Internet-Draft draft-dogru-cedulon-05.txt is now available.
Title: Cedulon: An Audit Layer for Agent-to-Agent Commerce
Author: Emek Can Dogru
Name: draft-dogru-cedulon-05.txt
Pages: 86
Dates: 2026-08-31
Abstract:
This document defines the Cedulon Protocol, an audit layer for agent-
to-agent commerce. Payment rails such as HTTP 402 flows (x402) and
mandate protocols (AP2) already move value, and a mandate protocol
can already refuse a spend before it happens and return signed
receipts. What they do not, by themselves, give a party that is
neither payer nor rail operator is a retrievable record of that
decision and a signed spend receipt that reconciles against an
authenticated extract of the rail. Cedulon specifies a Trade
Manifest (signed offer before payment), a Policy Decision Point with
default deny, a Spend Receipt (COSE/CWT claim set after a gated
payment), epoch checkpoints, and rail-extract reconciliation. The
reconciliation shows that no settlement on the extract lacks a
receipt and no settled receipt is absent from the extract. That
result is unconditional only when the verifier pins the rail key out
of band and states the period under audit; otherwise the document
requires it to be reported as conditional. Checkpoints carry the
suppression guarantee, so the document profiles the checkpoint as a
Signed Statement, gives the verification algorithm a step that
consumes the witness receipts returned for checkpoints, names what a
witness holding a checkpoint the presented chain omits reports,
brings equivocation within reach by comparing recorded copies against
the presented chain, and states how checkpoint totals may be withheld
without withholding the fact that they were. No signed object may be
verified against a key it carries itself, and a presented Trade
Manifest must be bound both to the receipts that name it and to the
terms those receipts claim. The document also names a threat no
adversary causes, a settlement recorded on a rail with no receipt
behind it, and defines a Dispute Evidence Bundle (evidence, not an
award) and optional SCITT anchoring. This revision defines the
encodings earlier revisions called canonical without defining them,
and states the exact input to every hash-valued field, so that an
independent verifier can be written from the text alone. Cedulon is
not a competitor to x402 or AP2; it sits above them.
The IETF datatracker status page for this Internet-Draft is:
https://datatracker.ietf.org/doc/draft-dogru-cedulon/
There is also an HTMLized version available at:
https://datatracker.ietf.org/doc/html/draft-dogru-cedulon-05
A diff from the previous version is available at:
https://author-tools.ietf.org/iddiff?url2=draft-dogru-cedulon-05
Internet-Drafts are also available by rsync at:
rsync.ietf.org::internet-drafts
_______________________________________________
I-D-Announce mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not
affiliated with the servers or forums shown here and is not responsible for
the content of articles, which is written by their respective authors.