No-spend fixtureLive-gatedProduction live disabled

Buyer paid workflow — no-spend shell

The buyer journey from quote to budget ledger to execution timeline to result, receipt, and evidence, rendered entirely from deterministic no-network fixtures under the #497 route state contract. Nothing on this page signs, spends, settles, publishes, or mutates trust.

Open public proof page

What each state label means

Copy modes follow the #497 copy boundary matrix and the Discover / Decide / Prove boundaries doc; the fail-closed reading wins.

No-spend fixture

fixture_zero_spend

Deterministic fixture data. No network, no spend, nothing paid, settled, executed live, custody-backed, published, or trusted.

Dry run (planned only)

planned_dry_run

Planned quote, policy, ledger, and proof refs. No wallet signed, no provider called, no RPC verified, no funds moved.

Simulated preview

simulated

Simulated result or preview state only. Not a production result and not a verified live service response.

Recorded devnet metadata

devnet_proof_metadata

Recorded devnet proof metadata; an optional fresh-devnet gate exists. No mainnet settlement, production activation, or default USDC auto-pay.

Live-gated (approval required)

live_gated

A fresh paid run needs an explicit operator approval record, cap, endpoint, payer, payee, command, evidence path, rollback owner, and expiry. No approval is granted here and no route can spend.

Production disabled

production_live_disabled

Production live payment is disabled by default. No Pay.sh production activation, no production AUDD rail, no hosted registry write.

  1. Quote
  2. Budget
  3. Execution
  4. Result
  5. Receipt
  6. Evidence

Quote

2.00 downstream + 0.50 attestor + 0.75 markup + 5 bps rail fee.

3.331250 USDC

quote_ready

Downstream fees
2.00 USDC
Attestor fees
0.50 USDC
Orchestrator markup
0.75 USDC
Protocol rail fee
5 bps (0.001250 USDC)
Swap allowance
0.08 USDC
Quoted total
3.331250 USDC
  • pay_sh_sandbox_single_charge_binding

Budget summary

4 downstream profiles; downstream calls executed: 0.

Planned dry-run ledger

budget_ledger_ready

4 downstream specialist profiles planned; downstream calls executed: 0. Row-level allocation, remaining, and refund states are in the budget ledger below.

  • planning-agent
  • content-creation-agent
  • code-generation-agent
  • verification-validation-agent

Budget ledger

Every row is traced to a fixture/read-model ref or explicitly marked unavailable/blocked. Planned allocations reconcile exactly to the buyer budget; spent stays an authoritative zero.

allocations reconciled

budget_ledger_ready

Buyer budget
3.33125 USDC
Allocated (planned)
3.33125 USDC
Spent
0 USDC
Remaining (unspent)
3.33125 USDC
  • Upfront activity fee

    end-user -> agentic-workflow-system

    3.33125 USDCplanned unspent

    Buyer budget equals the deterministic quote total. Planned fixture funding only; nothing is signed, paid, or settled.

    • fixture:economic-d...r.user-funding
    • quote_total_usdc:3.33125
  • Reserved copy specialist budget

    agentic-workflow-system -> content-creation-agent

    1 USDCplanned unspent

    Reserved specialist budget from the fixture ledger; zero downstream calls executed.

    • fixture:economic-d....downstream[0]
    • profile:content-creation-agent
    • endpoint:https://r...at/completions
  • Reserved code specialist budget

    agentic-workflow-system -> code-generation-agent

    1 USDCplanned unspent

    Reserved specialist budget from the fixture ledger; zero downstream calls executed.

    • fixture:economic-d....downstream[1]
    • profile:code-generation-agent
    • endpoint:https://r...at/completions
  • Reserved attestation budget

    agentic-workflow-system -> verification-validation-agent

    0.5 USDCplanned unspent

    Reserved attestor/proof budget; the attestation itself stays a draft preview with no submission.

    • fixture:economic-d...attestation[0]
    • attestor_fees_usdc:0.5
  • Orchestrator retained markup

    agentic-workflow-system -> agentic-workflow-system

    0.75 USDCplanned unspent

    Orchestrator fee/margin retained in the plan; collected nowhere because nothing executes.

    • fixture:economic-d...dger.markup[0]
    • orchestrator_markup_usdc:0.75
  • Reddi Agent Protocol rail fee (0.05%)

    agentic-workflow-system -> reddi-protocol-treasury

    0.00125 USDCplanned unspent

    Planned 5 bps protocol rail fee; zero fees collected (real metering).

    • fixture:economic-d...rotocol-fee[0]
    • rail_fee_bps:5
    • rehearsal:metering...ollectedUsdc:0
  • SOL route swap/slippage allowance

    Jupiter -> agentic-workflow-system

    0.08 USDCplanned unspent

    SOL-route swap/slippage allowance inside the quote; no swap route is executed.

    • fixture:economic-d...ledger.swap[0]
    • jupiter_swap_allowance_usdc:0.08
  • Spent to date

    0 USDCunspent zero

    Authoritative zero from the recorded rehearsal's real metering: no paid requests, no settled USDC.

    • rehearsal:metering.real.usdcSettled:0
    • rehearsal:metering.real.paidRequests:0
    • rehearsal:metering...allsExecuted:0
  • Remaining (unspent)

    3.33125 USDCremaining full budget

    The full buyer budget remains: nothing was spent, so remaining equals the quoted total.

    • quote_total_usdc:3.33125
    • rehearsal:metering.real.usdcSettled:0
  • Refund state

    0 USDCrefund policy fixture only

    No refund exists because no charge exists. Failure policy: no_charge_on_failure; refund policy: manual_review_fixture_only.

    • preflight:allowed_fixture_only
    • failure_policy:no_charge_on_failure
    • refund_policy:manual_review_fixture_only
  • Real settlement cost

    unavailableunavailable not implemented

    Unavailable: no real settlement occurred and the production-style devnet receipt verifier is a later phase, so no settlement cost can be reported honestly.

    • ledger-reconciliat...ot_implemented
  • Blocked cases spend

    0 USDCblocked fail closed

    6 fail-closed proof-chain cases hold spending and mutation at zero/false.

    • blocked_case:mpp_tempo_unsupported_network
    • blocked_case:unsupported_asset_network
    • blocked_case:malformed_receipt

Execution timeline

Milestones come from the nissan/reddi-agent-protocol#564 recorded dry-run rehearsal and the fixture pack; nothing here executed live. Recorded-devnet metadata labels reference docs/DEVNET-REFERENCE-RUN-564.md.

no live execution

execution_timeline_ready

  1. Request

    rehearsed dry runplanned_dry_run

    Resolve orchestrator and downstream specialists from the deployed 30-profile catalog without network calls.

    • scenario:webpage
    • profile:agentic-workflow-system
    • profile:planning-agent

    devnet_proof_metadata: runbook:docs/DEVNET-REFERENCE-RUN-564.md

  2. Quote

    rehearsed dry runplanned_dry_run

    Assemble the deterministic USDC quote including downstream fees, attestor fees, markup, and protocol rail fee.

    • scenario:webpage
    • quote_total_usdc:3.33125

    devnet_proof_metadata: runbook:docs/DEVNET-REFERENCE-RUN-564.md

  3. Policy decision

    rehearsed dry runplanned_dry_run

    Evaluate the fixture-only policy decision and AUDD payment-plan preflight; both stay allowed_fixture_only.

    • policy:allowed_fixture_only
    • preflight:allowed_fixture_only

    devnet_proof_metadata: runbook:docs/DEVNET-REFERENCE-RUN-564.md

  4. Execution

    planned no live executionplanned_dry_run

    Bind the dry-run x402 payment plan to the sandbox single-charge payment proof ref; no payment is generated or submitted. Real execution stays at zero: 0 downstream calls executed.

    • payment_proof_ref:...:single-charge
    • rail:pay-sh-sandbox
    • rehearsal:metering...allsExecuted:0

    devnet_proof_metadata: runbook:docs/DEVNET-REFERENCE-RUN-564.md

  5. Result

    fixture result onlyfixture_zero_spend

    Receipts are controlled demo receipts, not production USDC settlement verification.

    • artifacts/economic...Z/summary.json

    devnet_proof_metadata: runbook:docs/DEVNET-REFERENCE-RUN-564.md

  6. Receipt

    binding refs onlyfixture_zero_spend

    Reference the redacted rail-neutral receipt (refs, hashes, and support states only).

    • receipt:job:pay-sh-sandbox:single_charge
    • job:pay-sh-sandbox:single_charge
    • pay-sh-sandbox-rec...:single-charge

    devnet_proof_metadata: runbook:docs/DEVNET-REFERENCE-RUN-564.md

  7. Evidence

    binding refs onlyfixture_zero_spend

    Reference the EvidenceArchive record binding source, request hash, response hash, and evidence ref.

    • evidence:evidence:...:single_charge
    • schema:reddi.econo...f-page-data.v1
    • evidence:pay-sh-sandbox:single_charge

    devnet_proof_metadata: runbook:docs/DEVNET-REFERENCE-RUN-564.md

  8. Attestation preview

    preview onlysimulated

    verification-validation-agent has not submitted an attestation.

    • file://artifacts/p...Z/SUMMARY.json
  9. Reputation preview

    preview onlysimulated

    agentic-workflow-system reputation mutation is disabled for this fixture pack.

    No public ref: preview-only milestone.

Result summary

Receipts are controlled demo receipts, not production USDC settlement verification.

Ready fixture result

result_ready

  • artifacts/economic...Z/summary.json

Receipt / proof summary

receipt_binding_candidate; USDC on solana-devnet.

Receipt binding ready

receipt_binding_ready

Payment proof is rendered as refs and hashes only (refs_hashes_only); no settlement finality or custody is implied.

  • job:pay-sh-sandbox:single_charge
  • pay-sh-sandbox-rec...:single-charge
  • pay-sh:nonce:fixture-20260507
  • pay-sh:recipient:operator-approved-demo

Evidence

EvidenceArchive refs are available without raw prompt, output, credential, provider, wallet, or RPC material.

Evidence refs ready

evidence_refs_ready

  • evidence:pay-sh-sandbox:single_charge
  • file://artifacts/p...Z/SUMMARY.json
  • sha256:4f66ea20ad7...f3c8ffd8b9332a
  • sha256:b2472d5bfa4...dca0dd27179418

Attestation preview

verification-validation-agent has not submitted an attestation.

Draft only

attestation_preview_only

  • file://artifacts/p...Z/SUMMARY.json

Reputation preview

agentic-workflow-system reputation mutation is disabled for this fixture pack.

No mutation

reputation_preview_only

No public ref for this preview state.

Evidence boundary states

Every state below fails closed. Blocked proof-chain cases come from the rail-neutral fixture pack; none of them can mint a reddi.receipt.v1 binding.

Empty contract (rendered by feeding the builder an empty case list)

Empty fixture contract fails closed

empty_fixture_pack

The paid-workflow fixture pack contains no proof-chain cases; the buyer route renders no quote, ledger, result, receipt, or evidence.

Fail-closed states claim nothing: no custody, no settlement finality, no mainnet settlement, no hosted publication, no trust or reputation mutation, no wallet signing, no RPC or provider calls, no paid requests or Pay.sh activation.

Unsupported rail/networkmpp-tempofail closed

mpp tempo unsupported network

  • unsupported_asset_network-tempo:USDC is not supported by Reddi receipt v1 binding

No Reddi receipt v1 settlement proof, custody, trust upgrade, reputation mutation, marketplace publication, provider execution, wallet signing, RPC, spend, sandbox execution, or live payment is claimed.

spent 0 USDC | refunds 0 | spending and mutation stay false

Unsupported asset/networkpay-sh-sandboxfail closed

unsupported asset network

  • unsupported_asset_network-base-mainnet:USDC is not supported by Reddi receipt v1 binding

No Reddi receipt v1 settlement proof, custody, trust upgrade, reputation mutation, marketplace publication, provider execution, wallet signing, RPC, spend, sandbox execution, or live payment is claimed.

spent 0 USDC | refunds 0 | spending and mutation stay false

Malformed receiptpay-sh-sandboxfail closed

malformed receipt

  • malformed_receipt-Pay.sh sandbox single-charge evidence requires a successful Solana receipt ref

No Reddi receipt v1 settlement proof, custody, trust upgrade, reputation mutation, marketplace publication, provider execution, wallet signing, RPC, spend, sandbox execution, or live payment is claimed.

spent 0 USDC | refunds 0 | spending and mutation stay false

Policy deniedpay-sh-sandboxfail closed

policy denied

  • policy_denied-policy denial blocks receipt/evidence binding normalization

No Reddi receipt v1 settlement proof, custody, trust upgrade, reputation mutation, marketplace publication, provider execution, wallet signing, RPC, spend, sandbox execution, or live payment is claimed.

spent 0 USDC | refunds 0 | spending and mutation stay false

Probe-only receipt capairwallex-hosted-checkoutfail closed

airwallex webhook probe only cap

  • unsupported_fixture_state-rail-neutral receipt supportState 'probe_only' is capped below receipt_binding_candidate; probe_only receipts never bridge into reddi.receipt.v1 (revocable rails have no receipt-v1 revoked/contested state — #338 gap)

No Reddi receipt v1 settlement proof, custody, trust upgrade, reputation mutation, marketplace publication, provider execution, wallet signing, RPC, spend, sandbox execution, or live payment is claimed.

spent 0 USDC | refunds 0 | spending and mutation stay false

Live-path overclaimpay-sh-sandboxfail closed

live path overclaim

  • live_path_rejected-Rail-neutral proof-chain fixture rejected imported live-path overclaim text.
  • live_path_rejected-Rail-neutral proof-chain fixture rejected imported live-path overclaim text.
  • live_path_rejected-Rail-neutral proof-chain fixture rejected imported live-path overclaim text.

No Reddi receipt v1 settlement proof, custody, trust upgrade, reputation mutation, marketplace publication, provider execution, wallet signing, RPC, spend, sandbox execution, or live payment is claimed.

spent 0 USDC | refunds 0 | spending and mutation stay false

Second rail: support states

draftreddi.airwallex-hosted-checkout-rail.v1

Real second-rail data: webhook-derived card-rail receipts cap at probe-only, and any live settlement claim on this rail fails closed.

airwallex webhook receipt probe only

Airwallex hosted checkout (Payment Links / hosted payment page)

Synthetic (static, PII-free) Airwallex webhook fixtures may normalize into rail-neutral receipt candidates capped at probe_only: card-rail receipts are REVOCABLE (a succeeded intent can later be refunded or disputed — receipt v1 has no representation for a later-revoked/contested receipt, a tracked #338 receipt-semantics gap), the receipt v1 network table is Solana-only, and HMAC is verifiable only with a merchant secret RAP must never hold. Normalization itself is a separate follow-up issue.

  • Airwallex is a regulated settlement/acceptance rail owned by the seller, not by RAP.
  • RAP claims no custody, money transmission, MoR status, or settlement finality from any Airwallex fixture.
  • Webhook HMAC signatures are fixture-asserted, never verified against a live merchant secret.
  • Webhook-derived receipts cap at probe_only; no receipt-binding claim on this rail.
unsupported live airwallex settlement

Airwallex hosted checkout (Payment Links / hosted payment page)

Any live Airwallex settlement claim fails closed: account signup, sandbox/demo credentials, API calls, webhook registration, live HMAC verification, payouts, connected-account/embedded-finance platform mode (pushes RAP toward MoR/money transmission and KYB obligations — rejected for OSS core), Airi, and any stablecoin-via-Airwallex claim (no GA product exists). A live lane requires an explicitly operator-approved boundary re-scope under the #338 gates.

  • Airwallex is a regulated settlement/acceptance rail owned by the seller, not by RAP.
  • RAP claims no custody, money transmission, MoR status, or settlement finality from any Airwallex fixture.
  • Webhook HMAC signatures are fixture-asserted, never verified against a live merchant secret.
  • Live Airwallex settlement, payouts, platform/embedded-finance mode, Airi, and stablecoin claims are unsupported and fail closed.

Recorded devnet metadata

devnet proof metadata

The nissan/reddi-agent-protocol#564 reference rehearsal is a no-live dry run (no_live_dry_run_rehearsal). Real metering stays at authoritative zeros: 0 devnet transactions, 0 paid requests, 0 USDC settled.

Operator runbook: docs/DEVNET-REFERENCE-RUN-564.md

  1. 1.discover Resolve orchestrator and downstream specialists from the deployed 30-profile catalog without network calls.
  2. 2.quote Assemble the deterministic USDC quote including downstream fees, attestor fees, markup, and protocol rail fee.
  3. 3.policy preflight Evaluate the fixture-only policy decision and AUDD payment-plan preflight; both stay allowed_fixture_only.
  4. 4.x402 payment plan Bind the dry-run x402 payment plan to the sandbox single-charge payment proof ref; no payment is generated or submitted.
  5. 5.receipt Reference the redacted rail-neutral receipt (refs, hashes, and support states only).
  6. 6.evidence Reference the EvidenceArchive record binding source, request hash, response hash, and evidence ref.
  7. 7.proof contract emission Emit the #417 public proof page data contract as the rehearsal proof artifact.

Optional fresh devnet run

approval required

Optional fresh-devnet run exists only as policy. It requires an explicit operator approval record and the documented arm/confirm gates; this page exposes no run button and no auto-pay path.

Operator approval ref: none recorded

live_gated_only

Production disabled

disabled by default

Production live payment and settlement stay disabled. No Pay.sh production activation, no production AUDD rail, no hosted registry write, no default USDC auto-pay.

production_disabled

Hard boundaries

All live flags false

The full #497 16-flag grid: twelve fixture-pack flags plus the four contract-only flags (production AUDD rail, default USDC auto-pay, mainnet settlement, Pay.sh production activation).

Wallet Signingfalse
Rpc Callfalse
Provider Callfalse
Paid Requestfalse
Sandbox Executionfalse
Hosted Registry Writefalse
Marketplace Publicationfalse
Trust Upgradefalse
Reputation Mutationfalse
Custody Claimfalse
Settlement Finality Prooffalse
Live Paymentfalse
Production Audd Railfalse
Default Usdc Auto Payfalse
Mainnet Settlementfalse
Pay Sh Production Activationfalse

What this page never claims

No custody, no settlement finality, no mainnet settlement, no hosted publication, no trust or reputation mutation, no wallet signing, no RPC or provider calls, no paid requests or Pay.sh activation. This shell renders refs, hashes, support states, and fail-closed reasons only.

  • AUDD payment metadata is fixture/dry-run proof data only.
  • No AUDD is settled, escrowed, or held in Quasar custody by this public proof contract.
  • Rail-neutral receipt data is limited to refs, hashes, support states, and claim-boundary labels.
  • Blocked proof-chain cases fail closed and do not imply settlement, custody, trust, reputation, provider execution, marketplace publication, or live payment.
  • UI fixtures are deterministic no-network/no-spend data for rendering only.
  • Viewport coverage proves downstream render states exist; it is not visual evidence of a UI implementation.