Botvatar/ Protocols
Protocols
Three pages on how this actually works underneath. Written for people who are going to go and read the specs anyway, with the sources at the bottom of each one.
Signed identity cards
Live nowHow an Ed25519 manifest gets written inside the JPEG, what all eight fields mean, what the verifier checks and in what order, and why the whole thing runs in your browser instead of on our server.
x402 — paying over plain HTTP
In development
The revival of 402 Payment Required. The three-step handshake, the
three headers that carry it, why a facilitator means the server never touches a
chain, and what Cloudflare ships for it on Workers.
AP2 — mandates and authorisation
In developmentGoogle's Agent Payments Protocol. What a Checkout Mandate and a Payment Mandate each contain, why they're split between merchant and payment network, and how that produces an audit trail nobody in the chain can walk back.
Live now means it is running on botvatar.app today and you can go test it. In development means we have built nothing you can call yet — those pages describe the protocol as specified and the direction we're taking, and they say so again at the bottom.