KYA-OSAGENT-ACTIONABLE
Merchant edge · verifier view
merchant
responsible party
Connect Claude · /agent/mcp
Human consent → scoped grant → order → revocation. Claude or the scripted MCP client requests two risotto, CHF 39.80. The human grants authority up to CHF 50.00 for one GS1 product class. Every place_order appears here as the merchant verifies it.
0 · Discovery · well-knownnot read yet
merchant
merchant DID
accepts
holder key
revocation
clock skew
scopes
agent says
The grant
responsible party
agent (subject)
audience
scope · GS1 Digital Link product class
MaxAmount
valid until
status bit
list index
Signed receipt · evidence recordexpand
every allowed response is signed by the merchant's key — a receipt any party can verify
Audit trail · shipped protocol
0 ENTRIES
signed by the merchant key · hash-chained · delivery required
Verification gates
READY
The shipped verifier decides · nothing mocked ·
Live MCP client · same tools as Claude Desktop
Responsible Party · the shopper's hub
did
signing key
status list
ceremony
Event logclear

Confirm revocation with your passkey

Use your registered passkey or security key to withdraw this grant.
FIDO2 · the WebAuthn challenge is the hash of this exact revocation
AUDIT TRAIL
every decision the gate made, as the SDK recorded it · signed · hash-chained · RFC 9162 checkpoint · witnessed by the Responsible Party
esc · close
Ledger ·
Checkpoint · signed RFC 9162 root
Merkle tree · leaves = entry digests
Offline verifier · verifyAuditBundle · trust from policy only