Built to be checked, not trusted.
Attesso's authorization and evidence layer ends in a provable record: append-only, checkpointed, time-anchored, and verifiable without asking us. Here is what is shipped, and what is still in the lab.
What is shipped, described plainly.
Everything in this section is in the product and documented. Nothing below depends on the research that follows.
User-signed authority
The end user approves an immutable, time-bounded mandate with a passkey on a hosted page. Attesso enforces those exact bounds, nothing wider.
Deterministic decisions
Each proposed action is evaluated against the exact mandate: ALLOW, DENY, or INDETERMINATE, with one reservation per ALLOW and one execution per reservation.
Verifiable evidence
Every step from the approval to the reported outcome is signed into one bundle that anyone can verify against published keys, without trusting Attesso.
The provable record
Every mandate event is appended to one tamper-evident log. Signed checkpoints chain and an independent RFC 3161 authority fixes their existence in time; hold a snapshot, and later prove nothing before it was rewritten or removed.
What is still in the lab.
Research here means exactly that: nothing in this section is shipped, certified, or claimed.
AP2 v0.2 adapter
In developmentA human-not-present adapter so mandates issued in other systems could enter the same runtime, with Attesso as the verifier, not the merchant or payment-method provider. Conformance and production compatibility are not yet claimed.
Agentic commerce interoperability
We track the emerging agentic payment and identity protocols as they settle, and keep the runtime source-neutral so a new mandate format can enter the same evaluation and evidence path.
Standards-first verification
Everything is designed to verify with ordinary tooling: WebAuthn, JWS with ES256, SHA-256, RFC 6962, RFC 3161, rather than novel cryptography a security team cannot assess.
No compatibility, certification, or delivery date is promised for anything on this list.
The rules we build by.
Neutral by design
PSP-agnostic and free of provider-shaped versions: the same proof has to hold whichever rail you run, or it is not proof.
Standards, not inventions
WebAuthn, JWS, SHA-256, RFC 6962, RFC 3161: primitives your security team can assess with tools it already has.
Smallest useful surface
Raw HTTP plus a quickstart. No SDK sprawl, no hidden client, no drift between the docs and the product.
Nothing ships on a claim
Every public statement is checkable: free test keys, a live playground, published keys, and verification guides that run on your machine.
Verify it. Then trust it.
Free test keys, a live playground, and guides that check the evidence and the record on your own machine.