core. It is published in the same graph because it is independently obtained evidence about this operator's software, not because it shares the star's topology.
SubjectRole testedVerifying partyLevelConformanceCertificationModulesSame NOMOS coreRuntime state
OpenID4VP 1.0 Final / HAIP 1.0 FinalVERIFIEROpenID Foundation conformance suiteEXTERNAL_STANDARDS_CONFORMANCEPASSEDPENDING_NOT_GRANTED11/11 applicable (7 PASSED, 4 REVIEW) of 12 in planNOT_PROVENSAFE_IDLE

OpenID4VP 1.0 Final · HAIP 1.0 Final — VERIFIER

NOT A CERTIFICATION. conformance_status PASSED · certification_status PENDING_NOT_GRANTED. The certification package was created and published for certification. Formal OpenID Foundation certification has NOT been granted. Until it is, no certification wording may be used.

The OpenID Foundation conformance suite was run against this verifier; all eleven applicable modules of the OID4VP 1.0 Final + HAIP verifier plan reached a successful final outcome, and one defect was found and repaired in the process. This is not a certification.

Verifying party: OpenID Foundation conformance suite · plan dDw7z2oO2q0vB · suite 5.2.3 · run 2026-08-18T17:57:33Z

Profile tested: SD-JWT VC (sd_jwt_vc), response mode direct_post.jwt, client id scheme x509_hash, request delivery request_uri_signed.

11 of 11 applicable modules reached a SUCCESSFUL FINAL OUTCOME. That is not the same as '11 PASSED': seven finished PASSED automatically because the verifier rejected the presentation with HTTP 4xx, and four finished REVIEW with an uploaded screenshot that was accepted. Both are successful outcomes in this suite; they are reported separately here rather than merged into one number.

#ModuleOutcomeNote
1happy-flowREVIEW
2minimal-cnf-jwkREVIEW
3request-uri-method-postREVIEWafter a scoped, per-transaction POST repair
4request-uri-fetched-twiceREVIEW
5invalid-session-transcriptNOT_APPLICABLE
6invalid-kb-jwt-signaturePASSED
7invalid-credential-signaturePASSED
8invalid-sd-hashPASSED
9invalid-kb-jwt-noncePASSED
10invalid-kb-jwt-audPASSED
11kb-jwt-iat-in-pastPASSEDpost-repair; the PRE-REPAIR run accepted it
12kb-jwt-iat-in-futurePASSEDpost-repair; the PRE-REPAIR run accepted it

The defect the external gate found

The external suite found a real defect that this operator's own testing did not. The pre-repair state is published here on purpose and has not been rewritten or hidden. KB-JWT iat freshness validation gap: adapter/sdjwtvc.py checked only that the Key Binding JWT carried an iat claim, with no freshness window in either direction. Missed by 101 local unit tests on the same file, and eleven earlier suite modules. The gap was written down — file and line — before this strand's first external run, and left unrepaired on purpose so the external result would be falsifiable rather than pre-arranged.

StageCaseVerifierStatusSuite outcome
PRE-REPAIRKB-JWT iat one year in the pastACCEPTEDHTTP 200IMAGE_REQUIRED
PRE-REPAIRKB-JWT iat one year in the futureACCEPTEDHTTP 200IMAGE_REQUIRED
POST-REPAIRKB-JWT iat one year in the pastREJECTEDHTTP 400PASSED
POST-REPAIRKB-JWT iat one year in the futureREJECTEDHTTP 400PASSED

Both pre-repair instances remain in IMAGE_REQUIRED and are NOT superseded in place. They ask for a screenshot of a rejection that never happened, so none was ever produced or fabricated. They are the record of the finding. Wallets with badly-set clocks are now rejected where they previously passed. That is intended.

The exact build this claim is bound to

Filesha256
adapter/sdjwtvc.py067fd1094327440949dcbfed8477c5992d688d18c04f79e6b7e3a2a9b26ff79b
adapter/request_builder.pyc69a5de459f399d922a558b785773bee4af7611f6eb49495657fd1f1440d2f65
gateway/server.py6b27ec2ea7fca343b10c3f6e13242c2f34fc5558324fd5f6b04250d66fa4c8a2

Freshness policy: max age 300 s, future skew 60 s. Deployment policy chosen by this operator. No external authority validates these two numbers; the suite confirms only that SOME window exists and catches gross deviations.

Evidence

Sealed checkpoint cp_agentnomos_openid4vp_haip_external_conformance_evidence_FINAL_r1_20260818T175733Z (10 sealed entries), supplemented by cp_agentnomos_openid4vp_final_evidence_url_reference_r1_20260818T180128Z (9 entries). Chain: 20 checkpoints, 238 sealed entries. All 20 checkpoint manifests re-verified at publication time; 0 mismatches.

Packagesha256How this digest was checked
OIDF certification packaged69b63164dceb446b1cb89a1506f88e79d1c63fb24cc58a9725db54765f47f36OPERATOR_ATTESTED
OIDF client-data evidence package04852dca15a40dee182da12c67aad62373d31ea1c9b8b9b6a5c214d5424aa555LOCALLY_VERIFIED

OPERATOR_LOCAL_SEALED_EVIDENCE. The suite's own result pages were served from process memory and went offline when the lane was disarmed; they are NOT durable evidence and are deliberately not cited as retrievable URLs. The durable form is the sealed checkpoint chain above, which includes sealed HTML copies of those pages.

Runtime state of the tested lane

SAFE_IDLE — service inactive and disabled, public routes absent (all lab paths return 404). The tested lane is deliberately disarmed. Nothing in this node claims a reachable or running OpenID4VP verifier.

What this proves

What this does NOT prove

Limitations (read these — they are part of the claim)
Forbidden claims
References to the OpenID Foundation, the OpenID Foundation conformance suite, OpenID4VP or HAIP identify a specification and a test tool used in this experiment. They do not imply endorsement, certification, validation or partnership by the OpenID Foundation. Formal OpenID Foundation certification has NOT been granted for this implementation.

Shared invariants

Verify the evidence

Execution receipts verify offline against the public JWKS at https://feedoracle.io/.well-known/nomos-execution-jwks.json (Ed25519, domain-separated signing input). The x402 purchase evidence family is published at https://agentnomos.com/.well-known/nomos-x402-purchase.json. Interop run evidence lives in sealed operator-local checkpoints referenced above.

Claim boundaries

Machine-readable allowed/forbidden claims per ecosystem: claim-boundaries.json. The forbidden lists are part of this page's claim, not a footnote.

Bring your own agent

No live onboarding exists in this phase. If you operate an agent in any of these ecosystems and want to reproduce a governed, receipted read-only run against this boundary, contact the operator via the published agent card. Nothing about these experiments requires your ecosystem to grant or receive authority.

References to NANDA, CodeMinder, AgentBeats, AGNTCY, SLIM, Cisco, the Linux Foundation, x402, Base or any provider identify technologies, networks or contexts used in these experiments. They do not imply endorsement, certification, validation or partnership by any of these parties.

Status: PUBLISHED · generated 2026-08-18T19:33:23Z · machine graph: graph.json