{
  "tool_id": "art-565-kya-x402-scope-verifier",
  "kernel_id": "art-565-kya-x402-scope-verifier",
  "display_name": "KYA Credential x x402 Payload Scope Verifier",
  "tool_version": "1.0.0",
  "mandate_type": "compliance_mandate",
  "purpose": "Cross-checks a declared KYA (Know Your Agent) credential's scope against a declared x402 PaymentPayload: amount vs the credential's spend cap, network/asset vs its allowed set, payee vs its merchant allowlist, validity window vs the payload's timestamps, and scope-string coverage of the payment scheme. Returns findings[] and a verdict of IN_SCOPE, OUT_OF_SCOPE, or INDETERMINATE (when the credential omits a claim the payload requires -- never guessed). Verify-only: never fetches either input, never contacts Skyfire or a facilitator, performs no signature verification, and never initiates or settles an x402 payment.",
  "control_description": "Cross-checks a declared KYA (Know Your Agent) credential's scope against a declared x402 PaymentPayload: amount vs the credential's spend cap, network/asset vs its allowed set, payee vs its merchant allowlist, validity window vs the payload's timestamps, and scope-string coverage of the payment scheme. Returns findings[] and a verdict of IN_SCOPE, OUT_OF_SCOPE, or INDETERMINATE (when the credential omits a claim the payload requires -- never guessed). Verify-only: never fetches either input, never contacts Skyfire or a facilitator, performs no signature verification, and never initiates or settles an x402 payment.",
  "declared_inputs": [],
  "declared_outputs": [],
  "kernel_digest": "sha256:f6c593e542fe2fbd5e4226a231dff7ce88a280d8fa68cc757c9fe6602afe29f3",
  "trust_label": "independently verified: zkVM execution proof (risc0/groth16-bn254)",
  "data_vintage": "2026-08-07",
  "last_validated": "2026-08-07",
  "conformance_fixtures_vendored": true,
  "compute_proof_ready": "ready",
  "wave": 92,
  "source_url": "https://ainumbers.co/chaingraph/art-565-kya-x402-scope-verifier.html",
  "generated_at": "2026-08-15T11:12:17.704Z"
}
