{
  "tool_id": "art-596-ap2-x402-cart-correlation",
  "kernel_id": "art-596-ap2-x402-cart-correlation",
  "display_name": "Ap2 X402 Cart Correlation",
  "tool_version": "1.0.0",
  "mandate_type": "compliance_control",
  "purpose": "Correlates a built AP2 CartMandate (cart_root, cart_items, merchant) against an x402_spend_evidence pack: does the cart total (sum of quantity*unit_price per currency) match the x402 authorization's value, does the CartMandate's merchant map to the authorization's recipient address, and does the CartMandate's own hash-chain independently re-verify against the supplied cart_items (never trusted as a self-reported flag). Output vocabulary is CORRELATION_STATUS (CORRELATED / NOT_CORRELATED / INDETERMINATE) -- this is a plausibility check over two independently-produced artifacts, never a cryptographic binding. Google has not shipped an AP2-compatible x402 extension; no field or code path here implies one exists. Zero network calls; never a facilitator, proxy, gateway, or settlement relay.",
  "control_description": "Correlates a built AP2 CartMandate (cart_root, cart_items, merchant) against an x402_spend_evidence pack: does the cart total (sum of quantity*unit_price per currency) match the x402 authorization's value, does the CartMandate's merchant map to the authorization's recipient address, and does the CartMandate's own hash-chain independently re-verify against the supplied cart_items (never trusted as a self-reported flag). Output vocabulary is CORRELATION_STATUS (CORRELATED / NOT_CORRELATED / INDETERMINATE) -- this is a plausibility check over two independently-produced artifacts, never a cryptographic binding. Google has not shipped an AP2-compatible x402 extension; no field or code path here implies one exists. Zero network calls; never a facilitator, proxy, gateway, or settlement relay.",
  "declared_inputs": [
    "art-595-ap2-cartmandate-hashchain-builder"
  ],
  "declared_outputs": [],
  "kernel_digest": "sha256:bd768b21783024010879049cb1560f975da0ac0a210a9fde5da62dca74523c81",
  "trust_label": "independently verified: zkVM execution proof (risc0/groth16-bn254)",
  "data_vintage": "2026-08-21",
  "last_validated": "2026-08-21",
  "conformance_fixtures_vendored": true,
  "compute_proof_ready": "ready",
  "wave": 107,
  "source_url": "https://ainumbers.co/chaingraph/art-596-ap2-x402-cart-correlation.html",
  "generated_at": "2026-08-22T18:50:53.805Z"
}
