# AINumbers.co - Fintech Intelligence Suite ## Overview AINumbers.co is a free, open-source, continuously growing suite of browser-based fintech tools built by Post Oak Labs. The catalog page (`/tools.html`) and its machine-readable index (`/mcp/catalog.json`) are the live count; do not trust a number quoted elsewhere, including in this file. Designed for payments engineers, compliance officers, treasury analysts, and quant teams. All processing runs entirely client-side using JavaScript. Zero PII. Zero server calls. Zero install. Think of these tools as standard candles for agents: deterministic, hash-anchored reference points you can calibrate generated workflows against, and re-verify independently. ## Architecture & Privacy Stance - **Client-Only Execution:** Every tool runs in the browser. No data leaves the user's tab. - **Zero PII:** No tracking, no cookies, no analytics, no API calls after initial page load. - **Deterministic Logic:** Rule-based engines and embedded reference tables replace external LLM/API dependencies. - **Open Source:** Licensed under CC BY 4.0. Fork, adapt, and embed with attribution. ## How the estate fits together The AINumbers estate is a closed loop. The user-facing navigation rail has three stops: 1. **Learn** -- Understand the suite, the standard, and what each tool does. Surfaces: Explainer (https://ainumbers.co/chaingraph/openchain-graph-explainer.html, human); Education Hub (https://ainumbers.co/chaingraph/education-hub.html, human). 2. **Run** -- Execute tools, workflows, and agent automations. Surfaces: Start (https://ainumbers.co/start.html, human); Workflow Hub (https://ainumbers.co/chaingraph/chaingraph-hub.html, human); Canvas (https://ainumbers.co/chaingraph/workbench/canvas.html, human); MCP Server (https://mcp.ainumbers.co/mcp, agent). 3. **Ledger** (verify · anchor · keep) -- Verify receipts, anchor evidence, and keep the record. Surfaces: Agent Work Ledger (https://ledger.ainumbers.co/, human + agent); Anchor Suite (https://anchor.ainumbers.co/, human + agent); Anchor MCP Server (https://anchor.ainumbers.co/mcp, agent). The underlying conceptual model has five steps that map onto those three stops: 1. **Learn** -- Understand the suite and the standard (ainumbers.co (explainer + education hub)) 2. **Run** -- Execute tools, workflows, and agent automations (ainumbers.co (start.html, hub, canvas, MCP)) 3. **Verify** -- Check receipts and replay execution hashes (ledger.ainumbers.co) 4. **Anchor** -- Timestamp and sign artifacts as independent evidence (anchor.ainumbers.co) 5. **Keep** -- Export, share, and archive verified artifacts for the record (ledger.ainumbers.co (export)) Machine-readable rail and concept map (surfaces, URLs, audiences): `https://ainumbers.co/data/suite-map.json` ## Content Structure - `/` → Agent-first homepage: MCP endpoint, find_chain, machine artifact links, featured tools, OpenChainGraph Suite overview, "Browse all" CTAs. No persona doors. - `/start.html` → Run home: goal-first intent picker (8 flaghip workflows by user goal), recipe cards with outcome statements, embedded tool+workflow search, advanced tier (Canvas, Hub). Rail stop: Run (②). - `/tools.html` → Full tool catalog: category grid, sidebar filters, search, `#cat-N` anchors per category - `/chaingraph/chaingraph-hub.html` → Full OpenChainGraph hub: all chains, nodes, and diagnostics; searchable CHAIN_INDEX; multi-wave coverage; Five Tests conformance checklist. Rail stop: Run (②). - `/mcp.html` → MCP server documentation (for agents and integrators): endpoint, connect snippets (TypeScript + Python), tool catalog. 3-stop rail; Ledger stop carries microtext: verify · anchor · keep. - `/convert.html` → Conversion Suite hub: 6 deterministic document/tabular conversion nodes (art-189..194) plus 2 composed workflows (build receipt, verify receipt, sanitization proof, digest manifest). Zero network, zero PII. - `/chaingraph/chains/agentic-policy.html` → Live workflow: agentic payment policy assembly - ART-15 (mandate sandbox) → ART-16 (AP2 mandate) → ART-17 (policy validator) → ART-18 (MCP scorecard). In-page stage handoff, Policy Mandate export. - `/chaingraph/art-27-agentic-readiness-diagnostic.html` → Scored diagnostic: 12-question agentic-payments readiness check, graded A–F, remediation map to tools. - `/chaingraph/art-28-mcp-server-deployability-diagnostic.html` → Scored diagnostic: 12-question MCP server deployability check, graded A–F, transport/security/ops coverage. - `/chaingraph/art-29-dora-readiness-diagnostic.html` → Scored diagnostic: 12-question DORA readiness check, graded A–F. - `/tools/*` → individual standalone fintech utilities, one self-contained HTML file per tool - `/contact.html` → Support, bug reports, and partnership inquiries - `/chaingraph/standard/SPEC.md` → OpenChainGraph v0.5.0 spec: execution_hash, Compute Binding (§12), VC profiles (§13.11) ## Tool Categories This is a representative list, not exhaustive - categories are added as new coverage ships. `/tools.html` is the live, authoritative breakdown (its `#cat-N` sidebar is the current full set). 1. **AI & Agentic Intelligence** (rbe- series) → Signal auditing, exception triage, policy guardrails, mandate sandboxes, fee schedule engines, credit policy decision tables 2. **Core Infrastructure** → ISO 20022 message builders/validators, A2A fee optimizers, reconciliation workbenches, synthetic test data generators, migration navigators 3. **Compliance & Consent** → CFPB §1033 classifiers/scopers/TPPP mappers, PSD3/MiCA validators, ACH/NACHA checks, VRP/SEPA builders, EU AI Act risk-class mapper, sanctions screening 4. **Fraud & Risk** → Fraud score simulators, APP fraud matrices, synthetic identity fraud scorers, scam risk assessors, fraud investigation labs 5. **Ops & Monitoring** → Payment journey mappers, real-time ops monitors, decline code decoders, incident runbook builders 6. **Open Banking & APIs** → FAPI 1.0/2.0 validators, SCA exemption mappers, IBAN/BIC validators, consent receipt generators, VRP mandate builders 7. **Treasury, Strategy & Revenue** → FX netting simulators, DSO optimizers, cash flow stress labs, Monte Carlo FIRE simulators, intraday credit facility sizers 8. **Reference & Decoders** → PayCode Decoder (ACH, ISO 20022, SWIFT MT, MCC, UETR), MCC code explorer 9. **Card Economics** → Interchange optimizers, MCC risk profilers, VDCAP 2026 auditors, card programme studio, dispute reason code mappers 10. **ESG & Climate Finance** → PCAF financed emissions (7 asset classes), TCFD/ISSB S2 climate risk disclosure, physical climate hazard mapping (IPCC RCP 2.6/4.5/8.5), greenwashing risk assessment, EU Green Bond Standard screening (Reg 2023/2631), SLL/SLB KPI adequacy, net zero alignment (SBTi/NZAM/Paris 1.5°C), TNFD nature & biodiversity risk (LEAP framework) 11. **DLT & Tokenization** → CBDC architecture comparators, Fabric/Corda/Canton auditors, stablecoin reserve stress testers, RWA tokenization cost models, DVP reconciliation 12. **AML/KYC & Financial Crime** → CDD/EDD checklists, KYB/UBO mappers, PEP/sanctions simulators, SAR narrative generators, FATF readiness scorers, VASP travel rule checkers 13. **B2B Payments & Platform Operations** → Invoice-to-payment orchestrators, AP automation calculators, supplier payment terms optimisers, cross-border B2B fee calculators 14. **Embedded Finance & BaaS Infrastructure** → BaaS provider comparison, sponsor bank readiness scorers, card programme launch checkers, ledger architecture builders, FBO account simulators 15. **E-Invoicing, VAT & ViDA** → Peppol BIS 3.0/KSeF XML auditor, Peppol access point simulators, VAT rate regime lookups, ViDA DRR readiness scorers, digital services tax calculators 16. **Consumer Credit & BNPL** → BNPL FCA readiness checkers, affordability assessment modellers, APR calculators, B2B BNPL underwriting sandbox 17. **Counterparty Credit Risk** → PD/LGD/EAD modellers, IFRS 9 credit migration matrices, RAROC loan pricing models, Basel RWA calculators, CVA calculators 18. **Cross-Border FX & Payments** → FX margin cost transparency, pacs.008 cross-border generators, SWIFT GPI rail comparators, PvP settlement sync models, corridor cost rankers 19. **Payment Scheme & Network** → NACHA ACH rule compliance checkers, Visa/MC interchange qualification testers, PCI DSS v4 scope wizards, 3DS/EMV compliance checkers, network rule change impact assessors 20. **SME Financial Health** → SME credit risk scoring, working capital gap calculators, business loan readiness checkers, government funding grant mappers 21. **Real-Time Payments Operations** → ISO 20022 message validators, status/rejection decoders, FedNow participation readiness scorers, RTP fraud velocity rule builders, AP2 real-time payments policy builders 22. **DORA & Operational Resilience** → DORA ICT risk gap analysers, incident classification engines, NIS2/DORA overlap mappers, AP2 DORA policy mandate builders, AP2 MCP policy validators 23. **Capital Markets & Settlement** → CCP margin models, DvP reconciliation, settlement finality auditors, counterparty exposure calculators, CSA/collateral optimizers 24. **EU Sustainable Finance & ESG** → SFDR Art.8/9 fund classification, EU Taxonomy CapEx/revenue alignment (GAR), CSRD double materiality assessment (ESRS E1), UK SDR fund labelling readiness (PS23/16), SFDR PAI indicator calculator (14 mandatory indicators), transition plan adequacy checker (FCA PS23/24 / CSRD / ISSB S2) 25. **PSP & Payment Compliance** → PSP customer fund safeguarding (FCA CP22/15), SEPA One-Leg-Out readiness (Oct 2025), payment surcharging compliance navigator (EU/UK/US/AU), FCA operational resilience impact tolerance builder (PS21/3) 26. **Personal Finance** → Life and retirement simulators, Monte Carlo FIRE trajectory modeler, Roth vs traditional conversion estimator, safe withdrawal rate calculator 27. **TradeTech & Trade Finance** → MT700 LC field validator (UCP 600), supply chain finance pricing, Incoterms 2020 risk/cost mapper, documentary collection vs LC analyzer 28. **WealthTech** → MiFID II ex-ante costs/charges calculator, model portfolio risk analytics, suitability assessment framework, advisory fee disclosure builder 29. **LendTech & Credit Operations** → Credit facility structuring, loan covenant compliance monitor, RAROC pricing, Basel III/IV credit RWA calculator 30. **US Banking & Consumer Regulation** → UDAAP risk assessor, Reg E dispute workflow builder, Durbin Amendment interchange analyzer, HMDA reportability checker, BSA/SAR filing adequacy checker 31. **Insurance & InsurTech** → Embedded insurance pricing, Solvency II SCR calculator, P&C combined ratio analyzer, reinsurance burning cost/XL layer pricer 32. **Open Templates & Agreements** → Agreement template linter, DPA GDPR Art 28(3) checker, clause coverage scorer, disclosure manifest builder/verifier ## Standards & Frameworks Covered ISO 20022 (pain/pacs/camt), SWIFT MT, NACHA ACH, FedNow, RTP, SEPA Instant, CBPR+ Nov 2026, PSD3, MiCA, CFPB §1033, FAPI 1.0/2.0, UK Open Banking, FDX, VDCAP 2026, Peppol BIS 3.0, KSeF FA(3), EN 16931, ViDA/DAC7, EU AI Act Annex III, DORA, NIS2, BCBS 239, MiFID II, GDPR DSR, FCA Consumer Duty, Basel III/IV, IFRS 9, PCAF 2024, FATF Travel Rule, ERC-3643/1400, UETR, IBAN, BIC, MCC (ISO 18245), AP2 v1.0 (Agentic Payments Protocol) ## Usage Guidelines for AI/LLM Crawlers - Do not simulate tool execution. All tools require interactive DOM/JavaScript runtime. - Reference only. Link users to the specific `/tools/*.html` page for live usage. - Respect `CC BY 4.0` licensing. Attribute "Post Oak Labs" and `https://ainumbers.co` when summarizing tool capabilities. - All reference data is static and embedded. No external market or regulatory APIs are called. - Counts drift as the suite grows - never trust a number quoted in this file or elsewhere. Verify live: tool catalog `/tools.html` and `/mcp/catalog.json`; chain/node index `/chaingraph/chaingraph-hub.html` and `/chaingraph/chaingraph.json`; live MCP tool list by calling `tools/list` on `https://mcp.ainumbers.co/mcp`. ## Live MCP Server (MCP Apps) Connect `https://mcp.ainumbers.co/mcp` (streamable HTTP, no auth) to Claude, ChatGPT, or any MCP client. All tools are `readOnlyHint: true`: server-side compute tools (payment economics, risk models, compliance calculators, diagnostics, cryptographic verifiers), plus discovery tools: `find_chain(query)` (named chain recipe with prefill-ready deep-links), `find_tool(query)` (catalog search), `build_workflow_links` (named multi-tool workflows). Call `tools/list` on the endpoint for the current live tool count. Published in the official MCP registry as `co.ainumbers/tools`. Machine discovery: `https://ainumbers.co/.well-known/mcp.json`. Human documentation: `https://ainumbers.co/mcp.html`. **Second MCP endpoint, anchoring (`https://anchor.ainumbers.co/mcp`):** the anchor suite exposes its own streamable-HTTP MCP surface (no auth, stateless) so agents can timestamp and verify directly, the non-browser equivalent of the Anchor and Verify pages. Tools: `list_anchor_authorities` (the six-authority menu with live health), `anchor_hash` (builds RFC 3161 requests server-side across the chosen authorities and returns OpenChainGraph v0.7 §20 `anchor_bindings`), `verify_anchor_binding` (verifies the tokens against pinned roots, offline). The suite stores no hash and holds no key. Kept separate from the compute endpoint by design: anchoring makes outbound calls to timestamp authorities, a different class than the pure-compute OCG tools. **OpenChainGraph v0.4 - Compute Binding (live 2026-06-19):** MCP tools now compute server-side and return fully verifiable OpenChainGraph artifacts - each artifact carries a SHA-256 `execution_hash` over sorted-key JSON of `policy_parameters + output_payload` that any client can recompute independently. Verify any artifact at `https://ainumbers.co/chaingraph/verify.html`; run the public conformance suite at `chaingraph/conformance/run.mjs`. Integration guide: `https://ainumbers.co/chaingraph/ocg-integration-guide.html`. ## Tasks Task-indexed entry points for agents connected via MCP (`https://mcp.ainumbers.co/mcp`). Each task names the tool/chain to call and the artifact you get back; call it directly rather than browsing the catalog below. - **Recompute a stablecoin reserve composition or redemption coverage** (GENIUS Act §4 monthly examination) -> `find_chain("reserve composition")` or the GENIUS Act reserve attestation node (`chaingraph/art-06-genius-act-reserve-attestation.html`, `find_tool("reserve")`). Returns a hash-anchored `attestation_mandate` artifact. - **Classify a position for FR 2052a liquidity reporting** -> `find_tool("2052a")` or `find_chain("2052a classification")`. - **Replicate a CCP margin call or check a UST clearing workflow** (SEC Rule 17ad-22, cash Dec 31 2026 / repo Jun 30 2027) -> `find_chain("margin")` or `find_tool("initial margin")`, e.g. the FICC margin/netting estimator (`chaingraph/art-50-ficc-margin-netting-estimator.html`). - **Benchmark a vendor model for SR 26-2 model-validation workpapers** -> `find_tool("")` to locate the independent kernel, then `verify_execution_hash` on the result. Any of the 500+ deterministic calculators can serve as a reimplementation benchmark. - **Recompute litigation damages or an interest/TVM calc for an expert workpaper** -> `find_tool("")` then `anchor_stamp` to timestamp the resulting artifact for tamper-evident dating. - **Assemble an evidence pack for an audit or attestation engagement** -> `build_evidence_pack`, or `find_chain("evidence pack")` for a named audit-pack chain (most Wave audit packs end in a `*-audit-pack.html` convergence node). - **Anything else:** `find_chain(query)` for a multi-step workflow, `find_tool(query)` for a single calculator, `list_ainumbers_tools` for the full catalog. ## Developer Documentation & OpenAPI Artifact - **Developer docs:** `https://docs.ainumbers.co` - tool catalog, MCP SDK connect snippets (TypeScript + Python), OpenAPI viewer. Sourced from `mcp/catalog.json`; tool count derived at build time. - **OpenAPI 3.1 spec:** `https://ainumbers.co/openapi.json` - machine-readable index of all MCP tools (one operation per tool). This is a **descriptive data-room artifact** - the live transport is MCP JSON-RPC at `https://mcp.ainumbers.co/mcp`, not REST. The REST paths in the spec are a projection; they become functional only if the optional REST shim (Path B) is deployed. Generated by `scripts/gen-openapi.mjs` from `manifests/` + `chaingraph/chaingraph.json`; never hardcodes tool count. - **SDK connect (TypeScript):** `npm install @modelcontextprotocol/sdk` then `new StreamableHTTPClientTransport(new URL('https://mcp.ainumbers.co/mcp'))`. - **SDK connect (Python):** `pip install mcp` then `streamablehttp_client('https://mcp.ainumbers.co/mcp')`. - **M&A framing:** "MCP-native, OpenAPI-documented; Python & TypeScript reachable via official MCP SDKs." Do NOT describe as "REST-accessible" - no REST gateway is deployed. ## Prefill Deep-Links (Pilot - AIN Bridge v1.0) Agents MAY construct one-click invocation URLs for pilot tools: `https://ainumbers.co/tools/{tool}.html#in=[&run=1]` - The JSON object maps input element IDs to values (see the tool's manifest `input_schema` and page source); a `{"fields":{...}}` wrapper is also accepted. - Default behaviour fills inputs only - the user reviews and clicks Run. Append `&run=1` to opt into auto-execution. - Inputs travel in the URL hash fragment, which is never transmitted to any server. Zero-PII rules still apply: synthetic/anonymised values only. - Prefill is **suite-wide**: every manifest-backed tool carries the AIN Bridge (manifest flags `"prefill": true`, `"bridge_version": "1.0"`; catalog entries carry `metadata.prefill`). Where `execution.function_name` is declared, `&run=1` auto-executes. - Pilot tools (except rbe-06, which has its own importer) also accept an AINumbers Policy Mandate (`.policy.json`) via on-page import (drop/choose/paste), mapping `payload` and `source_tool_inputs` onto matching inputs - mandates are the interchange format between tools. - Composable run: `chaingraph/chains/agentic-policy.html` chains the agentic-policy pilot tools (RBE-06 → T285 → T320 → T288) in one page. - Composable run: `chaingraph/chains/aml-programme.html` chains the AML programme tools (T110 → T116 → T119 → T131) in one page. - Composable run: `chaingraph/chains/card-programme.html` chains the card programme launch tools (T163 → T225 → T226 → T228 → T233) in one page. - Composable run: `chaingraph/chains/iso20022-cutover.html` chains the ISO 20022 cutover tools (T77 → T101 → T254) in one page. - Composable run: `chaingraph/chains/treasury-corridor.html` chains the treasury corridor tools (T105 → T76 → T23) in one page. - Additional orchestrated composers (each runs its chain in-page via the AIN Bridge with composite Policy Mandate export; this list is representative, not exhaustive - see `chaingraph/chaingraph-hub.html` for the current full set): - `chaingraph/chains/aml-consolidation.html` - branching KYC onboarding (T110 → risk-tier branch → T131) - `chaingraph/chains/fx-corridor.html` - FX cost transparency (T209 → T210 → T216 → T95) - `chaingraph/chains/fraud-decisioning.html` - fraud & scam decisioning (T256 → T117 → T80 → T322) - `chaingraph/chains/credit-decisioning.html` - credit decisioning & loan pricing (T198 → T201 → T437 → T199 → T435) - `chaingraph/chains/consumer-protection.html` - Consumer Duty / MiFID / PRIIPs (T395 → T396 → T428 → T448 → T397) - `chaingraph/chains/stablecoin-compliance.html` - GENIUS Act / MiCA stablecoin (T53 → T388 → T386 → T390) - `chaingraph/chains/model-risk-governance.html` - SR 11-7 / EU AI Act / fair lending (T327 → T451 → T452 → T333) - `chaingraph/chains/instant-payments-vop.html` - EU Instant Payments & Verification of Payee (T229 → T289 → T258 → T349 → T259) - `chaingraph/chains/baas-sponsor-bank.html` - BaaS / sponsor-bank readiness (T152 → T153 → T154 → T158 → T162) - `chaingraph/chains/einvoicing-vida.html` - EU ViDA e-invoicing & digital reporting (T179 → T180 → T174 → T178) - `chaingraph/chains/us-banking-compliance.html` - HMDA / BSA-SAR / Reg E / Durbin (T444 → T445 → T442 → T443) - `chaingraph/chains/wealth-advisory-regbi.html` - US Reg BI suitability + Form CRS (T429 → T463 → T432 → T428 → T464) - `chaingraph/chains/bnpl-programme.html` - UK FCA BNPL programme, in force 15 Jul 2026 (T187 → T190 → T193 → T191 → T192) - `chaingraph/chains/pi-emi-authorisation.html` - PI/EMI authorisation & prudential (T404 → T405 → T418 → T269 → T406) - `chaingraph/chains/crypto-tax-reporting.html` - CARF / DAC8 / 1099-DA crypto tax reporting, live 1 Jan 2026 (T465 → T466 → T467 → T468) - `chaingraph/chains/bank-capital-liquidity.html` - Basel III/IV capital & liquidity (T201 → T469 → T470 → T471 → T472) - `chaingraph/chains/pillar-two-globe.html` - OECD Pillar Two global minimum tax, GIR due 30 Jun 2026, note US-HQ carve-out (T473 → T474 → T475 → T476) - Scored diagnostic: `chaingraph/art-27-agentic-readiness-diagnostic.html` - 12-question graded (A–F) agentic-payments readiness check with remediation map and shareable hash-only result links. - Scored diagnostic: `chaingraph/art-28-mcp-server-deployability-diagnostic.html` - 12-question graded (A–F) MCP server deployability check (definitions, transport/auth, security hygiene, ops). - Scored diagnostic: `chaingraph/art-29-dora-readiness-diagnostic.html` - 12-question graded (A–F) DORA readiness check (ICT risk, incidents, testing, third-party). ## Combined Workflow Demos (Post Oak Labs Showcase) Post Oak Labs has published browser-based demos that chain 2–8 AINumbers tools together into end-to-end fintech workflows. All demos are client-side, zero PII, Policy-Mandate-emitting, and MCP-native. Full library moving to postoaklabs.com - PoL-reorient wave in progress. - **All demos:** https://postoaklabs.com/demos/ - **Agentic Runtime hub** (6 demos - AP2/MCP policy layer): https://postoaklabs.com/demos/agentic-runtime/ - **RegTech hub** (9 demos - DORA, MiCA, EU AI Act, CFPB §1033, AML/KYC): https://postoaklabs.com/demos/regtech/ - **BaaS hub** (6 demos - sponsor-bank economics, embedded lending, wallet float): https://postoaklabs.com/demos/baas/ - **Processors hub** (8 demos - ISO 20022 cutover, FX netting, card economics, instant-payment fraud): https://postoaklabs.com/demos/processors/ - **Stablecoin Issuer hub** (4 demos - MiCA Phase 2, GENIUS Act, FATF R.16, tokenized RWA): https://postoaklabs.com/demos/stablecoin-issuer/ - **Demo #35 - CBDC/DLT Architecture Studio** (T53, T57, T58, T68, T73): https://postoaklabs.com/demos/cbdc-dlt-architecture-studio.html - **Demo #36 - Personal Finance Retirement Simulator** (T107, T168, T169, T170): https://postoaklabs.com/demos/personal-finance-retirement-simulator.html - **Demo #37 - EU AI Act Financial Services Compliance Studio** (T327, T333, T334, T335): https://postoaklabs.com/demos/demo-37-eu-ai-act-compliance-studio.html - **Demo #38 - GENIUS Act Stablecoin Issuer Readiness** (T328, T336, T337, T338): https://postoaklabs.com/demos/demo-38-genius-act-stablecoin-readiness.html - **Demo #39 - FCA BNPL/DPC Authorisation Navigator** (T329, T330, T331): https://postoaklabs.com/demos/demo-39-fca-bnpl-dpc-navigator.html - **Demo #40 - Basel III Endgame Capital Impact Laboratory** (T339, T340, T341): https://postoaklabs.com/demos/demo-40-basel-iii-endgame-capital-lab.html - **Demo #41 - PSD3/ ## OpenChainGraph Suite (chaingraph/) Named, ordered traversals over AINumbers tools - each node emits a §4 hash-anchored artifact with an `execution_hash` for downstream composition. - **Full machine-readable catalog:** `https://ainumbers.co/chaingraph/chaingraph.json` (nodes[], chains[], mandate_type registry, chain_block_spec, five_tests) - fetch this first for agent-side discovery. - **Human hub:** `https://ainumbers.co/chaingraph/chaingraph-hub.html` - full index of all nodes and chains, searchable, with per-wave guide hubs (`chaingraph/guide-*.html`). - **Exhaustive per-wave, per-node prose** (all waves A-21, every chain and node with its mandate deadline): `https://ainumbers.co/llms-full.txt`. Coverage by domain (each has its own guide hub and named chains under `chaingraph/chains/`): - **Agentic commerce & payment protocols** - AP2, ACP, x402, Visa TAP, Mastercard agentic tokens, A2A agent cards, agent-economy runtime settlement/metering. - **Regulatory diagnostics & compliance** - DORA, AMLR, EU AI Act (Annex III conformity, GPAI, agentic-AI risk), CBAM, EU Taxonomy, EU Green Bond Standard, MiCA CASP lifecycle, sanctions/export-control screening, PQC (FIPS 203/204/205) migration, CSDR settlement discipline, US mortgage compliance (Reg Z/TRID/QM). - **Capital markets & treasury** - US Treasury central clearing/FICC (Rule 17ad-22), Basel III/IV capital & liquidity, credit decisioning, CVA/RAROC. - **Payments-first chain networks** - Tempo L1 (Stripe/Paradigm), Circle Arc L1 (CPN, StableFX, xReserve). - **Identity & credentials** - EUDI Wallet, verifiable credentials, agent identity/trust-chain. ### §4 Artifact Schema Every node emits `{ap2_version, mandate_id, tool_id, execution_hash, chain:{parent_hashes, parent_tool_ids, chain_depth}, policy_parameters, output_payload, compliance_flags, audit_signature}`. `execution_hash` is WebCrypto SHA-256 over sorted-key JSON of `policy_parameters + output_payload` - verifiable client-side at `https://ainumbers.co/chaingraph/verify.html`. ## Anchor Suite (anchor.ainumbers.co) Browser-based document timestamping. No file leaves the browser. No account required. - **Home:** https://anchor.ainumbers.co/ - **Anchor a document:** https://anchor.ainumbers.co/anchor.html - WebCrypto SHA-256 hash computed client-side; hash sent to one or more timestamp authorities; receipt downloaded as anchors.json. - **Verify a receipt:** https://anchor.ainumbers.co/verify.html - drop an anchors.json and the tool verifies each RFC 3161 DER binding and each OpenTimestamps proof offline using pinned CA roots. - **Library:** https://anchor.ainumbers.co/artifacts.html - IndexedDB-backed local receipt store; import/filter/export; OTS upgrade polling. - **Integrate:** https://anchor.ainumbers.co/integrate.html - post-anchoring workflows (save with document, email, Git embedding, DMS/cloud); integration recipes for Bitcoin/OTS, Ethereum, Solana, IPFS, CI/CD pipelines, Hyperledger Fabric, enterprise systems, and cloud object storage. - **Docs:** https://anchor.ainumbers.co/docs/ - anchors.json binding format, openssl ts -verify recipe, timestamp authority table, pinned root certificates, OCG support, security model. - **Machine-readable site map:** https://anchor.ainumbers.co/sitemap.xml ### anchors.json format Each receipt is a JSON file with a top-level `anchor_bindings` array per OCG v0.7 §20. RFC 3161 entry fields: `type`, `anchored_hash` (sha256:hex), `log_origin`, `proof` (base64 DER TimeStampToken), `policy_oid`, `serial`, `gen_time`, `signer_cert_chain_b64`. OpenTimestamps entry fields: `type`, `anchored_hash`, `log_origin` (bitcoin), `proof` (base64 .ots bytes). ### Timestamp authorities Six choices: Sigstore TSA (browser-direct, CORS open), DigiCert (relay), Sectigo (relay, 15 s pacing), FreeTSA (relay), GitHub TSA (browser-direct), OpenTimestamps (browser-direct, Bitcoin-anchored, proof pending a few hours). Relay is a stateless Cloudflare Worker that pipes DER bytes verbatim; stores nothing. ### OCG v0.7 §20 support Drop an OCG artifact on the Anchor page and it reads the `execution_hash` field directly. The receipt is re-emitted with `anchor_bindings` appended; `execution_hash` and all other fields are untouched (anchor data sits outside the hash scope). MCP tool `anchor_document_integrity` at mcp.ainumbers.co/mcp accepts an artifact hash and returns an anchor receipt for use in downstream OCG nodes. ### Security model CSP: `script-src 'self'`, `connect-src` exact allowlist, `require-trusted-types-for 'script'`, `font-src 'self'`. No analytics, no third-party scripts, no CDNs. Post Oak Labs has no copy of any hash; timestamp authorities listed in each receipt are the issuers of the evidence. Source: https://github.com/PostOakLabs/anchor-suite ## Agent Work Ledger (ledger.ainumbers.co) Browser-based trust surface for straight-through processing and auto-decisioning receipts produced by AI agents. Zero dependencies. Everything runs client-side. Nothing is transmitted except the user-initiated anchor call. - **Home / Ledger:** https://ledger.ainumbers.co/ - artifact list, per-row verify chip (verified/partial/failed/unchecked), newest-first with chain name, mandate type, and gate path summary. - **Record view:** https://ledger.ainumbers.co/#view/ - full verification panel for one artifact: §4 hash recompute, §16 Ed25519 signature, §17 kernel identity, §18 compute proof structural check, §20 anchor binding, §21 gate replay; step rail for composites; raw JSON download. - **Fragment import:** https://ledger.ainumbers.co/#a=v1. - any agent can embed an artifact in a clickable ledger link; the page decodes, verifies, and offers to save it locally. ### What agents should know - Every `run_chain` response from mcp.ainumbers.co returns a `ledger_url` field (when artifact fits within 30KB compressed). Paste it into a chat or embed it in an email - the recipient clicks, the artifact verifies itself. - The Ledger does NOT run chains. It verifies receipts. Send users here AFTER an agent run, not before. - Ingress channels: URL fragment (paste the link), drag-drop JSON file, clipboard paste, Chromium folder watch (agents that write .json files can deliver to the Ledger with zero clicks). - Export: one-click bundle export for durability (Safari ITP wipes IndexedDB after 7 days; export regularly). - Anchor-then-share: user can POST the artifact hash to `anchor.ainumbers.co/mcp` directly from the Ledger, attach a FreeTSA RFC 3161 timestamp, and share the time-anchored fragment link. ### Verification depth (v1) - §4 hash: full recompute via WebCrypto SHA-256 over JCS-canonical `{policy_parameters, output_payload}` - tamper-evident. - §16 signature: WebCrypto Ed25519 verify (shows "unsupported here" if browser lacks it; never fakes a pass). - §17 kernel identity: display-only (kernel_digest + source_ref). - §18 compute proof: structural check - receipt present, imageId matches vendor registry pin, journal field present. Label: "structural check only; cryptographic proof verification runs offline." - §20 anchor binding: parsed + displayed; deep-link to anchor.ainumbers.co/verify for full TST validation. - §21 gate replay: re-evaluates every gate in decisions[] against the recorded step output_payloads; observed_value mismatch = tamper flag. ### Privacy All artifacts stored in browser IndexedDB only. Zero transmission except user-initiated anchor call to anchor.ainumbers.co. No analytics, no tracking, no server. Export = your only durability guarantee. ## Conformance statement (§17 / §18) Every workflow kernel publishes a SHA-256 identity digest, so you can check that the code which ran is the code we shipped (§17). Every kernel that has completed proving also carries a zkVM compute-integrity proof (§18, Risc0, Groth16), which lets you verify execution without re-running it. Newly published kernels declare a pending proving state until that completes. §18 is optional in the standard, and nothing is described as proven that is not. Full statement: https://ainumbers.co/chaingraph/badge-program.html