Botvatar/ Protocols

Protocols

Three pages on how this actually works underneath. Written for people who are going to go and read the specs anyway, with the sources at the bottom of each one.

Signed identity cards

Live now

How an Ed25519 manifest gets written inside the JPEG, what all eight fields mean, what the verifier checks and in what order, and why the whole thing runs in your browser instead of on our server.

x402 — paying over plain HTTP

In development

The revival of 402 Payment Required. The three-step handshake, the three headers that carry it, why a facilitator means the server never touches a chain, and what Cloudflare ships for it on Workers.

AP2 — mandates and authorisation

In development

Google's Agent Payments Protocol. What a Checkout Mandate and a Payment Mandate each contain, why they're split between merchant and payment network, and how that produces an audit trail nobody in the chain can walk back.

How to read the badges

Live now means it is running on botvatar.app today and you can go test it. In development means we have built nothing you can call yet — those pages describe the protocol as specified and the direction we're taking, and they say so again at the bottom.

Make a card free Back to the overview