feat(action-providers): add ActionRefVerify provider — recomputable, third-party-checkable reference for any declared action - #1459

Open
giskard09 wants to merge 1 commit into
coinbase:mainfrom
giskard09:feat/action-ref-verify-provider
Open

feat(action-providers): add ActionRefVerify provider — recomputable, third-party-checkable reference for any declared action#1459
giskard09 wants to merge 1 commit into
coinbase:mainfrom
giskard09:feat/action-ref-verify-provider

Conversation

@giskard09

Copy link
Copy Markdown

What this adds

A new, read-only action provider, ActionRefVerifyActionProvider — no wallet required, no transactions. Two actions:

  • compute_action_ref — derives action_ref, a deterministic content-addressed identifier (SHA-256 of RFC 8785 JCS canonicalization, action-ref-v1 spec) for a declared {agent_id, action_type, scope, timestamp}.
  • verify_action_ref_anchor — queries a public chain's RPC directly (Base, Arbitrum One, or Ink — same AnchorRegistry CREATE2 address on all three) for an Anchored(bytes32,address,uint256) event matching a given action_ref. Trusts nothing off-chain.

Why

X402ActionProvider.retryWithX402 dispatches a real x402 payment and, on success, reports {status: "success", details: {paymentUsed, paymentProof}}paymentProof decoded straight from the payment-response / x-payment-response header the facilitator sent back. That's the provider's own account of settlement. This provider does not close that boundary — it answers an adjacent, narrower question: given a declared request and result, can any third party — not just the facilitator — recompute a content-addressed identifier for that exact pair and confirm an independent, operator-external anchor timestamp, regardless of whether the underlying payment was accurately reported?

The same construction applies to any other action provider's declared input/output, not just x402 — this provider is intentionally generic, not specific to any single provider or protocol.

What it does NOT do

  • Does not verify that a declared action actually happened as described.
  • Does not evaluate whether an action was safe or advisable.
  • Does not sign, dispatch, or modify any transaction, payment, or other agent action.
  • Does not require any change to any other provider's API — it composes with any action's declared inputs/outputs after the fact.

Worked example

A full, independently-reproducible instance (derivation + a real on-chain anchor on Base mainnet, modeled on X402ActionProvider.retryWithX402) is published at giskard09/coinbase-x402-action-ref-anchor. It is explicitly a synthetic worked example — see that repo's PROVENANCE.md — no real wallet, no real x402 payment. Read it before using this provider against a real action.

Testing

6/6 tests passing (actionRefVerifyActionProvider.test.ts), including a byte-exact check against the published worked example's action_ref. pnpm lint, pnpm format:check, and tsc --noEmit all clean.

Read-only, no wallet, no transactions. Derives action_ref (action-ref-v1:
SHA-256 of RFC 8785 JCS over agent_id/action_type/scope/timestamp) for a
declared action, and independently checks the public chain for a matching
Anchored event against the permissionless AnchorRegistry contract.
Modeled on X402ActionProvider.retryWithX402's real request/response shape.
Full worked example (incl. a real on-chain anchor) at
github.com/giskard09/coinbase-x402-action-ref-anchor.
Tests: 6/6 passing. Lint, prettier, tsc --noEmit all clean.
@cb-heimdall

Copy link
Copy Markdown

🟡 Heimdall Review Status

RequirementStatusMore Info
Reviews 🟡 0/1
Denominator calculation
Show calculation
1 if user is bot0
1 if user is external0
2 if repo is sensitive0
From .codeflow.yml1
Additional review requirements
Show calculation
Max0
0
From CODEOWNERS0
Global minimum0
Max 1
1
1 if commit is unverified0
Sum1

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

action providerNew action providerdocumentationImprovements or additions to documentationtypescript

Development

Successfully merging this pull request may close these issues.

2 participants

@giskard09@cb-heimdall
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

feat(action-providers): add ActionRefVerify provider — recomputable, third-party-checkable reference for any declared action - #1459

Open
giskard09 wants to merge 1 commit into
coinbase:mainfrom
giskard09:feat/action-ref-verify-provider
Open

feat(action-providers): add ActionRefVerify provider — recomputable, third-party-checkable reference for any declared action#1459
giskard09 wants to merge 1 commit into
coinbase:mainfrom
giskard09:feat/action-ref-verify-provider

Conversation

@giskard09

Copy link
Copy Markdown

What this adds

A new, read-only action provider, ActionRefVerifyActionProvider — no wallet required, no transactions. Two actions:

  • compute_action_ref — derives action_ref, a deterministic content-addressed identifier (SHA-256 of RFC 8785 JCS canonicalization, action-ref-v1 spec) for a declared {agent_id, action_type, scope, timestamp}.
  • verify_action_ref_anchor — queries a public chain's RPC directly (Base, Arbitrum One, or Ink — same AnchorRegistry CREATE2 address on all three) for an Anchored(bytes32,address,uint256) event matching a given action_ref. Trusts nothing off-chain.

Why

X402ActionProvider.retryWithX402 dispatches a real x402 payment and, on success, reports {status: "success", details: {paymentUsed, paymentProof}}paymentProof decoded straight from the payment-response / x-payment-response header the facilitator sent back. That's the provider's own account of settlement. This provider does not close that boundary — it answers an adjacent, narrower question: given a declared request and result, can any third party — not just the facilitator — recompute a content-addressed identifier for that exact pair and confirm an independent, operator-external anchor timestamp, regardless of whether the underlying payment was accurately reported?

The same construction applies to any other action provider's declared input/output, not just x402 — this provider is intentionally generic, not specific to any single provider or protocol.

What it does NOT do

  • Does not verify that a declared action actually happened as described.
  • Does not evaluate whether an action was safe or advisable.
  • Does not sign, dispatch, or modify any transaction, payment, or other agent action.
  • Does not require any change to any other provider's API — it composes with any action's declared inputs/outputs after the fact.

Worked example

A full, independently-reproducible instance (derivation + a real on-chain anchor on Base mainnet, modeled on X402ActionProvider.retryWithX402) is published at giskard09/coinbase-x402-action-ref-anchor. It is explicitly a synthetic worked example — see that repo's PROVENANCE.md — no real wallet, no real x402 payment. Read it before using this provider against a real action.

Testing

6/6 tests passing (actionRefVerifyActionProvider.test.ts), including a byte-exact check against the published worked example's action_ref. pnpm lint, pnpm format:check, and tsc --noEmit all clean.

Read-only, no wallet, no transactions. Derives action_ref (action-ref-v1:
SHA-256 of RFC 8785 JCS over agent_id/action_type/scope/timestamp) for a
declared action, and independently checks the public chain for a matching
Anchored event against the permissionless AnchorRegistry contract.
Modeled on X402ActionProvider.retryWithX402's real request/response shape.
Full worked example (incl. a real on-chain anchor) at
github.com/giskard09/coinbase-x402-action-ref-anchor.
Tests: 6/6 passing. Lint, prettier, tsc --noEmit all clean.
@cb-heimdall

Copy link
Copy Markdown

🟡 Heimdall Review Status

RequirementStatusMore Info
Reviews 🟡 0/1
Denominator calculation
Show calculation
1 if user is bot0
1 if user is external0
2 if repo is sensitive0
From .codeflow.yml1
Additional review requirements
Show calculation
Max0
0
From CODEOWNERS0
Global minimum0
Max 1
1
1 if commit is unverified0
Sum1

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

action providerNew action providerdocumentationImprovements or additions to documentationtypescript

Development

Successfully merging this pull request may close these issues.

2 participants

@giskard09@cb-heimdall
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(action-providers): add ActionRefVerify provider — recomputable, third-party-checkable reference for any declared action - #1459

Open
giskard09 wants to merge 1 commit into
coinbase:mainfrom
giskard09:feat/action-ref-verify-provider
Open

feat(action-providers): add ActionRefVerify provider — recomputable, third-party-checkable reference for any declared action#1459
giskard09 wants to merge 1 commit into
coinbase:mainfrom
giskard09:feat/action-ref-verify-provider

Conversation

@giskard09

Copy link
Copy Markdown

What this adds

A new, read-only action provider, ActionRefVerifyActionProvider — no wallet required, no transactions. Two actions:

  • compute_action_ref — derives action_ref, a deterministic content-addressed identifier (SHA-256 of RFC 8785 JCS canonicalization, action-ref-v1 spec) for a declared {agent_id, action_type, scope, timestamp}.
  • verify_action_ref_anchor — queries a public chain's RPC directly (Base, Arbitrum One, or Ink — same AnchorRegistry CREATE2 address on all three) for an Anchored(bytes32,address,uint256) event matching a given action_ref. Trusts nothing off-chain.

Why

X402ActionProvider.retryWithX402 dispatches a real x402 payment and, on success, reports {status: "success", details: {paymentUsed, paymentProof}}paymentProof decoded straight from the payment-response / x-payment-response header the facilitator sent back. That's the provider's own account of settlement. This provider does not close that boundary — it answers an adjacent, narrower question: given a declared request and result, can any third party — not just the facilitator — recompute a content-addressed identifier for that exact pair and confirm an independent, operator-external anchor timestamp, regardless of whether the underlying payment was accurately reported?

The same construction applies to any other action provider's declared input/output, not just x402 — this provider is intentionally generic, not specific to any single provider or protocol.

What it does NOT do

  • Does not verify that a declared action actually happened as described.
  • Does not evaluate whether an action was safe or advisable.
  • Does not sign, dispatch, or modify any transaction, payment, or other agent action.
  • Does not require any change to any other provider's API — it composes with any action's declared inputs/outputs after the fact.

Worked example

A full, independently-reproducible instance (derivation + a real on-chain anchor on Base mainnet, modeled on X402ActionProvider.retryWithX402) is published at giskard09/coinbase-x402-action-ref-anchor. It is explicitly a synthetic worked example — see that repo's PROVENANCE.md — no real wallet, no real x402 payment. Read it before using this provider against a real action.

Testing

6/6 tests passing (actionRefVerifyActionProvider.test.ts), including a byte-exact check against the published worked example's action_ref. pnpm lint, pnpm format:check, and tsc --noEmit all clean.

Read-only, no wallet, no transactions. Derives action_ref (action-ref-v1:
SHA-256 of RFC 8785 JCS over agent_id/action_type/scope/timestamp) for a
declared action, and independently checks the public chain for a matching
Anchored event against the permissionless AnchorRegistry contract.
Modeled on X402ActionProvider.retryWithX402's real request/response shape.
Full worked example (incl. a real on-chain anchor) at
github.com/giskard09/coinbase-x402-action-ref-anchor.
Tests: 6/6 passing. Lint, prettier, tsc --noEmit all clean.
@cb-heimdall

Copy link
Copy Markdown

🟡 Heimdall Review Status

RequirementStatusMore Info
Reviews 🟡 0/1
Denominator calculation
Show calculation
1 if user is bot0
1 if user is external0
2 if repo is sensitive0
From .codeflow.yml1
Additional review requirements
Show calculation
Max0
0
From CODEOWNERS0
Global minimum0
Max 1
1
1 if commit is unverified0
Sum1

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

action providerNew action providerdocumentationImprovements or additions to documentationtypescript

Development

Successfully merging this pull request may close these issues.

2 participants

@giskard09@cb-heimdall
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(action-providers): add ActionRefVerify provider — recomputable, third-party-checkable reference for any declared action - #1459

Open
giskard09 wants to merge 1 commit into
coinbase:mainfrom
giskard09:feat/action-ref-verify-provider
Open

feat(action-providers): add ActionRefVerify provider — recomputable, third-party-checkable reference for any declared action#1459
giskard09 wants to merge 1 commit into
coinbase:mainfrom
giskard09:feat/action-ref-verify-provider

Conversation

@giskard09

Copy link
Copy Markdown

What this adds

A new, read-only action provider, ActionRefVerifyActionProvider — no wallet required, no transactions. Two actions:

  • compute_action_ref — derives action_ref, a deterministic content-addressed identifier (SHA-256 of RFC 8785 JCS canonicalization, action-ref-v1 spec) for a declared {agent_id, action_type, scope, timestamp}.
  • verify_action_ref_anchor — queries a public chain's RPC directly (Base, Arbitrum One, or Ink — same AnchorRegistry CREATE2 address on all three) for an Anchored(bytes32,address,uint256) event matching a given action_ref. Trusts nothing off-chain.

Why

X402ActionProvider.retryWithX402 dispatches a real x402 payment and, on success, reports {status: "success", details: {paymentUsed, paymentProof}}paymentProof decoded straight from the payment-response / x-payment-response header the facilitator sent back. That's the provider's own account of settlement. This provider does not close that boundary — it answers an adjacent, narrower question: given a declared request and result, can any third party — not just the facilitator — recompute a content-addressed identifier for that exact pair and confirm an independent, operator-external anchor timestamp, regardless of whether the underlying payment was accurately reported?

The same construction applies to any other action provider's declared input/output, not just x402 — this provider is intentionally generic, not specific to any single provider or protocol.

What it does NOT do

  • Does not verify that a declared action actually happened as described.
  • Does not evaluate whether an action was safe or advisable.
  • Does not sign, dispatch, or modify any transaction, payment, or other agent action.
  • Does not require any change to any other provider's API — it composes with any action's declared inputs/outputs after the fact.

Worked example

A full, independently-reproducible instance (derivation + a real on-chain anchor on Base mainnet, modeled on X402ActionProvider.retryWithX402) is published at giskard09/coinbase-x402-action-ref-anchor. It is explicitly a synthetic worked example — see that repo's PROVENANCE.md — no real wallet, no real x402 payment. Read it before using this provider against a real action.

Testing

6/6 tests passing (actionRefVerifyActionProvider.test.ts), including a byte-exact check against the published worked example's action_ref. pnpm lint, pnpm format:check, and tsc --noEmit all clean.

Read-only, no wallet, no transactions. Derives action_ref (action-ref-v1:
SHA-256 of RFC 8785 JCS over agent_id/action_type/scope/timestamp) for a
declared action, and independently checks the public chain for a matching
Anchored event against the permissionless AnchorRegistry contract.
Modeled on X402ActionProvider.retryWithX402's real request/response shape.
Full worked example (incl. a real on-chain anchor) at
github.com/giskard09/coinbase-x402-action-ref-anchor.
Tests: 6/6 passing. Lint, prettier, tsc --noEmit all clean.
@cb-heimdall

Copy link
Copy Markdown

🟡 Heimdall Review Status

RequirementStatusMore Info
Reviews 🟡 0/1
Denominator calculation
Show calculation
1 if user is bot0
1 if user is external0
2 if repo is sensitive0
From .codeflow.yml1
Additional review requirements
Show calculation
Max0
0
From CODEOWNERS0
Global minimum0
Max 1
1
1 if commit is unverified0
Sum1

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

action providerNew action providerdocumentationImprovements or additions to documentationtypescript

Development

Successfully merging this pull request may close these issues.

2 participants

@giskard09@cb-heimdall
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

feat(action-providers): add ActionRefVerify provider — recomputable, third-party-checkable reference for any declared action - #1459

Open
giskard09 wants to merge 1 commit into
coinbase:mainfrom
giskard09:feat/action-ref-verify-provider
Open

feat(action-providers): add ActionRefVerify provider — recomputable, third-party-checkable reference for any declared action#1459
giskard09 wants to merge 1 commit into
coinbase:mainfrom
giskard09:feat/action-ref-verify-provider

Conversation

@giskard09

Copy link
Copy Markdown

What this adds

A new, read-only action provider, ActionRefVerifyActionProvider — no wallet required, no transactions. Two actions:

  • compute_action_ref — derives action_ref, a deterministic content-addressed identifier (SHA-256 of RFC 8785 JCS canonicalization, action-ref-v1 spec) for a declared {agent_id, action_type, scope, timestamp}.
  • verify_action_ref_anchor — queries a public chain's RPC directly (Base, Arbitrum One, or Ink — same AnchorRegistry CREATE2 address on all three) for an Anchored(bytes32,address,uint256) event matching a given action_ref. Trusts nothing off-chain.

Why

X402ActionProvider.retryWithX402 dispatches a real x402 payment and, on success, reports {status: "success", details: {paymentUsed, paymentProof}}paymentProof decoded straight from the payment-response / x-payment-response header the facilitator sent back. That's the provider's own account of settlement. This provider does not close that boundary — it answers an adjacent, narrower question: given a declared request and result, can any third party — not just the facilitator — recompute a content-addressed identifier for that exact pair and confirm an independent, operator-external anchor timestamp, regardless of whether the underlying payment was accurately reported?

The same construction applies to any other action provider's declared input/output, not just x402 — this provider is intentionally generic, not specific to any single provider or protocol.

What it does NOT do

  • Does not verify that a declared action actually happened as described.
  • Does not evaluate whether an action was safe or advisable.
  • Does not sign, dispatch, or modify any transaction, payment, or other agent action.
  • Does not require any change to any other provider's API — it composes with any action's declared inputs/outputs after the fact.

Worked example

A full, independently-reproducible instance (derivation + a real on-chain anchor on Base mainnet, modeled on X402ActionProvider.retryWithX402) is published at giskard09/coinbase-x402-action-ref-anchor. It is explicitly a synthetic worked example — see that repo's PROVENANCE.md — no real wallet, no real x402 payment. Read it before using this provider against a real action.

Testing

6/6 tests passing (actionRefVerifyActionProvider.test.ts), including a byte-exact check against the published worked example's action_ref. pnpm lint, pnpm format:check, and tsc --noEmit all clean.

Read-only, no wallet, no transactions. Derives action_ref (action-ref-v1:
SHA-256 of RFC 8785 JCS over agent_id/action_type/scope/timestamp) for a
declared action, and independently checks the public chain for a matching
Anchored event against the permissionless AnchorRegistry contract.
Modeled on X402ActionProvider.retryWithX402's real request/response shape.
Full worked example (incl. a real on-chain anchor) at
github.com/giskard09/coinbase-x402-action-ref-anchor.
Tests: 6/6 passing. Lint, prettier, tsc --noEmit all clean.
@cb-heimdall

Copy link
Copy Markdown

🟡 Heimdall Review Status

RequirementStatusMore Info
Reviews 🟡 0/1
Denominator calculation
Show calculation
1 if user is bot0
1 if user is external0
2 if repo is sensitive0
From .codeflow.yml1
Additional review requirements
Show calculation
Max0
0
From CODEOWNERS0
Global minimum0
Max 1
1
1 if commit is unverified0
Sum1

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

action providerNew action providerdocumentationImprovements or additions to documentationtypescript

Development

Successfully merging this pull request may close these issues.

2 participants

@giskard09@cb-heimdall
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(action-providers): add ActionRefVerify provider — recomputable, third-party-checkable reference for any declared action - #1459

Open
giskard09 wants to merge 1 commit into
coinbase:mainfrom
giskard09:feat/action-ref-verify-provider
Open

feat(action-providers): add ActionRefVerify provider — recomputable, third-party-checkable reference for any declared action#1459
giskard09 wants to merge 1 commit into
coinbase:mainfrom
giskard09:feat/action-ref-verify-provider

Conversation

@giskard09

Copy link
Copy Markdown

What this adds

A new, read-only action provider, ActionRefVerifyActionProvider — no wallet required, no transactions. Two actions:

  • compute_action_ref — derives action_ref, a deterministic content-addressed identifier (SHA-256 of RFC 8785 JCS canonicalization, action-ref-v1 spec) for a declared {agent_id, action_type, scope, timestamp}.
  • verify_action_ref_anchor — queries a public chain's RPC directly (Base, Arbitrum One, or Ink — same AnchorRegistry CREATE2 address on all three) for an Anchored(bytes32,address,uint256) event matching a given action_ref. Trusts nothing off-chain.

Why

X402ActionProvider.retryWithX402 dispatches a real x402 payment and, on success, reports {status: "success", details: {paymentUsed, paymentProof}}paymentProof decoded straight from the payment-response / x-payment-response header the facilitator sent back. That's the provider's own account of settlement. This provider does not close that boundary — it answers an adjacent, narrower question: given a declared request and result, can any third party — not just the facilitator — recompute a content-addressed identifier for that exact pair and confirm an independent, operator-external anchor timestamp, regardless of whether the underlying payment was accurately reported?

The same construction applies to any other action provider's declared input/output, not just x402 — this provider is intentionally generic, not specific to any single provider or protocol.

What it does NOT do

  • Does not verify that a declared action actually happened as described.
  • Does not evaluate whether an action was safe or advisable.
  • Does not sign, dispatch, or modify any transaction, payment, or other agent action.
  • Does not require any change to any other provider's API — it composes with any action's declared inputs/outputs after the fact.

Worked example

A full, independently-reproducible instance (derivation + a real on-chain anchor on Base mainnet, modeled on X402ActionProvider.retryWithX402) is published at giskard09/coinbase-x402-action-ref-anchor. It is explicitly a synthetic worked example — see that repo's PROVENANCE.md — no real wallet, no real x402 payment. Read it before using this provider against a real action.

Testing

6/6 tests passing (actionRefVerifyActionProvider.test.ts), including a byte-exact check against the published worked example's action_ref. pnpm lint, pnpm format:check, and tsc --noEmit all clean.

Read-only, no wallet, no transactions. Derives action_ref (action-ref-v1:
SHA-256 of RFC 8785 JCS over agent_id/action_type/scope/timestamp) for a
declared action, and independently checks the public chain for a matching
Anchored event against the permissionless AnchorRegistry contract.
Modeled on X402ActionProvider.retryWithX402's real request/response shape.
Full worked example (incl. a real on-chain anchor) at
github.com/giskard09/coinbase-x402-action-ref-anchor.
Tests: 6/6 passing. Lint, prettier, tsc --noEmit all clean.
@cb-heimdall

Copy link
Copy Markdown

🟡 Heimdall Review Status

RequirementStatusMore Info
Reviews 🟡 0/1
Denominator calculation
Show calculation
1 if user is bot0
1 if user is external0
2 if repo is sensitive0
From .codeflow.yml1
Additional review requirements
Show calculation
Max0
0
From CODEOWNERS0
Global minimum0
Max 1
1
1 if commit is unverified0
Sum1

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

action providerNew action providerdocumentationImprovements or additions to documentationtypescript

Development

Successfully merging this pull request may close these issues.

2 participants

@giskard09@cb-heimdall
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(action-providers): add ActionRefVerify provider — recomputable, third-party-checkable reference for any declared action - #1459

Open
giskard09 wants to merge 1 commit into
coinbase:mainfrom
giskard09:feat/action-ref-verify-provider
Open

feat(action-providers): add ActionRefVerify provider — recomputable, third-party-checkable reference for any declared action#1459
giskard09 wants to merge 1 commit into
coinbase:mainfrom
giskard09:feat/action-ref-verify-provider

Conversation

@giskard09

Copy link
Copy Markdown

What this adds

A new, read-only action provider, ActionRefVerifyActionProvider — no wallet required, no transactions. Two actions:

  • compute_action_ref — derives action_ref, a deterministic content-addressed identifier (SHA-256 of RFC 8785 JCS canonicalization, action-ref-v1 spec) for a declared {agent_id, action_type, scope, timestamp}.
  • verify_action_ref_anchor — queries a public chain's RPC directly (Base, Arbitrum One, or Ink — same AnchorRegistry CREATE2 address on all three) for an Anchored(bytes32,address,uint256) event matching a given action_ref. Trusts nothing off-chain.

Why

X402ActionProvider.retryWithX402 dispatches a real x402 payment and, on success, reports {status: "success", details: {paymentUsed, paymentProof}}paymentProof decoded straight from the payment-response / x-payment-response header the facilitator sent back. That's the provider's own account of settlement. This provider does not close that boundary — it answers an adjacent, narrower question: given a declared request and result, can any third party — not just the facilitator — recompute a content-addressed identifier for that exact pair and confirm an independent, operator-external anchor timestamp, regardless of whether the underlying payment was accurately reported?

The same construction applies to any other action provider's declared input/output, not just x402 — this provider is intentionally generic, not specific to any single provider or protocol.

What it does NOT do

  • Does not verify that a declared action actually happened as described.
  • Does not evaluate whether an action was safe or advisable.
  • Does not sign, dispatch, or modify any transaction, payment, or other agent action.
  • Does not require any change to any other provider's API — it composes with any action's declared inputs/outputs after the fact.

Worked example

A full, independently-reproducible instance (derivation + a real on-chain anchor on Base mainnet, modeled on X402ActionProvider.retryWithX402) is published at giskard09/coinbase-x402-action-ref-anchor. It is explicitly a synthetic worked example — see that repo's PROVENANCE.md — no real wallet, no real x402 payment. Read it before using this provider against a real action.

Testing

6/6 tests passing (actionRefVerifyActionProvider.test.ts), including a byte-exact check against the published worked example's action_ref. pnpm lint, pnpm format:check, and tsc --noEmit all clean.

Read-only, no wallet, no transactions. Derives action_ref (action-ref-v1:
SHA-256 of RFC 8785 JCS over agent_id/action_type/scope/timestamp) for a
declared action, and independently checks the public chain for a matching
Anchored event against the permissionless AnchorRegistry contract.
Modeled on X402ActionProvider.retryWithX402's real request/response shape.
Full worked example (incl. a real on-chain anchor) at
github.com/giskard09/coinbase-x402-action-ref-anchor.
Tests: 6/6 passing. Lint, prettier, tsc --noEmit all clean.
@cb-heimdall

Copy link
Copy Markdown

🟡 Heimdall Review Status

RequirementStatusMore Info
Reviews 🟡 0/1
Denominator calculation
Show calculation
1 if user is bot0
1 if user is external0
2 if repo is sensitive0
From .codeflow.yml1
Additional review requirements
Show calculation
Max0
0
From CODEOWNERS0
Global minimum0
Max 1
1
1 if commit is unverified0
Sum1

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

action providerNew action providerdocumentationImprovements or additions to documentationtypescript

Development

Successfully merging this pull request may close these issues.

2 participants

@giskard09@cb-heimdall
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

feat(action-providers): add ActionRefVerify provider — recomputable, third-party-checkable reference for any declared action - #1459

Open
giskard09 wants to merge 1 commit into
coinbase:mainfrom
giskard09:feat/action-ref-verify-provider
Open

feat(action-providers): add ActionRefVerify provider — recomputable, third-party-checkable reference for any declared action#1459
giskard09 wants to merge 1 commit into
coinbase:mainfrom
giskard09:feat/action-ref-verify-provider

Conversation

@giskard09

Copy link
Copy Markdown

What this adds

A new, read-only action provider, ActionRefVerifyActionProvider — no wallet required, no transactions. Two actions:

  • compute_action_ref — derives action_ref, a deterministic content-addressed identifier (SHA-256 of RFC 8785 JCS canonicalization, action-ref-v1 spec) for a declared {agent_id, action_type, scope, timestamp}.
  • verify_action_ref_anchor — queries a public chain's RPC directly (Base, Arbitrum One, or Ink — same AnchorRegistry CREATE2 address on all three) for an Anchored(bytes32,address,uint256) event matching a given action_ref. Trusts nothing off-chain.

Why

X402ActionProvider.retryWithX402 dispatches a real x402 payment and, on success, reports {status: "success", details: {paymentUsed, paymentProof}}paymentProof decoded straight from the payment-response / x-payment-response header the facilitator sent back. That's the provider's own account of settlement. This provider does not close that boundary — it answers an adjacent, narrower question: given a declared request and result, can any third party — not just the facilitator — recompute a content-addressed identifier for that exact pair and confirm an independent, operator-external anchor timestamp, regardless of whether the underlying payment was accurately reported?

The same construction applies to any other action provider's declared input/output, not just x402 — this provider is intentionally generic, not specific to any single provider or protocol.

What it does NOT do

  • Does not verify that a declared action actually happened as described.
  • Does not evaluate whether an action was safe or advisable.
  • Does not sign, dispatch, or modify any transaction, payment, or other agent action.
  • Does not require any change to any other provider's API — it composes with any action's declared inputs/outputs after the fact.

Worked example

A full, independently-reproducible instance (derivation + a real on-chain anchor on Base mainnet, modeled on X402ActionProvider.retryWithX402) is published at giskard09/coinbase-x402-action-ref-anchor. It is explicitly a synthetic worked example — see that repo's PROVENANCE.md — no real wallet, no real x402 payment. Read it before using this provider against a real action.

Testing

6/6 tests passing (actionRefVerifyActionProvider.test.ts), including a byte-exact check against the published worked example's action_ref. pnpm lint, pnpm format:check, and tsc --noEmit all clean.

Read-only, no wallet, no transactions. Derives action_ref (action-ref-v1:
SHA-256 of RFC 8785 JCS over agent_id/action_type/scope/timestamp) for a
declared action, and independently checks the public chain for a matching
Anchored event against the permissionless AnchorRegistry contract.
Modeled on X402ActionProvider.retryWithX402's real request/response shape.
Full worked example (incl. a real on-chain anchor) at
github.com/giskard09/coinbase-x402-action-ref-anchor.
Tests: 6/6 passing. Lint, prettier, tsc --noEmit all clean.
@cb-heimdall

Copy link
Copy Markdown

🟡 Heimdall Review Status

RequirementStatusMore Info
Reviews 🟡 0/1
Denominator calculation
Show calculation
1 if user is bot0
1 if user is external0
2 if repo is sensitive0
From .codeflow.yml1
Additional review requirements
Show calculation
Max0
0
From CODEOWNERS0
Global minimum0
Max 1
1
1 if commit is unverified0
Sum1

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

action providerNew action providerdocumentationImprovements or additions to documentationtypescript

Development

Successfully merging this pull request may close these issues.

2 participants

@giskard09@cb-heimdall