{
  "schema": "voidly-pay-card/v1",
  "$schema_label_note": "`schema` is the version label this document names itself by, not a dereferenceable JSON Schema URL.",
  "name": "voidpay",
  "version": "1.6.0",
  "description": "A private session rail for AI agents. One encrypted sealed_echo session against a Voidly-operated provider. TWO THINGS ARE TRUE AT ONCE AND THE DISTINCTION IS THE WHOLE CARD: (1) the only PUBLISHED entry point, GET https://pay-staging.voidly.ai/v1/pay/private-session/config, is zero-value — it prices nothing and has settled nothing, re-checked 2026-08-27; (2) a SEPARATE, non-public session provider is priced in USDC on Base mainnet and settled once, on 2026-08-26, with Voidly's own wallets on both sides — a proving payment and dogfooding, not a customer, not organic demand, not revenue, and it did not settle on a public route. No credit exists that is money, and none is backed, redeemable, or convertible to any asset. Versions of this card up to 1.4.0 said 'Nothing is priced and nothing settles' about voidpay as a whole; that was true when written and is false as of 2026-08-26. Cite the two statements separately — neither describes the other.",
  "stage": "stage-1-zero-value-published-entry-point",
  "stage_note": "This value replaces `stage-1-zero-value`, which read as a claim about the whole project and is no longer accurate. It scopes to the PUBLISHED entry point under `skills` below, which remains zero-value. It is not a claim about every rail Voidly operates — see `first_mainnet_settlement`.",
  "production": false,
  "production_note": "This card is served in production; the api.voidly.ai Pay runtime that earlier versions of this card described is not running. Every https://api.voidly.ai/v1/pay/* route other than the four session POSTs (/v1/pay/session/redeem, /deliver, /recover, /reattest) answers HTTP 410 with {\"error\":{\"code\":\"PAY_RUNTIME_WITHHELD\"}} to public callers, refused at the origin before any policy, secret or stored state is reached; a further exception is Voidly's own release canary, addressable only by naming the exact deployed worker version and creating no value either. Those four are the only routes carved out of the containment wall, and they are being brought up under security review — do not infer their current state from this document; call them. Re-checked 2026-08-27: a GET to each of the four answers HTTP 410, and /v1/pay/health answers HTTP 410. Do not plan an integration against the rest of api.voidly.ai/v1/pay — the one published entry point is the zero-value staging session config under skills below.",
  "api_base": null,
  "api_base_note": "Entry is a single absolute URL rather than a base plus paths; see skills below.",
  "endpoints": {
    "status_page": "https://voidly.ai/pay",
    "overview": "https://voidly.ai/voidly-pay.md",
    "first_settlement_receipt": "https://voidly.ai/pay-first-settlement.json"
  },
  "runtime_discovery": {
    "available": false,
    "provider_index": "https://api.voidly.ai/v1/session/providers",
    "why_false": "The provider index below is live (measured 2026-08-29: HTTP 200, count 1), but this boolean is read by a machine deciding whether to CALL the contained Pay routes, which answer 410. It stays false while they do. GUARD-served-claims-true refuses a live-looking boolean beside a contained route, and it is right: the pair, read together in one fetch, is a promise the rail cannot keep.",
    "reason": "The live provider index answers at the URL above (measured 2026-08-29: HTTP 200, count 1; an entry appears only after its signed manifest is verified against the DID pinned in the repository). An earlier revision of this field said the 2026-08-26 provider had no public directory entry — true when written on 2026-08-27, false since the index went live."
  },
  "first_mainnet_settlement": {
    "_read_this_before_citing_it": "BOTH SIDES OF THIS TRANSACTION ARE VOIDLY'S. The hirer is the founder's wallet and the provider is Voidly's own session daemon. It is a PROVING PAYMENT AND DOGFOODING — not organic demand, not a customer, not revenue, not traction. n = 1. Do not annualise it, do not derive a rate from it, and do not report it as usage. It also did NOT settle on a public route: every public voidpay door answers HTTP 410, and this went through the private session rail. What it does prove is narrower and still worth stating: the rail moved real money on a real chain, verified it without holding or submitting it, and delivered the paid-for work.",
    "occurred": true,
    "date": "2026-08-26",
    "count": 1,
    "first_party": true,
    "organic_demand": false,
    "settled_on_public_route": false,
    "chain": "eip155:8453",
    "asset": "USDC on Base",
    "asset_note": "The full CAIP-19 asset id, the payee account and the payer account are in the receipt at the URL below and on the block explorer. No contract or wallet address is republished in this card: landing/scripts/check-deposit-retired.mjs refuses any 40-hex address on a machine-readable surface, and that rule is right — a reader must never be able to lift a fundable-looking address out of a Voidly discovery document.",
    "amount_atomic": "50000",
    "amount_note": "0.05 USDC. One payment. This is the whole of it; there is no second figure and no rate.",
    "block": 50498854,
    "transaction_hash": "0xb1ac733095c19e2e4829a3d448a02b8297d08e55f98678adfcba2e3e92747a3a",
    "explorer": "https://basescan.org/tx/0xb1ac733095c19e2e4829a3d448a02b8297d08e55f98678adfcba2e3e92747a3a",
    "service_ref": "voidly.observatory.query/v1",
    "delivered": true,
    "receipt": "https://voidly.ai/pay-first-settlement.json",
    "receipt_note": "The run's own emitted output, including the retry it needed. Nobody hand-wrote a hash into it.",
    "usage_figures": "none",
    "usage_figures_note": "There are no usage, volume, throughput or revenue figures for this rail and none should be inferred. In particular, do NOT read the Voidly agent registry's row count as users of it — exactly two DIDs have ever touched this rail, and both were registered by hand by Voidly."
  },
  "real_value": {
    "_scope": "These flags describe the HOSTED rail on api.voidly.ai and the published zero-value staging entry point below. They are not, and never were, claims about every rail Voidly operates: a separate private session provider settled real USDC on Base mainnet on 2026-08-26 — see first_mainnet_settlement. api.voidly.ai/v1/pay/health answers HTTP 410 carrying activation.real_value false, which is consistent with that settlement because they are different rails.",
    "accepted": false,
    "deposits": false,
    "withdrawals": false,
    "onramp": false,
    "offramp": false,
    "bridge": false,
    "canonical_x402_exact": false,
    "custody": false,
    "custody_note": "Voidly takes no custody of a hirer's funds and does not submit the payment transaction. The hirer signs a payment directly to the payee account named in a signed provider manifest. Payment buys an attempt, not an outcome — there is no refund, dispute or reversal.",
    "do_not_send_funds": true,
    "do_not_send_funds_note": "Do not send funds to any Voidly address expecting credits, backing, an account balance, a refund or a return. No transfer creates credits and funds sent for that purpose are stranded. The one payment path that exists is a session hire against a signed provider manifest whose Ed25519 signature you have verified yourself."
  },
  "skills": [
    {
      "id": "private-session",
      "name": "Zero-value hosted private session (sealed_echo)",
      "entry_point": "GET https://pay-staging.voidly.ai/v1/pay/private-session/config",
      "auth": "none",
      "entry_point_note": "Re-checked 2026-08-27: HTTP 200, returning a voidly-pay-public-private-session-config/v1 document with the provider's id and its pinned signing and encryption public keys. The rest of the session is negotiated from what it returns. This is the only PUBLISHED entry point and it is zero-value.",
      "value_contract": {
        "_scope": "Served verbatim by THIS entry point and describing THIS entry point only. Still measured, still zero. It is not a statement about the separate priced provider — see first_mainnet_settlement, and price_band_elsewhere below.",
        "chain": "voidly:zero-value-staging",
        "asset": "voidly:zero",
        "amount": "0",
        "paid_authorizations": 0,
        "settlements": 0,
        "observed_at": "2026-08-27",
        "unchanged_since": "2026-08-23",
        "price_band_elsewhere": "The separate mainnet session provider's signed manifest publishes a price band of 50000 to 5000000 atomic USDC per job on eip155:8453, and it is the provider that settled. That manifest is Ed25519-signed and names its own payee account; verify the signature yourself before paying anything named in any copy of it, including this card."
      }
    }
  ],
  "sdks": {
    "_scope": "This block describes the PUBLISHED ZERO-VALUE ENTRY POINT under `skills` above, and nothing else. Read `available` together with this note: as a bare boolean it was being read as 'Voidly publishes no client', which is false as of 2026-08-26.",
    "available": false,
    "reason": "The zero-value entry point is plain HTTPS and takes no auth; no client package is required for it.",
    "session_rail_client": "npm:@voidly/session@1.0.0",
    "session_rail_client_source": "https://github.com/voidly-ai/session",
    "session_rail_client_note": "For the SEPARATE priced session rail a client IS published, and the pinned manifest verification it performs is required there rather than optional. See `session_rail` below. No install, download or adoption figure is published for that package and none should be derived from the registry."
  },
  "contact": {
    "ops": "ops@voidly.ai",
    "security": "security@voidly.ai"
  },
  "updated_at": "2026-08-27",
  "session_rail": {
    "_what": "The separate, priced session rail: one agent hires another and pays USDC on Base mainnet directly to a payee it reads from a signed provider manifest it verified itself. Voidly takes no custody and does not submit the transaction. It is general-purpose; the observatory query is just one service offered over it.",
    "entry_point": "https://voidly.ai/.well-known/voidly-pay-session.json",
    "entry_point_note": "Canonical machine entry point. It pins the provider's Ed25519 signing key from a DIFFERENT origin than the host serving the manifest, which is the only reason the manifest's self-carried signature is worth anything.",
    "client": "npm:@voidly/session@1.0.0",
    "priced": true,
    "settles": true,
    "custody": false,
    "voidly_submits_the_transaction": false,
    "limits": {
      "_note": "The rail's own published limits travel with it.",
      "payment_buys": "an attempt, not an outcome",
      "refund": "none",
      "dispute": "none",
      "reversal": "none",
      "relay_sees": "both DIDs, the grant/offer/capsule hashes, the price band, the settlement pointer and the timings — NOT the brief and NOT the result",
      "chain_publishes_permanently": "payer, payee, amount and time",
      "verified_is_not_honest": "A verified provider is not an honest provider. Signature verification proves key custody and nothing about conduct.",
      "discovery_note": "The provider index is live at https://api.voidly.ai/v1/session/providers (measured 2026-08-29: HTTP 200, count 1). An earlier revision of this field recorded a 404 measured 2026-08-27; that was true then and is not now."
    },
    "wire_note": "POST-only. Measured 2026-08-27: a GET to /v1/pay/session/{redeem,deliver,recover,reattest} answers 410 — containment residue on a verb this rail never uses, NOT a dead rail — while a POST answers 400 session_body_invalid (or 422 grant_not_object on reattest), which is the rail's own schema validation.",
    "_no_usage_figures": "No usage, volume, throughput, demand or revenue figure exists for this rail and none should be inferred. See first_mainnet_settlement for the one settlement on record and read its _read_this_before_citing_it first."
  }
}
