Inspiration
AI agents are becoming paying customers of the internet. Cloudflare's x402 lets websites charge agents per request; Google's AP2 and the card networks' agent programs are building how machines pay. But walk it forward 18 months: your company runs 50 agents, each effectively carrying a corporate card that works at machine speed. The CFO's questions arrive fast — who authorized this spend? What did we actually get? Can we prove any of it?
Every participant in the agent economy profits from more spending — the rails from volume, the sellers from consumption — except the organization whose agents do the buying. And a payment network attesting to its own transactions is a company auditing itself. TLS solved this class of problem with Certificate Transparency. Machine commerce had nothing.
So we built the missing layer — and then built the first agent born with it.
What it does
AttestedResearchAgent is a repetitive-task research agent built on the AWS Strands Agents SDK: give it a topic, it plans, fetches its sources, and writes a summary report. Thousands of teams have built that agent.
Here is what no other agent does: every consequential action is cryptographically attested to a tamper-evident ledger implementing MCA (Machine Commerce Attestation) — an open, Certificate-Transparency-style evidence standard we published. Every fetch is recorded as a hash-chained attestation record (request hash, response content SHA-256, status, timing). When the agent hits an HTTP 402 paywall, it captures the payment terms as evidence — in the demo it discovers a paywall demanding 0.0100 USDC over the x402 rail. Even failures are attested (synthetic 599 events): this agent cannot act off the record. After each run it prints its own audit trail: 7 events reported → 7 accepted → RESULT: PASS, plus the public URLs where anyone can verify the log's signed Merkle checkpoints.
The agent helps with the repetitive task. The attestation makes it deployable where it matters — finance, procurement, compliance — because "trust me" becomes "verify me."
How we built it
- Strands Agents SDK (Python) for the agent loop;
attested_fetchis registered as a native@tooland is the agent's only network path. attested_fetchwraps httpx: hashes the request descriptor and response content, parses 402 payment terms into flat descriptors, and fire-and-forgets events to the reporter. It never raises into the agent — transport failures return an error result and attest a synthetic 599 event.mca_reporterbatches events to a production-grade attestation ledger (IONDRA's ACA-X ingestion API) with a drop-oldest bounded queue and a background drain thread. Event ids are derived from (run_id, request hash, content hash) — re-running a run is acknowledged as duplicates, proven by a replay test.- The ledger implements the open MCA v0.1 spec: JCS canonicalization, SHA-256 hash chains, RFC-6962 Merkle checkpoints signed with Ed25519, published at a public
/.well-known/mca/log.jsondiscovery document — with an open-source, dependency-free reference verifier. - Offline-deterministic by default: the demo runs in CI with zero model keys (canned plan + extractive summarizer); Bedrock/OpenAI providers are one env var away.
Challenges we ran into
The best bug of the project: our key-generation script's cleanup tried to delete a previous demo user — and the platform's append-only audit ledger refused, because deleting an actor would orphan its audit history. Our own integrity model defended the record against our demo's cleanup script. We shipped the demo with fresh identities and kept the lesson: the system protecting history from everyone includes us. Also non-trivial: making attestation truly zero-risk to the agent (bounded queues, never-raise semantics — load-tested), and designing idempotent event identity so retries can never double-count spend evidence.
Accomplishments that we're proud of
- Two independent implementations of the MCA verifier agree byte-for-byte on the conformance vectors — one written from the published spec alone. The standard is real, not documentation for one codebase.
- Our build system refused to ship three times — and that's our favorite feature. A completion reviewer rejected software-key custody as not meeting the task's HSM bar. The agent withheld the demo sequence because one payment path lacked test coverage. Then it declined to generate inclusion proofs at all — because a stranger running the public verifier couldn't have validated them. Three gates, three correct refusals, zero embarrassing artifacts shipped. Most teams' tooling optimizes for shipping; ours is wired to be right in public.
- We rotated a signing key under fire, live, mid-hackathon. A source-controlled key copy was discovered, removed, and rotated; production spent the gap failing CLOSED through five distinct states — honest errors, never one false attestation — and the incident closed with cryptographic verification from the public internet. The evidence layer proved its own integrity model before it ever recorded a fact.
- The log now runs a versioned canonical era (log id record-hash-v1) whose checkpoint cadence is declared machine-readably in the discovery document itself — and whose runtime inclusion proofs are gated behind the actual public mca-verify CLI passing against runtime-generated artifacts. Not a reimplementation. The real tool a stranger would run.
- A production log anyone on Earth can verify right now, free, forever — guarded by a 1,048-test suite run twice in strict sequence plus a deterministic no-parallelism pass, because a shared append-only database could theoretically fake a green chain and we refuse to accept even that.
- The phrase "the first natively-attested AI agent" is, as far as we can tell, simply true.
What we learned
Agents don't need more capabilities to be trusted with money — they need evidence. The gap between a cool demo and a deployable agent in a regulated enterprise is exactly one tamper-evident audit trail. And open standards beat proprietary lock-in: we gave the format away (CC-BY spec, Apache-2.0 verifier) because evidence you must pay to check isn't evidence.
What's next
Update, 31 Aug 2026 — the promise from this section came true, during judging. Proof-0 is live: an agent operating under an IONDRA one-shot mandate (Base mainnet only, one allowlisted domain, $3 cap, exactly one payment) paid Exa 0.007 USDC for a real search — Base transaction 0x15502e8e…41fdb7 — and the request, payment, and delivery were sealed as hashes into the public log (checkpoint rh1-cp-8). See it and verify it yourself: https://www.iondra.com/proof/0 — the page publishes the BaseScan link, the canonical record, the checkpoint, the inclusion proof, and copy-paste commands for the pinned public verifier; a stranger running them gets record, chain, checkpoint, and inclusion all VALID. Rails prove money moved. This proves what was requested, what was paid, and what was delivered — and that none of it was rewritten. Next: witness federation (the checkpoint is honestly labeled UNWITNESSED today), signed spend mandates, cross-rail binding (Stripe next), delivery attestation, and listing the attestation service itself in the x402 bazaar. The agent economy is getting its rails. This is its flight recorder — and it has recorded its first real fact.
Verify it yourself (60 seconds)
git clone https://github.com/1omega/mca-verify && cd mca-verify && npm test
curl https://www.iondra.com/.well-known/mca/log.json
Spec: github.com/1omega/mca-spec · Agent: github.com/1omega/strands-mca-agent · iondra.com/mca
Built With
- amazon-web-services
- node.js
- postgresql
- python
- strands-agents
- typescript
- x402
Log in or sign up for Devpost to join the conversation.