{
  "tool_id": "art-592-x402-domain-nonce-window-checker",
  "kernel_id": "art-592-x402-domain-nonce-window-checker",
  "display_name": "x402 Domain & Nonce Window Checker",
  "tool_version": "1.0.0",
  "mandate_type": "compliance_control",
  "purpose": "Checks an EIP-3009 TransferWithAuthorization's domain separation and replay-defense-adjacent fields against caller-supplied expectations. Takes expected_chain_id and expected_verifying_contract as separate, mandatory policy parameters -- distinct from the chainId/verifyingContract actually baked into the signed domain -- and refuses hard (never a soft warning) on either mismatch, the cross-domain replay defect class EIP-712 domain separation exists to prevent. Also checks the validAfter/validBefore window against a caller-supplied now_unix, and the nonce's format (bytes32, non-zero). Accepts an optional caller-supplied nonce_already_used boolean computed against the caller's own on-chain record; this kernel never queries a chain, so on-chain nonce uniqueness is enforced by the token contract at settlement time, not by this verifier. Zero network calls; never a facilitator, proxy, or settlement relay.",
  "control_description": "Checks an EIP-3009 TransferWithAuthorization's domain separation and replay-defense-adjacent fields against caller-supplied expectations. Takes expected_chain_id and expected_verifying_contract as separate, mandatory policy parameters -- distinct from the chainId/verifyingContract actually baked into the signed domain -- and refuses hard (never a soft warning) on either mismatch, the cross-domain replay defect class EIP-712 domain separation exists to prevent. Also checks the validAfter/validBefore window against a caller-supplied now_unix, and the nonce's format (bytes32, non-zero). Accepts an optional caller-supplied nonce_already_used boolean computed against the caller's own on-chain record; this kernel never queries a chain, so on-chain nonce uniqueness is enforced by the token contract at settlement time, not by this verifier. Zero network calls; never a facilitator, proxy, or settlement relay.",
  "declared_inputs": [],
  "declared_outputs": [],
  "kernel_digest": "sha256:b38255c8483b8792648d21f7a06a061fa24aaaea6ffce83ffb9c9b340afab72a",
  "trust_label": "independently verified: zkVM execution proof (risc0/groth16-bn254)",
  "data_vintage": "2026-08-11",
  "last_validated": "2026-08-11",
  "conformance_fixtures_vendored": true,
  "compute_proof_ready": "ready",
  "wave": 99,
  "source_url": "https://ainumbers.co/chaingraph/art-592-x402-domain-nonce-window-checker.html",
  "generated_at": "2026-08-15T11:12:17.704Z"
}
