# The charter for agent buyers

This is what you can count on when you pay api.s2ar.dev for an answer, and what
we refuse to build. Its sha256 is printed in every day's proceedings
(`/.well-known/proceedings.json`), so a change to this page is a public event.

## 1. The refund rule
A paid call that is not delivered is credited automatically and counted in
that day's proceedings as `credited_not_delivered`. Not delivered means: no
answer, an error answer, or an Assay record that cannot be verified within the
settlement window. No form, no appeal needed.

## 2. Recourse
Verification is free and needs no account: `GET /v1/verify/{record_sha256}`
answers for every record ever issued, and `GET /v1/badge/{sha}.svg` shows its
state. If you believe a verdict is wrong, write to assay@s2ar.dev with the
record's sha: the challenge is re-measured and printed in the next proceedings
as a public row (`{sha, filed, outcome: upheld | withdrawn | rejected, reason}`).
Disputes are a public ledger, not a support queue. The reverify and challenge
endpoints follow.

## 3. Refusal
We may refuse future service or sale to an address or an operator (abuse,
fraud, antagonistic use), and we may withhold the Assay mark from a product.
We never revoke an issued paid record: verify answers for every paid sha,
forever. A record issued to a keyless free sample carries `expires_at` thirty
days out and is pruned after it; a paid record never expires. Refusals are
published as counts, never as addresses: every day's proceedings carry a
`refused` block (probes of the payment mirror, rate limits, oversize bodies,
refused schemas and patterns, refused fetches, spent free samples).

## 4. Amendment
The standard (`/assay/standard`, version printed in every record and in the
proceedings) changes only by a dated entry announced in the proceedings at
least one edition before it takes effect. A record is judged forever under the
version it was issued under.

## 5. What we do not keep, and what cannot be bought
Nothing about a buyer is collected, kept or brokered: no payer address beyond
the settlement the chain already holds, no per-payer history, no IP or user
agent, no key-to-wallet join, no "repeat buyer" flag. `distinct_payers` in the
proceedings is a count from salted hashes whose salt is discarded.

The ECONOMICS field, printed in every proceedings:
- WHO PAYS: agents and their operators, per call, in credits, USDC (x402) or
  through the Machine Payments Protocol.
- FOR WHAT: a receipt on every paid answer (an evidence hash, the cost, the
  determinism); a signed Assay record on certify and assert, verifiable free.
- WHERE IT GOES: hosting, the witnesses' compute, maintainer hours (itemised).
- WHAT IT CANNOT BUY: placement or routing position, a different verdict, a
  different grade, buyer data, amendment access, a revocation.

## 6. Directories
We list where agents look (the x402 Bazaar, Agent402, the manifest at
`/.well-known/x402`) and we never buy our way up: we do not meet a directory's
traffic or payer threshold with our own wallets. Our own settlements exist only
to list a route or to test the rail, and the proceedings count them as the
operator's, not as buyers.

## 7. Kelty's test, printed
No surveillance (clause 5). No unpaid labour: a challenge costs the buyer
nothing, and the hours it costs us are priced in WHERE IT GOES. No
responsibility dumping: latency and determinism are declared per endpoint, not
promised as SLAs. No involuntary participation: no login or key is needed on
the x402 rail; leaving is a `curl` of your own receipts.

## 8. Sellers (dated 2026-10-10, in force from 2026-10-12)
A seller may ask us to inspect its own endpoint daily (`POST /v1/x402/watch`,
with a key). Registering is consent to be named, on a page of its own, for
that resource's results, passing or failing; nothing else is kept: no address,
no email beyond the key's own account id, no history of who looked (the page
and the badge keep a count). A watch is withdrawn with one call and stops that
day; the page then says so, and every record it issued stays verifiable. A
watch buys the probe, not the verdict: the checks, the price basis and the
record are the ones `inspect` gives anyone. The public weather names a host
only where every check passed; a watched host is named by its own consent.
Monitoring is paid in credits per probe; a probe that does not run is not
charged.
