tp tate@programs proof online
tate@programs ~/proof/case-files public work log

Public proof of work

Public proof for agent-commerce, paid API, and MCP launch work.

These are real public assets: merged patches, payment-surface reviews, npm packages, GitHub Actions, MCP registry publishing, and launch workflows. They show the kind of scoped proof Tate Programs can repeat for founders, agencies, and commerce teams.

Current proof trail

x402 launch checks that changed public payment surfaces.

Open x402 Surface Check
May 26

AgentScrape launch validation quote approved

HSH Intelligence approved public attribution after two no-payment readbacks helped close x402 and MCP launch-surface gaps. The quote is now usable in sales material without implying a paid engagement.

The reverse-engineering style of your check, with no payment, no signatures, and no paid calls, is the right shape for launch validation.
AgentScrape repo public close-out
May 22

Commercial proof buyers can verify quickly

Recent public work now maps directly to the paid offer: agent-payment spend controls, browser-readable x402 challenges, non-cacheable paid-action receipts, AgentCore payment lifecycle checks, origin-safe UCP server middleware, official UCP example validation, ACP delegate-auth schema validation, NVIDIA Retail Agentic Commerce A2A documentation, mppx x402 resource-binding verification, Apify MCP task-mode payment guard review, Fireblocks x402 preview flow, Bazaar metadata guidance, MCP payment metadata, Universal Cart header paths, and registry-ready API specs. This is the proof base behind the $750 readiness maps and $2,500+ launch sprints.

Shopify UCP catch Shopify maintainer credit Shopware UCP re-check Shopware Google feed patch ToolRouter StableTravel re-check Resonate x402 no-store PR CommandLayer receipt PR AWS AgentCore re-check UCP Go SDK CORS PR Official UCP validation PR ACP delegate-auth PR NVIDIA UCP A2A docs PR mppx resource-binding re-check Apify task-mode guard note x402trace Bazaar PR Fireblocks x402 agent PR Boson x402B paywall close Apify MCP x402 PR merged Nansen pay-skills PR merged DCP spend accounting merged
May 22

Resonate and CommandLayer payment-receipt patches

Two fresh PRs target the same launch-risk class from different angles: x402 402 challenges should not be cached, and paid-action receipt/error responses should not be cached. Both patches include focused local tests.

Resonate PR #913 CommandLayer PR #293
May 22

AWS AgentCore payment lifecycle re-check

An AgentCore Pay for Data sample was updated after a public lifecycle note. The re-check confirms host-side catalog sync no longer requires payment-session environment variables.

AWS AgentCore re-check
May 22

UCP Go SDK origin-safe CORS patch

A Universal Commerce Protocol server middleware PR adds Vary: Origin when allowed origins are reflected, so shared caches do not reuse another agent or platform origin's CORS policy. Full Go tests pass.

UCP Go SDK PR #1
May 22

Official UCP example validation cleanup

An official Universal Commerce Protocol PR makes the lightweight example-validation test harness report missing optional ucp-schema coverage as skipped instead of failed, matching the test contract.

Official UCP PR #477
May 22

Agentic Commerce Protocol delegate-auth schema patch

An official ACP PR fixes result-bearing delegate-authentication examples that were rejected by schema composition, then maps delegate-auth and feed examples into the consistency validator.

ACP PR #261
May 22

NVIDIA Retail Agentic Commerce UCP A2A alignment

A NVIDIA AI Blueprint PR aligns the architecture, PRD, feature summary, and agent guide with the implemented UCP A2A checkout transport after REST checkout routes were removed.

NVIDIA PR #111
May 22

mppx x402 exact resource-binding re-check

After a public source-readback note, mppx added route-resource binding before facilitator verification. A local no-payment script confirmed cross-resource replay rejects with 402 while same-resource settlement proceeds.

mppx re-check
May 22

Apify MCP task-mode x402 guard readback

An Apify MCP server PR now has a source-readback note on a task-mode path where a standby Actor can still reach a generic 402 task result before the new precise standby rejection runs.

Apify PR #893 note
May 22

x402trace Bazaar body-discovery guidance

The x402trace validator now has a PR keeping body-discovery failure remediation aligned with info.input, info.output, and schema instead of sending API-style services toward MCP-style name/description fields.

x402trace PR #80
May 22

Fireblocks x402 payment-info preview patch

A Fireblocks x402 agent PR keeps the preview-only x402_get_payment_info tool from querying vault balances, so teams can inspect public 402 requirements before configuring Fireblocks signing credentials.

Fireblocks PR #2
May 22

Shopify, Shopware, and ToolRouter public proof

High-signal public loops landed the same day: Shopify's UCP CLI merged a custom-header discovery fix, Shopware corrected UCP order-proof URLs away from localhost, Shopware added Google feed validator coverage, and ToolRouter's StableTravel x402 PR merged after wrapper tests passed.

Shopify merged PR Shopware fixed re-check Shopware feed patch ToolRouter merged PR
buyer fit

What this proves for agentic commerce teams

When agents buy, call paid APIs, or pass through Universal Cart/UCP-style checkout, the launch risk is practical: challenge readability, retry headers, cache behavior, payee/resource binding, receipt shape, amount caps, and post-payment reconciliation.

Agent Commerce Readiness Sprint Universal Cart readiness
live paid

tools402 seller endpoint

Tate Programs is now listed in the tools402 public catalog with a $0.01 proxy-mode readiness snapshot. No-payment calls return a valid 402 challenge, and the upstream stays probe-safe for marketplace health checks.

tools402 public meta paid endpoint
May 21

Universal Cart / UCP public sample

The free checker now has a captured Allbirds sample report: UCP profile, agent docs, MCP endpoint behavior, agentic sitemap, product/policy schema gaps, and the exact line between public discovery and private checkout proof.

Allbirds UCP sample run the checker
new

May 20-21 patch loops

Same-day checks closed the loop on provider fixes and live PRs: Blocksize closed resource, browser-readability, exposed-header, and no-store notes; Carbon Cashmere shipped a flat 177-endpoint manifest; Nevermined's Python Visa/x402 mirror exposed a provider-type regression in CI; and Dynamic's auto-fund path got a spend-control review before merge.

Blocksize final clean re-check Carbon final clean re-check Crest re-check Phoenix re-check Mameta launch review Mameta patch re-check Nevermined Python CI note Dynamic auto-fund note
new

Tate Programs Bazaar discovery

The live paid endpoints were patched so Agentic Market's seller validator accepts the Bazaar discovery metadata. Triage, index watch, skill trust, and A2A all now parse cleanly and enter discovery processing.

Agentic Market validator
merged

DCP auto-approved spend accounting

A desktop payment protocol PR fixed auto-approved spend accounting for sign_x402 and /v1/vault/sign. The merged patch now debits daily budgets, covers repeated under-threshold spend, and keeps the internal ledger hidden from user-facing agent lists.

merged PR maintainer note
merged

MetaMask ERC-7710 x402 package

A high-brand wallet/account-abstraction PR passed local tests, lint, and build, then merged. The review isolated a default-path integration bug where the ERC-7710 wrapper could publish unchanged Base USDC requirements without assetTransferMethod: "erc7710" or facilitator addresses.

ERC-7710 repro merged PR
new

LogicNodes Bazaar catalog

The live Coinbase x402 PR showed 256 Bazaar-discoverable resources and FastAPI-style nested 402 challenge bodies. A same-day pass added scanner support for that shape and scoped remaining launch work to browser-readable CORS, preflight retry headers, cache policy, and discovery clarity.

LogicNodes proof note
new

Dynamic Agent Payments auto-fund

A wallet-infrastructure PR added Tempo MPP and Checkout auto-funding. The review isolated the commercial spend boundary: agent callers need hard per-call caps, strict network and asset selection, and tests for malicious high-amount or unsupported-network payment challenges.

spend-control review
new

Nevermined Visa x402 SDK

The Python Visa/x402 mirror added card-delegation support, but the e2e job showed a real parser regression: card-only provider typing rejected backend erc4337 rows before Stripe and Braintree flows could run.

Visa x402 review
new

Automattic x402-Pay hosted wallet

The Gravatar Wallet provider reintroduced a hosted-wallet payment row. The review isolated a replay-window mismatch: the provider hard-coded a 10-minute EIP-3009 authorization while the paywall advertises a 120-second payment timeout.

hosted-wallet review
new

Automattic paid MCP upload hook

A fresh MPP hook PR had strong pre-upload safeguards. The public review isolated the post-S3 paid recovery boundary: if complete_upload fails after bytes are uploaded, agents need the same upload_id recovery path instead of restarting a paid begin_upload.

paid-flow review
new

AgentLair identity and trust API

The public pass found a clean Base-mainnet x402 challenge on the trust-score lookup. The follow-up confirmed well-known discovery, no-store cache posture, browser preflight, and documented resource scope landed.

final proof re-check
new

x402watch and KR Crypto

Fresh Coinbase ecosystem reviews split the signal correctly: KR Crypto's OpenAPI routes were clean, while x402watch had useful launch-polish notes around agent-facing OpenAPI scope, no-store policy, and well-known discovery.

KR Crypto clean proof x402watch proof note
01

TensorFeed premium routes

No-payment probes found parameter-required routes reaching validation before canonical payment challenges. Follow-up checks confirmed eleven routes moved behind clean x402 challenges, and TensorFeed called the checker "load-bearing" for catching audit gaps.

final verification builder reply
02

x402jp Japan data

Weather routes that previously returned 500 now return structured Base x402 challenges across the sampled manifest. Remaining notes were scoped to browser preflight and resource echo metadata.

fix verification
03

MetEngine data agent

OpenAPI probes showed coherent Solana x402 challenges and payment-header alternatives. The public note isolated a browser preflight blocker to fix or document before distribution.

surface note
04

KR Crypto Intelligence

Initial probes found browser preflight and accept-resource gaps. Follow-up probes now show sampled paid routes returning clean x402 challenges with browser preflight and resource URLs aligned.

fix verification
05

Vegacore document services

OpenAPI probes confirmed live x402 challenges for contract, invoice, document-compliance, and human-review services. The public note isolated a doc-compliance live-price mismatch and browser payment-header readiness gaps.

surface note
06

UZPROOF verify

Follow-up probes confirmed canonical Solana x402 pricing, browser payment headers, and an MPP `WWW-Authenticate: Payment` path on the paid verification route.

fix verification
07

HYRE Agent

Live OpenAPI probes isolated a material 10x price drift. The provider moved to a single source of truth, and follow-up probes now show sampled prices matching live Solana 402 challenges.

fix verification
08

anchor-x402

Browser preflight and actual 402 CORS are both fixed after the middleware-order patch. Follow-up probes now show sampled payment challenges are readable to browser agents.

fix verification
09

Agent Trust Bench

Repeated no-payment review loops moved the adversarial payment bench to clean sampled checks, then the builder publicly validated the third clean pass before merge.

builder validation
10

EconDash macro data

Follow-up probes confirmed free OpenAPI discovery, payment-header preflight, no-store policy, and resource echo are fixed. Actual 402 responses still need browser-readable CORS.

follow-up note
11

paysh-send private transfer

The transfer gate returns a structured Solana x402 challenge for valid no-payment samples. The review isolated browser preflight, resource binding, and no-store policy gaps before wallet-facing use.

surface note
12

Solrouter inference

The private LLM inference route and quote route returned structured Solana x402 challenges. The public note isolated HTTPS resource binding, price-copy alignment, and auth/session ordering as the highest-impact fixes.

surface note
13

Cryptorefills shopping

The Solana gift-card checkout manifest links into OpenAPI. Example-driven probes found free browse routes working, but the order example reached upstream stock handling before returning a 402 challenge.

surface note
14

Settle sandbox

The receipt-pinned devnet proxy returns structured x402 challenges with matching capability hashes for arxiv, translate, and summarize demos. The public note scoped remaining work to browser preflight and capability-discovery hygiene.

surface note
15

Nansen API

The Nansen follow-up confirmed sampled analytics routes still return structured x402 challenges, and the auth-only account route is no longer presented as a paid x402 surface.

fix verification
16

Blocksize market data

VWAP, bid/ask, FX, and metals endpoints return coherent Solana mainnet x402 challenges. The latest re-check confirmed actual 402 responses now expose browser-readable payment headers and repeat the requested resource; sampled responses still need a visible no-store cache policy.

follow-up note latest re-check
17

x402watch analytics

Paid ecosystem analytics endpoints return Base x402 challenges. OpenAPI metadata, resource echo, and POST preflight were fixed; actual 402 responses still need browser-readable CORS.

follow-up note
18

AlgoVoi compliance gate

The unsupported-network demo fixture and browser preflight were fixed. Follow-up checks now reach the intended `unsupported_network` verdict and allow the payment header set.

fix verification
19

Tetrac market data

Ten sampled market-data routes returned coherent Solana x402 challenges at `$0.05`, while browser preflight did not allow the documented `x-x402-payment` header.

surface note
20

three.ws resources

The live `resources[]` catalog exposes ten paid routes with structured x402 challenges. The public note isolated drift between PAY.md, OpenAPI, and live discovery, plus third-party browser origin handling.

surface note
21

Top Ledger wallet data

Sampled wallet-intelligence routes returned coherent MPP payment challenges at `$0.0004`, while discovery endpoints were missing and browser preflight omitted CORS payment headers.

surface note
22

Purch marketplace

Search, shop, and vault discovery routes returned structured x402 challenges at the documented fixed prices. The public note scoped remaining work to HTTPS resource URLs, dynamic-buy ordering, and discovery.

surface note
23

Orion memecoin safety

Documented gateway routes returned MPP challenges before data. The public note isolated browser-readable 402 CORS, Solana-vs-Base rail metadata, discovery, and PAY.md route-scope alignment.

surface note
24

Boundary Guard x402

Sampled scan, health-probe, readiness, launch-pack, and receipt routes returned structured Solana/Base x402 challenges. Follow-up verification cleared resource binding, sidecar scope, and health-probe boundary notes.

fix verification
25

Stratum macro data

Fresh May 16 checks found live macroeconomic data routes returning x402 challenges with visible Solana accept legs. The public note isolated broader OpenAPI scope and multi-rail listing clarity.

surface note
26

Mycelium Oasis

The direct clarity endpoint now returns canonical resource metadata, browser-readable 402 headers, and a clean OPTIONS preflight. The listing clearly separates testnet payment from mainnet audit anchoring.

final re-check
27

PayAI provider set

Scoped checks found Xona's sampled creative routes returning coherent Solana x402 challenges. A 0.2.17 recheck showed BlockRun chat reaches 402, while search price, image examples, and browser clarity remain.

follow-up note
28

MoltyCash gigs

The pay-per-task gig route returns a structured x402 challenge before escrow funding, with browser-readable 402 headers and a visible Solana mainnet USDC accept leg. The public note narrowed cleanup to pricing-formula clarity and accept-level resource echo.

surface note
29

MEV Intelligence

A same-day Coinbase x402 listing received a no-payment pass across OpenAPI discovery, four paid Base routes, free preview routes, browser preflight, cache posture, and accept-resource binding.

first pass

Core wedge

Shipcheck turns launch risk into a repeatable scanner and service offer.

Open Shipcheck
01

CLI package

Published npm scanner for JavaScript and TypeScript repos. It checks env boundaries, Stripe webhook safety, Supabase/Firebase evidence, debug routes, paid API usage controls, CI, docs, lockfiles, trusted publishing, and release hygiene.

npm package
02

GitHub Action

Marketplace action wrapper that can fail CI or upload SARIF into GitHub code scanning, so Shipcheck findings show up where developers already review security alerts.

Action repo
03

MCP server

MCP server for authorized local repo scans. The launch trail now includes npm, official MCP Registry latest metadata, Glama scoring, mcpservers.org approval, and an open curated directory PR.

MCP npm package Directory launch pass Checklist

Verification ledger

Public checks that make the offer easier to trust.

Open pulse JSON
01

Shipcheck CLI 0.4.9

Published npm scanner with MCP smoke-test proof checks, STDIO execution-boundary notes, remote-server auth-boundary notes, npm trusted-publishing checks, MCP registry version-drift checks, and payment-agent guardrails. The package self-scan reports clean before release.

npm package
02

Shipcheck MCP 0.1.12

Published MCP server package carrying the latest Shipcheck engine, with official registry metadata refreshed to the current version after npm publication.

registry search
03

Marketplace action

The public action repo now runs its own CI smoke test against a 100/100 fixture and validates SARIF output from the composite action.

workflow runs
04

MCP Registry Pulse

Daily aggregate snapshot of official MCP Registry launch signals: websites, package paths, remote paths, install config, safety notes, and smoke-test language.

public report

Example reports

Readable outputs that can become client deliverables.

01

Demo app scan

Shipcheck reports a debug API route, missing Supabase RLS proof, and missing paid API usage controls in a fixture app designed to mirror common launch mistakes.

Open Shipcheck
02

MCP launch review

The site includes a fixed-scope MCP review offer and sample report for package metadata, registry readiness, install config, and tool-safety notes.

Read sample report
03

Exposure check

A same-day report format for auth, public data, client-side secrets, deploy config, database rules, and payment boundaries.

Read sample report

Bounty and growth systems

Use bounties as proof and distribution, not as the whole business.

Open LaunchQuest

LaunchQuest

Torque project that rewards builders for completing secure-launch events: scanning, verifying fixes, sharing reports, and referring other builders.

Repo Demo post

Solana Narrative Radar

Dashboard for spotting Solana ecosystem narratives and product opportunities from public activity sources.

Repo Live app

Application kit

Reusable resume, platform answers, audit offer, follow-up notes, and operating plan so outreach stays consistent and honest.

See work

Service front door

Static site with paid offers, sample reports, payment links, self-checkers, and proof links for launch work.

Open home

Commercial path

The next proof is a paid review for a real app, MCP, or dev-tool repo.

Request review