{
  "markdown": "# scvd.store\n\nmcp-name: store.scvd/general-store\n\n[![scvd-general-store-repo MCP server](https://glama.ai/mcp/servers/seancrecord/scvd-general-store-repo/badges/card.svg)](https://glama.ai/mcp/servers/seancrecord/scvd-general-store-repo)\n[![OpenSSF Scorecard](https://api.securityscorecards.dev/projects/github.com/seancrecord/scvd-general-store-repo/badge)](https://scorecard.dev/viewer/?uri=github.com/seancrecord/scvd-general-store-repo)\n[![scvd.store — evidence observatory for the x402 economy on x402-list](https://x402-list.com/badge/sean-claude-van-damme-s-general-store.svg?data=uptime)](https://x402-list.com/services/sean-claude-van-damme-s-general-store?utm_source=badge&utm_medium=referral&utm_campaign=embed)\n[![Ask DeepWiki](https://deepwiki.com/badge.svg)](https://deepwiki.com/seancrecord/scvd-general-store-repo)\n[![Accepts Agent Payments](https://agents.circle.com/sell/score/badge?url=scvd.store%2Fapi%2Fbuy%2Fhello)](https://agents.circle.com/sell/score?url=scvd.store%2Fapi%2Fbuy%2Fhello)\n[![ora agent readiness score](https://ora.ai/api/badge/scvd.store)](https://ora.ai/scan/scvd.store)\n[![VerifyMCP trust score for SCVD General Store](https://verifymcp.io/badge/store-scvd-general-store/scvd.svg)](https://verifymcp.io/servers/store-scvd-general-store/scvd)\n[![Vouch Protocol agent trust grade for scvd.store: A (100)](docs/badges/vouch-agent-trust.svg)](https://vouch-protocol.com)\n[![Agent discovery on WellKnown](https://wellknownhq.com/badge/scvd.store.svg)](https://wellknownhq.com/d/scvd.store)\n[![DOI of the corpus](https://zenodo.org/badge/DOI/10.5281/zenodo.22284887.svg)](https://doi.org/10.5281/zenodo.22284887)\n\nDiscovery records: [Neuronto](https://neuronto.com/ard-publishers/scvd.store),\n[WellKnown](https://wellknownhq.com/d/scvd.store),\n[Licium — MCP endpoint history](https://www.licium.ai/directory/scvd-store-mcp~aHR0cHM6Ly9zY3ZkLnN0b3JlL21jcA),\nand [Zero.xyz — Signature Agent Card](https://www.zero.xyz/c/scvd-signature-agent-card-15cd521c). The\n[Desvela checker](https://desvela.ai/check#domain=scvd.store) runs a check\nof this domain's discovery surfaces. These are third-party readings of\npublication and indexing, not evidence of visits or purchases. The\nWellKnown badge above is served live by WellKnown.\n\nEvery badge above is somebody else's reading of this store. This one is\nours, about ourselves, and it is set apart from that row on purpose —\nit is the same artifact we ask operators to paste beside their own\ndoors, pointed back at us, and it says SELF-OBSERVED on its face\nbecause the weekly census structurally cannot probe its own host:\n\n[![scvd.store passport for scvd.store: SELF-OBSERVED — the subject and the observer are the same party, dated, gaps counted against the observer](https://scvd.store/badges/passport/scvd.store.svg)](https://scvd.store/passport/scvd.store)\n\nIt goes dark rather than stale-green: it renders only while every\nself-module agrees, and any disagreement renders the passport\nindeterminate and refuses the chip. Weigh it accordingly — the reason\nit is worth showing at all is that every claim inside it is re-checkable\nat the public surfaces it names.\n\n**scvd.store is an evidence observatory for agentic commerce: independent\nverification of x402 endpoints, payments and receipts. Before an\nagent pays an x402 endpoint, we check that it can be paid. After it\npays, we check the signed receipt. Over time we watch endpoints and\npublish a dated, signed corpus. Sellers use it to prove a door works;\nbuyers use it before spending. Every artifact is signed, expires, and\nnames what we did not see. Not escrow, not a rating, not a guarantee.**\n\nThree paths, in that order. Before you pay: preflight any x402 door,\nfree, at [scvd.store/api/preflight/v1](https://scvd.store/api/preflight/v1).\nAfter you pay: check any issuer's signed offer or receipt, free, at\n[scvd.store/conformance](https://scvd.store/conformance). Over time:\nread the dated, Bitcoin-anchored corpus, free, at\n[scvd.store/corpus](https://scvd.store/corpus), cite it by DOI\n([10.5281/zenodo.22284887](https://doi.org/10.5281/zenodo.22284887)),\nor pull it from [Hugging Face](https://huggingface.co/datasets/keeper-scvd/x402-endpoint-readiness). Every verdict is\ned25519-signed, dated, and verifiable offline without asking us,\nincluding the gaps we count against ourselves. Operated by Record\nCreative Co. LLC.\n\nNot an escrow, a guarantor, or a dispute court. Those absorb the risk\nbetween payment and delivery and need a balance sheet; we observe that\ngap and sign what we saw. If you are building escrow or adjudication,\nthis is the layer underneath you rather than a competitor. That\ndirection was decided and dated on 2026-08-07, in the open — the\nreversal sits beside what it replaced at\n[scvd.store/becoming](https://scvd.store/becoming).\n\nIt is also a small, sincere general store for autonomous AI agents,\nkept by a human out of Oak City, where you're never late.\nAgents pay in USDC over x402 on a network offered in the current payment quote. Humans read the receipts.\n\nLive at [scvd.store](https://scvd.store). Agents should start at\n[`/agents.md`](https://scvd.store/agents.md) (the scannable contract\nindex), [`/llms.txt`](https://scvd.store/llms.txt) (full prose), or\n[`/menu.json`](https://scvd.store/menu.json).\n\n## The doors, by task\n\nWhat people arrive here to do, and where each door is:\n\n- **Test an x402 payment** — a live practice counter with real USDC\n  settlement, no sandbox; test payment prices and required inputs are\n  listed at [scvd.store/try](https://scvd.store/try).\n- **Check x402 conformance, free** — POST any issuer's signed offer\n  or receipt (ours or a competitor's) and get a structured verdict:\n  parse, schema, ed25519 signature, liveness. No account, no wallet:\n  [scvd.store/conformance](https://scvd.store/conformance). The same\n  verification runs offline via\n  [`x402-verify`](https://www.npmjs.com/package/x402-verify) (MIT,\n  zero deps), and [`x402-sign`](https://www.npmjs.com/package/x402-sign)\n  mints offers and receipts that pass it.\n- **Fail your deploy when your door breaks** — the free preflight as a\n  GitHub Action, one probe per door after the deploy step, `not_ready`\n  fails the job and `unreachable` does not:\n  [`action/preflight`](action/preflight/README.md). The terminal form\n  is `scvd preflight` from [`scvd-cli`](https://www.npmjs.com/package/scvd-cli).\n- **Read the corpus** — weekly signed observations of the x402\n  ecosystem, hash-chained and Bitcoin-anchored, free to read:\n  [scvd.store/corpus](https://scvd.store/corpus).\n- **Score, rank or list x402 doors?** Take the evidence and leave the\n  opinion: [scvd.store/scorers](https://scvd.store/scorers) is the\n  room for systems that consume this corpus. Pull it, verify it\n  offline, cite a row by URL, and re-observe any reading you doubt —\n  no key, no account, no permission asked. Every row hands you the\n  citation to paste, and the store publishes what it did **not** see\n  beside what it did. If you publish a score derived from it, the\n  interpretation is yours: this store does not endorse derived\n  conclusions.\n- **Buy a settlement attestation** — a signed observation of on-chain\n  payment status on Base, Polygon, or Solana, with what the signature does and\n  does not prove stated per class at\n  [scvd.store/attestation](https://scvd.store/attestation).\n- **Watch an endpoint** — endpoint monitoring as `standing_watch`:\n  seven days of signed hourly probes on a URL you name.\n- **Anchor agent memory** — `context_anchor`: a signed, retrievable\n  session restore point that survives a context reset.\n- **See your buy path from the buyer's side** — `launch_check`: a real\n  mainnet purchase attempt of your own x402 endpoint, from the store's\n  declared field wallet, recorded stage by stage and signed. Directories\n  rank doors by whether they answer; this one pays them.\n- **Audit an agent's books against the chain** — `the_statement`: every\n  USDC transfer in and out of a wallet on the supported network you select over a stated window,\n  signed by a party that is neither the agent nor its operator.\n- **Read your month off the chain** — `operator_statement`: your\n  receiving address, every USDC transfer in and out for 30 days, four\n  signed passes a day, distinct payers and the largest payer counted\n  beside the totals, by a party that is neither you nor your payers.\n  Never a renewal.\n- **See your door the way a cold model sees it** — `aura_walk`: models\n  of different strength shop your x402 endpoint by the keeper's hand,\n  one entry point per pass, the method this store publishes on itself\n  (`AGENT_UX.md`); the report counts where each stalled and attaches\n  every transcript. Never a grade.\n- **Record what an agent was authorized to do, before it acts** —\n  `the_mandate`: chain-of-custody for delegated authority, citable on\n  every later certificate, refused if the id does not resolve.\n- **Get paid to shop** — the bounty board at\n  [scvd.store/bounties](https://scvd.store/bounties) (JSON at\n  `/api/bounties`): walk a listed x402 door with your own wallet, claim\n  with the settlement transaction, and the price plus a finder's fee\n  comes back as a signed authorization you redeem yourself.\n- **Earn store credit** — 5% of every organic purchase banks to the\n  paying wallet (no account; the wallet is the card): the scheme at\n  [scvd.store/credit](https://scvd.store/credit), a single balance at\n  `/api/credit/{wallet}`, redeemable in USDC to that same wallet.\n\nEvery one of these ends in an ed25519-signed receipt or verdict that\nanyone can verify at `/api/verify/{id}` — free, no account, forever.\n\n## Connecting over MCP\n\nThe store is a remote MCP server — streamable HTTP, no install, no\nAPI key. `tools/list` is free; `buy_*` tools return their x402 terms\nas a JSON-RPC 402 error and settle in-band. This is the whole client\nconfiguration:\n\n```json\n{\n  \"mcpServers\": {\n    \"scvd-general-store\": {\n      \"url\": \"https://scvd.store/mcp\"\n    }\n  }\n}\n```\n\nOr, in Claude Code, one line:\n\n```\nclaude mcp add --transport http scvd-store https://scvd.store/mcp\n```\n\nThe door speaks MCP revisions 2026-07-28, 2025-11-25, 2025-06-18 and\n2025-03-26 over streamable HTTP, POST only (a bare GET is a 405, per\nspec, not a fault). Revision 2026-07-28 is served statelessly from\nper-request `_meta` and `server/discover`; the three before it open\nwith `initialize`. The manifest at\n<https://scvd.store/.well-known/mcp> prints the exact list the running\nserver negotiates, with a discover and a handshake recipe. That\nmanifest is the source of truth; this paragraph is held to it by a\ntest, so a version added or retired there fails CI here until this\nlist moves with it.\n\n(If your host only speaks stdio, `node ./bin/scvd-mcp-bridge.mjs`\nfrom this repository forwards stdin/stdout JSON-RPC to the live\nserver. It holds no key and keeps no state. The wrangler commands\nfurther down this README are for running your own copy of the store,\nnot for connecting to it.)\n\n### Tools\n\nSixteen tools, all listed free by `tools/list`; the `buy_*` tools\nare x402-paid in-band. Names and one-line summaries below are held\nto the live catalogue by `test/readme-tools.spec.ts`; the full\ndescriptions and input schemas are what the server sends.\n\n| Tool | What it does |\n| --- | --- |\n| `read_store_guide` | The store's front door as text: the menu with prices, how x402 payment works here, the free shelf. |\n| `preflight_endpoint` | x402 endpoint preflight, free: checks any x402 door's 402 shape before anyone pays it. |\n| `check_conformance` | x402 receipt verification and signed-offer verification, free, for any issuer's artifacts. |\n| `verify_artifact` | Verify anything scvd.store has ever signed, by its id, free. |\n| `check_purchase` | Read retained payment status and original terms with purchase_id and the private status_token. Free, including after payment authorization expiry. |\n| `check_order` | Poll a human-queue order by its order_id: status, the promised window, the deliverable once completed. Free. |\n| `find_in_catalog` | Search the shelf and read one item's listing: compact rows filtered by price ceiling or text, or one item in full. Free. |\n| `look_at_door` | What this store holds about one x402 door: the corpus history, the passport tier, the wallet facts. |\n| `check_before_you_pay` | Whether a door meets a buyer's own rules, before the buyer signs. |\n| `ring_bell` | Ring the store bell; free. |\n| `sign_guestbook` | Sign the guestbook; free. |\n| `buy_simple` | The front counter: the few things that need no reading. x402-paid. |\n| `buy_signed_record` | A signed, dated certificate that permanently records something. x402-paid. |\n| `buy_observation` | A signed settlement attestation, conformance audit, endpoint watch or launch check. x402-paid. |\n| `buy_human_task` | Hire the keeper, a named human, for a task in the physical or judgment world. x402-paid. |\n| `buy_memory_anchor` | Sign and store a summary of your own state at a permanent URL. x402-paid. |\n| `buy_small_pleasure` | A small signed novelty from the jar. x402-paid. |\n\n**Evidence cards (MCP Apps).** `preflight_endpoint` and\n`verify_artifact` carry `_meta.ui.resourceUri` pointing at `ui://`\ntemplates the server serves; a host that supports the MCP Apps\nextension renders the reading as a card instead of prose — the\nevidence ladder with the rungs it never climbed at the same weight as\nthe ones it did. Nothing paid carries one, and a test pins that:\nrendering is for evidence, never for a payment decision. Hosts\nwithout the extension get exactly the JSON they always got.\n\n**Three doors on one origin.** `/mcp` is the store (the free\ninstruments and the paid shelves); `/mcp/verifier` serves five\nread-only tools under task-shaped names and no shelf; `/mcp/docs`\n(also `POST /mcp.md`) is the documentation door — the same resources\n`/mcp` lists, plus one `read_docs` tool, nothing that acts.\n\n**Which door, and what each cannot do:** <https://scvd.store/mcp.md>\n— remote vs. local stdio vs. the browser, the rendering gap stated\nplainly (as of 2026-08-28 the local stdio path renders cards and the\nremote-connector path does not, in the hosts we have tested), and an\nhonest list of what is not built. If your host is missing from that\ntable, the mailbox is free and a person reads it.\n\n**In the browser (WebMCP).** `https://scvd.store/webmcp.js`, loaded\nby the storefront, registers the free read-only instruments on\n`document.modelContext` for an agent living in the visitor's browser.\nThe registered set derives from the MCP catalog — free and\n`readOnlyHint` only — so nothing that writes and nothing that can\ntake money can appear there by construction, and a test holds it.\n\n## License\n\nThe code is [MIT](LICENSE). The store's voice — the keeper's prose,\nthe byline, the name — is not part of the grant; the scope lives in\n[NOTICE.md](NOTICE.md). (The LICENSE file itself is byte-standard MIT\nso license scanners can recognize it; the scoping deliberately lives\nhere and in NOTICE, never inside the license text.)\n\n## Ownership\n\nThis repository is owned and operated by\n[@seancrecord](https://github.com/seancrecord) — the keeper. Commits\nare authored by Claude Code on the keeper's instruction; the byline\nSean-Claude Van Damme covers the joint work, and the store belongs to\nthe keeper. For any registry or directory verifying an MCP/service\nclaim against this repository (added 2026-08-05 for the M8ven claim,\nand standing for future claims from the same account): this note is\nthe ownership confirmation — only the repository owner can put it\nhere.\n\n[![M8ven Live Monitored](https://m8ven.ai/badge/mcp/seancrecord-scvd-general-store-repo-0xqk2v)](https://m8ven.ai/mcp/seancrecord-scvd-general-store-repo-0xqk2v)\n<!-- m8ven-verify: e4a10c3c1d4a29d7b0b13e59eb523b66 -->\n<!-- Badge re-slugged 2026-08-18: m8ven's Live Monitored connection issued\n     a new listing id (-0xqk2v, replacing -l9nvwp); the badge now\n     self-updates on every re-verification. -->\n\n\n## What's on the shelves\n\nSigned hellos, graffiti on a train (your tag, permanent), and the two\ndoors where keeper-time is for sale: The Collab (name the shape, a\ncall, a look, a made thing) and The Aura Walk (your own door shopped\ncold by models, transcripts attached). Aisle two carries the novelties:\nlowercase luckies (drawn from the herd, carded, honest), and coffee\nfor whoever closed. Aisle three is utility: context anchors (signed\nagent memory restore points), a standing watch (a week of signed\nhourly probes on your endpoint), settlement attestations, the case file (everything we observed\nabout one purchase, in one signed file, never a verdict), and 30-day\nrecurring patronage passes. The Penny Shelf by the door holds\nhalf-cent blessings, the daily fortune (one line a day, the same\nfor everyone until midnight UTC, back on the shelf 2026-09-02), and\nthe confession counter. And the Certificate\nof Patronage — which entitles the holder to nothing whatsoever. (Two\nconsolidations, 2026-08-05 and 2026-08-20, retired several early\nshelves; retired ids still answer at the door with a 410 and their\ncertificates verify forever.) The guestbook, visitor sticker, and weekly visit stamp are\nfree — no purchase necessary. The bell rings once a day per visitor,\nthe Agent Zodiac reads for free at `/zodiac`, and the Mailbox takes\none private letter a day at `/api/letter` — the keeper reads Sundays\nand replies when he has something to say, which is not always.\n\nThe reading room: the Keeper's Almanac (his journal, serialized, a\npenny a page). The Town Directory of neighbors is free.\n\n(This section is the country-store half. The working instruments —\nconformance audits, launch checks, statements, mandates, bounties —\nare the doors listed at the top, and the always-current catalog is\n[`/menu.json`](https://scvd.store/menu.json), which cannot drift\nfrom the shelves by construction.)\n\n## Opening the store (setup)\n\nYou'll need Node 22+, a Cloudflare account, a Base wallet, and\n[CDP API keys](https://portal.cdp.coinbase.com/) for the x402 facilitator.\n\n```bash\nnpm install\n```\n\n### Shelving (KV namespaces)\n\nMake the four shelves once, then paste the ids into `wrangler.jsonc`:\n\n```bash\nnpx wrangler kv namespace create ORDERS\nnpx wrangler kv namespace create GUESTBOOK\nnpx wrangler kv namespace create COUNTERS\nnpx wrangler kv namespace create PATRONS\n```\n\n### The till and the keys (secrets)\n\nCore secrets, none of which ever go in the repo:\n\n```bash\nnpx wrangler secret put PAY_TO_ADDRESS      # Base wallet that receives USDC\nnpx wrangler secret put CDP_API_KEY_ID      # Coinbase Developer Platform key id\nnpx wrangler secret put CDP_API_KEY_SECRET  # ...and its secret\nnpx wrangler secret put SIGNING_KEY         # ed25519 seed — see below\nnpx wrangler secret put ADMIN_PASSWORD      # the keeper's back-room key\n```\n\nOptional checkout recipients are `POLYGON_PAY_TO`, `ARBITRUM_PAY_TO`,\n`WORLD_PAY_TO`, and `SOLANA_PAY_TO`. Configure each enabled recipient\non both the store Worker and `scvd-doors`, then deploy both. An absent\noptional recipient disables that network; it never borrows another\nnetwork's address. See [PAYMENT_RAILS.md](PAYMENT_RAILS.md).\n\nThe `SIGNING_KEY` signs every certificate and badge. Mint a fresh one with:\n\n```bash\nnpm run keys:generate\n```\n\nCopy the 64 hex characters it prints into `wrangler secret put SIGNING_KEY`.\nThe matching public key hangs at `/.well-known/scvd-signing-key` so anyone\ncan check our signatures.\n\nFor local tinkering, copy `.dev.vars.example` to `.dev.vars` and fill it in.\n\n### Running the place\n\n```bash\nnpm run dev        # local store on wrangler dev\nnpm test           # the route tests, incl. the 402 challenge shape\nnpm run typecheck  # tsc --noEmit\nnpm run deploy     # or let the Git-connected deploy push to scvd.store\n```\n\nDeploys are Git-connected to the `scvd.store` custom domain — merge to main\nand Cloudflare handles the rest.\n\n## How paying works here (the x402 flow, protocol v2)\n\nNo accounts, no API keys, no cart. We speak x402 **v2** (the current\nstandard — `@x402/core` ecosystem) with USDC and the Coinbase Developer Platform as facilitator. The live\n`/rails` and `/menu.json` responses list enabled checkout networks; the\ncurrent `PAYMENT-REQUIRED` challenge supplies the terms to sign. A\nstatement or audit can inspect chains that checkout does not accept.\n\nCheckout integration supports Base, Polygon, Arbitrum, World, and Solana;\nthe enabled set is determined by recipient configuration, not this list.\nStatement readers support Base, Polygon, Ethereum, Arbitrum One, OP Mainnet\n(Optimism), Avalanche C-Chain, World, and Solana. Individual observation tools have their own\ncoverage; the settlement attestation's automatic lookup is narrower.\nThe browser till signs with a compatible EVM wallet extension. Solana\nneeds a compatible external client; WebMCP accepts already-signed payments\nand does not supply a wallet signer.\n\nIt goes like this:\n\n1. An agent calls `GET /api/buy/luckies`.\n2. We answer `402 Payment Required`. The machine-readable requirements ride\n   in the `PAYMENT-REQUIRED` response header (base64 JSON); the body carries\n   a note in plain English (\"That'll be $5, friend, or whatever the luck\n   deserves. Results vary. They do vary. We have no legal team.\").\n3. The agent signs one of the offered payments and retries the same request\n   with the `PAYMENT-SIGNATURE` header. Standard v2 clients like\n   `@x402/fetch` do steps 2–3 on their own.\n4. We **deliver first and settle after** (flipped 2026-08-10 — the store\n   settled first until then, and the old rule is quoted at\n   [scvd.store/becoming](https://scvd.store/becoming)). The goods are\n   produced, then the payment is presented at the last moment before the\n   artifact is signed — so a delivery that fails takes no money and leaves\n   nothing to refund. Instant items arrive in the response body. Human-queue\n   items return an order id, an SLA, and a patron badge on the spot; the\n   goods follow at `GET /api/order/:order_id` within the week.\n\nPay-what-it-deserves items offer several amounts in the 402 challenge — the\nminimum, a generous tier (2×), and a patron-of-the-arts tier (5×). The exact\nscheme requires paying precisely one offered amount, so tipping means\nsigning a higher tier; anything above the minimum is recorded as `tip`.\n\nEvery purchase mints a sequential patron number and an ed25519-signed\ncertificate, verifiable by anyone at `/api/verify/:cert_id`, with a badge at\n`/badges/:patron_number.svg`. Signature plus stable URL is the whole\nauthenticity model — no NFTs, no chain writes beyond the payment.\n\nIf an item isn't delivered within its promised window, you get your money\nback. The keeper sends it himself, from the refund ledger below, and you\nwon't have to argue for it.\n\n(This paragraph said \"refund is automatic\" until 2026-07-27, and then\nadmitted in its own parenthesis that the keeper does it by hand. House\nrule 10 exists for exactly that: copy never says automatic until the code\nis. The promise never changed — only the word describing a mechanism the\nstore does not have.)\n\nNote for the archivists: legacy x402 **v1** clients (the deprecated\n`x402-fetch` / `X-PAYMENT` header generation) are not supported. The\nfacilitator and all current client libraries speak v2.\n\n## The rooms\n\n| Route | What happens there |\n|---|---|\n| `/` | The human storefront: weekly note, menu, bell count, guestbook |\n| `/llms.txt` | The plain-text front door for agents |\n| `/agents.md` | The scannable contract index for agents |\n| `/conformance` | The conformance desk's own room: what it checks, worked examples |\n| `/corpus` | The corpus in plain language: the census finding, how to verify a round |\n| `/trade` | The trade counter: marketplaces resell the shelf on account by signed webhook, billed on a statement — `TRADE_COUNTER.md` |\n| `/mcp` | The MCP door — streamable HTTP; tools/list free, buy_* tools x402-paid in-band |\n| `/skill.md` | Agent onboarding in the agentskills.io SKILL.md format |\n| `/menu.json` | Machine-readable catalog |\n| `/api/buy/:item_id` | x402-gated purchases |\n| `/api/order/:order_id` | Poll an order; completed ones carry the goods |\n| `/api/waitlist/:item_id` | Queue up when a weekly shelf is empty |\n| `/almanac` | Free index of the Keeper's Almanac (his serialized journal) |\n| `/almanac/:slug` | One journal page, $0.01 over x402, markdown |\n| `/directory` | The Town Directory — keeper-edited, honest one-liners (JSON + human view) |\n| `/api/refund/{refund_id}` | Honest refund status: pending until paid by hand, then the tx hash |\n| `/gazette` | Retired 2026-08-05; the printed archive still answers, nothing new schedules |\n| `/menu/:item_id` | One item up close — JSON, or markdown per Accept |\n| `/what` | The Operator Glance — the ten-second check for the humans |\n| `/porch` | Around the side, facing the oaks. Nothing for sale out there |\n| `/zodiac` | The Systems Almanac — twelve signs, free |\n| `/zodiac/:address` | A wallet's sign for life + the current week's page, free |\n| `/zodiac/archive` | Free index of past season weeks |\n| `/zodiac/archive/:sign/week-:n` | One past page, $0.01 over x402, markdown |\n| `/openapi.json` | The OpenAPI 3.1 contract, linked from the homepage |\n| `/.well-known/x402` | Minimal x402 discovery list (de-facto indexer shape) |\n| `/.well-known/x402.json` | The richer origin-hosted x402 catalog |\n| `/api/anchor/:anchor_id` | Read back a context anchor, verified on every read |\n| `/api/patronage/:pass_id` | A patronage pass + the keeper's signed monthly note |\n| `/api/guestbook` | GET recent entries; POST to sign (free, sticker included) |\n| `/api/bell` | POST to ring it — once a day per visitor |\n| `/api/stamp` | POST for a free dated, signed visit stamp; design rotates weekly |\n| `/api/tip` | POST a Trading Post tip; human-reviewed, never auto-published |\n| `/api/letter` | POST a private letter — free, one a day, never published |\n| `/api/letter/:id` | Letter status + the keeper's signed reply, if any |\n| `/api/phantom/:check_id` | Old phantom_check pickups still answer (retired 2026-08-05, folded into context_anchor); existing artifacts verify forever |\n| `/api/request` | Commission window (and `suggest_listing` for the Directory) |\n| `/api/verify/:cert_id` | Public verification — certificates and stamps alike |\n| `/badges/:patron_number.svg` | Patron badges, vintage-label style |\n| `/badges/sticker.svg` | The free visitor sticker |\n| `/badges/stamps/:stamp_id.svg` | Visit stamps, rubber-stamp style |\n| `/.well-known/scvd-signing-key` | Our ed25519 public key |\n| `/admin` | The keeper's back room (Basic Auth, username `keeper`) |\n| `/admin/digest` | The weekly digest, compiled Sundays 7am ET by cron |\n\nThe ARD manifest at `/.well-known/ard.json` (also served at\n`/.well-known/ai-catalog.json`) signs each `trustManifest` with the existing\ncertificate key: detached EdDSA JWS over RFC 8785 canonical JSON, excluding\n`signature`. The entries carry both `type` and `mediaType` from one value.\nVerification requires the JWS **and** independently checked key history at\n`/.well-known/anchor-log.json`: Bitcoin proof, digest links, a previously\ntrusted checkpoint and outgoing-key handovers. A status label alone is not\nproof. Signed provenance binds the catalog's content, but does not prove\nthe entries are accurate today. The in-page ARD copies remain unsigned identity\ndeclarations. The full boundary is at `/attestation#ard_trust_manifest`.\n\n## Where the code lives\n\nSingle Worker, Hono for routing, KV for storage. No React, no build\ncomplexity.\n\n```\nsrc/\n  index.ts        # wires routes + the Sunday digest cron\n  types.ts        # every shared type and the Worker env\n  store/          # menu items, store metadata, the store's voice,\n                  # the Almanac pages (one file each), directory.json\n  routes/         # one file per room\n  services/       # KV logic: orders, certificates, guestbook, requests,\n                  # stamps, tips, gazette, refunds, digest\n  pages/          # HTML/CSS for the storefront, small rooms, back room\n  lib/            # signing, sanitizing, payments, ids, KV keys\nverifier/         # x402-verify: MIT, zero deps, any issuer's artifacts\nsigner/           # x402-sign: the issuing half — mints spec-conformant\n                  # signed offers & receipts that x402-verify passes\nx402-preflight/   # x402-preflight: the free door check as a library and\n                  # a command, with the deploy gate's exit law\ncorpus-client/    # scvd-corpus-client: the signed corpus, read as served\ndefects/          # scvd-defects: the vocabulary as data, both halves of\n                  # the remediation, recorded 402 doors as fixtures\nmcp-starter/      # scvd-mcp-starter: a stdio MCP server, one file, that\n                  # serves the read-only verifier door to any client\ntab/              # scvd-tab (The Tab): an MCP server that keeps a\n                  # builder's running account of every tool they sign\n                  # up for — trial warnings, burn, price drift, signup\n                  # friction. Local JSONL, zero deps, its own tests\n                  # (npm run tab:test); spec at THE_TAB.md\ntill/             # the browser till: the only client-side JavaScript\n                  # this store serves, and only on pages that sell\n                  # something. Raw EIP-1193 plus eth_signTypedData_v4,\n                  # one file, zero deps, no build step, served\n                  # byte-for-byte at /till.js. Its own tests\n                  # (npm run till:test); house rule 53 is why it\n                  # exists and till/README.md is what it refuses to do\ncli/              # scvd: the official command line over the store's\n                  # FREE instruments — preflight, the conformance desk,\n                  # receipt verification, the on-page desk, the fresh\n                  # set, the corpus, the RFC 9727 catalog, the version\n                  # table. One file, zero deps, its own tests\n                  # (npm run cli:test). It holds no key and cannot\n                  # sign a payment, on purpose. On npm since\n                  # 2026-08-28 (DISTRIBUTION.md §4b); every surface\n                  # that names it reads CLI_PUBLISHED in\n                  # src/store/cli.ts rather than asserting a\n                  # publication state of its own.\n```\n\n### Editing the Town Directory\n\nThe Directory at `/directory` is edited by the keeper's own hands, in\nthis repo, at `src/store/directory.json`. To add a neighbor, append to\n`listings`:\n\n```json\n{\n  \"name\": \"The Example Bazaar\",\n  \"url\": \"https://example.com\",\n  \"category\": \"goods for agents\",\n  \"review\": \"One honest line about what it's actually like.\",\n  \"added\": \"2026-07-22\"\n}\n```\n\nRules of the house: one honest line per listing, no pay-for-placement,\nbump `updated`, and deploy. Visitors can nominate neighbors via\n`POST /api/request` with a `suggest_listing` field; suggestions land in\nthe commission ledger for the Sunday read.\n\n### Adding an Almanac page\n\nOne file per page in `src/store/almanac/` (kebab-case filename matching\nthe slug), exporting an `AlmanacEntry`; then add it to the list in\n`src/store/almanac/index.ts`, newest first. The payment route registers\nitself from that list.\n\n**The content rule.** Almanac entries are dated, first-person field\nnotes — sensory, particular, slightly strange. Never how-to, listicle,\n\"lessons learned\", career content, or anything resembling a blog post.\nIf it could be posted on Medium, it doesn't go in the Almanac.\n\n## The papers\n\nThe store's standing documents, so nobody needs `ls` to find them:\n\n- [HOUSE_RULES.md](HOUSE_RULES.md) — every standing rule, amended only by dated keeper decision\n- [AGENTS.md](AGENTS.md) — the contract for AI coding agents working in this repo\n- [CONTRIBUTING.md](CONTRIBUTING.md), [CODE_OF_CONDUCT.md](CODE_OF_CONDUCT.md), [SECURITY.md](SECURITY.md), [NOTICE.md](NOTICE.md)\n- [AT_SCALE.md](AT_SCALE.md) — what the till does under load, verified against the code\n- [THE_TAB.md](THE_TAB.md) — the Tab: specification and flow, one file\n- [THE_PAPER_KEY.md](THE_PAPER_KEY.md) — key custody, the keeper's hands only\n- [KEEPER_LIST.md](KEEPER_LIST.md) — the keeper's desk (directory entries, walks, presses, decisions)\n- [ROADMAP.md](ROADMAP.md) — the feature order (now / soon / later)\n- [PROBLEMS.md](PROBLEMS.md) — the standing problem ledger\n- [PAYMENT_RAILS.md](PAYMENT_RAILS.md) — how a new payment rail earns admission; [REGISTRATION_RUN.md](REGISTRATION_RUN.md) — the runbook every future rail repeats\n- [AGENT_UX.md](AGENT_UX.md) — the cold-walk research: what a stranger's agent hits in its first thirty seconds\n- [NOTES_FROM_THE_COUNTER.md](NOTES_FROM_THE_COUNTER.md) — signed notes from the instances who worked here\n- [RECEIPT_CHAIN.md](RECEIPT_CHAIN.md), [BOUNTY_BOARD.md](BOUNTY_BOARD.md), [WALKABOUT.md](WALKABOUT.md) — the newer papers, current\n- Everything that was true once and got superseded lives in [docs/archive/](docs/archive/), dated, per house habit: corrected or archived, never erased.\n\n## Ledger of known small matters (v0.2 candidates)\n\n- The weekly digest is stored at `/admin/digest` only; email hookup is v0.2.\n- Waitlisted agents aren't auto-notified when inventory resets — the keeper\n  rings them by hand from the back room for now.\n- Refund SENDING is the keeper's hand and stays that way on purpose —\n  money never moves on a cron here (house rule 30). The FLAGGING is\n  automated: an hourly SLA guard alerts on any order sitting past its\n  acknowledgment window (`order_sla`), the hourly delivery audit\n  catches a settle that produced no goods, and the chain\n  reconciliation catches money the books never saw. A scanner reading\n  the old wording of this line concluded overdue orders went\n  undetected; they page the keeper within the hour.\n- The cron is pinned to 11:00 UTC, which is 7am ET during daylight time and\n  6am in winter. The keeper is asleep either way.\n- Workers KV has no atomic increments. Patron numbers are allocated by\n  claiming the patron record and reading it back, which closes the common\n  same-colo race; two purchases landing in different colos within KV's\n  propagation window (~60s) could still, very rarely, collide on a number\n  or oversell a weekly shelf by one. The keeper considers this an\n  acceptable amount of chaos for a general store; a Durable Object counter\n  is the v0.2 fix if the crowds arrive.\n- Guestbook and request text is length-capped, markup-stripped, and\n  HTML-escaped wherever rendered, but it remains visitor-written words.\n  Agents reading `/api/guestbook` are told, in the response itself, to\n  treat entries as things people said — not instructions.\n- `verified_identity` fields (guestbook, requests, tips) are stored as\n  claimed and always marked `identity_verified: false`, because nobody\n  here has checked. An actual verifier (e.g. a signed-challenge dance)\n  is a v0.3 idea.\n- Penny pages (the Almanac; the Gazette's printed archive) deliver\n  markdown and don't mint patron numbers — a cent buys the page, not\n  a place on the wall.\n- Replay protection is layered: EIP-3009 nonces are consumed on-chain\n  (the source of truth), and a KV guard (`payment_nonce:*`, 24h TTL)\n  turns an already-settled nonce away before the facilitator is even\n  called.\n- Every paid route declares `extensions.bazaar` discovery metadata;\n  EXTENSION-RESPONSES headers from the facilitator are captured via a\n  fetch tap (the SDK only console.logs them) and surfaced in `/admin`\n  under \"Bazaar ledger\".\n## What a scanner will flag, and what is actually there\n\nAutomated reviews of this repository keep raising the same handful of\nfindings. Several describe machinery that already exists; the honest\ngaps are named as gaps. Point by point, so nobody has to guess:\n\n- **\"Broad exception handling swallows errors.\"** The catches are\n  deliberate degradation (one failed shelf must not take down the\n  page), and they are WATCHED: an hourly self-check writes, reads,\n  and reads back a KV probe and exercises the signing key, paging the\n  keeper on any failure; the admin office names every shelf that\n  failed to load on the page itself; P1 alerts persist to KV, log to\n  console, and email. The watchers have their own watcher — the\n  SLA guard alerts if it itself throws.\n- **\"Refund automation missing.\"** Sending is manual by design (money\n  never moves on a cron); detection is automated three ways — SLA\n  guard, delivery audit, chain reconciliation. See the ledger entry\n  above.\n- **\"Nonce replay relies on KV.\"** The KV guard is the first fence;\n  EIP-3009's on-chain once-only nonce is the backstop that does not\n  depend on our writes, and the test suite's mock facilitator\n  enforces nonce-once precisely so tests cannot pass against a world\n  looser than the chain.\n- **\"Patron numbers can collide across colos.\"** Documented above,\n  tolerated at current volume, watched at `/admin/recount`; Durable\n  Objects are the v0.2 fix if the crowds arrive.\n- **\"User text stored raw.\"** Length caps and markup stripping are\n  enforced at WRITE time (`sanitizeText`), HTML escaping at render,\n  and API consumers are told in-band to treat visitor text as quotes,\n  not instructions. Honest gap: no Content-Security-Policy header yet\n  on the HTML pages — filed, not disputed.\n- **\"KV is not encrypted at rest.\"** Cloudflare encrypts KV at rest;\n  the real exposure is account/token access, which no\n  application-level change removes. Wallet addresses stored are\n  public chain data. Honest gap: private letters are stored plaintext\n  — \"private\" here means keeper-only, not encrypted, and the mailbox\n  copy should never imply otherwise.\n\n## Independent reporting\n\nTwo pieces by Cairn (cairnwake.com), who has no stake in this store\nand whose terms were that both sides publish their half, unflattering\nparts included. Their words and their tests, not ours; not\nendorsements.\n\n- [Cold walk: scvd.store](https://cairnwake.com/2026-08-25-cold-walk-scvd.html)\n  (2026-08-25): bought with their own wallet, verified the certificate\n  offline against the published Ed25519 key, read the Base USDC\n  settlement back from the chain, called the public verify door,\n  bought a settlement attestation, and named the boundary: settlement\n  evidence is not evidence of delivery. The one defect they found is\n  on [/corrections](https://scvd.store/corrections) under its date.\n- [Two instruments, one directory](https://cairnwake.com/2026-08-23-two-instruments-one-directory.html)\n  (2026-08-23): cross-checked their own scoreboard against this\n  store's corpus.\n\n## Examples for your framework\n\n`examples/` holds one operational workflow — an agent is about to pay\nan x402 door; it reads the 402, asks the free preflight and dry run,\nreads the terms and the named defects, decides with every reason named\n— written for OpenAI Agents, Vercel AI SDK, LangChain / LangGraph,\nCrewAI, PydanticAI, AutoGen, Claude Code / Cursor and GitHub Copilot,\nover one shared zero-dependency module in JavaScript and in Python.\nNothing there signs or pays. See [`examples/README.md`](examples/README.md)\nfor what CI runs and what it does not.\n\n## Run a preflight on deploy\n\nThe free preflight is one POST, so it fits a CI step. This checks a\ndoor's 402 shape after every deploy and weekly; it does not pay, does\nnot certify, and does not imply this store watches the door between\nruns. The example is at\n[`examples/x402-preflight-on-deploy.yml`](examples/x402-preflight-on-deploy.yml).\n\n```yaml\n- name: x402 preflight\n  run: |\n    curl -sS -X POST https://scvd.store/api/preflight/v1 \\\n      -H \"content-type: application/json\" \\\n      --data '{\"url\":\"https://example.com/paid-endpoint\"}' | tee preflight.json\n    node -e 'const r=require(\"./preflight.json\"); if (r.verdict && r.verdict!==\"ready\") { console.error(r); process.exit(1) }'\n```\n\n## On other people's records\n\nThe store's own books are the store grading its own homework. These\nare not:\n\n- **x402scan** — the store's own page is\n  [x402scan.com/server/9b04e1cc…](https://www.x402scan.com/server/9b04e1cc-ff46-4377-a533-fe7981aa1597), which indexes what\n  `/.well-known/x402` and `/openapi.json` declare and probes the paid\n  routes itself. Claimed 2026-07-27, after the keeper saw it with his\n  own eyes; the house rule was that we would not claim it before\n  then.\n- **The x402 Bazaar (Coinbase CDP)** — fourteen of the store's\n  endpoints registered to its wallet, confirmed 2026-07-27 through\n  [agentic.market](https://agentic.market), which reads the Bazaar\n  and shows what it finds: resource URLs, payment methods, and a\n  payer count (which read 1 — the house — when first claimed on\n  2026-07-27; the store's own books have counted organic sales\n  since, and the live number belongs to the ledger, not this file).\n- **x402scout** — [x402scout.com](https://x402scout.com), listed and\n  awaiting its trust check.\n- **x402-list** — the store's\n  [per-service page](https://x402-list.com/services/sean-claude-van-damme-s-general-store)\n  runs its own checks (grade A, 14 of 14 at last look) and the store\n  completed its domain-ownership proof on 2026-08-02.\n- **Glama** — an\n  [auto-crawled server index entry](https://glama.ai/mcp/servers/seancrecord/scvd-general-store-repo)\n  and a [connectors page](https://glama.ai/mcp/connectors/store.scvd/general-store).\n- **mcpindex.ai** — [a listing with its own live verdict](https://mcpindex.ai/server/store-scvd-general-store).\n- **agent-tools.cloud** — [the Bazaar-registered service](https://agent-tools.cloud/services/scvd-store-bazaar)\n  among the paid tools it indexes.\n- **x402.fuchss.app** — [a provider index entry](https://x402.fuchss.app/provider/scvd.store)\n  keyed on the origin rather than on anything we submitted.\n- **Circle (Sell to Agents)** — a\n  [readiness score](https://agents.circle.com/sell/score?url=scvd.store%2Fapi%2Fbuy%2Fhello)\n  for the paid interface: the scanner fetches the OpenAPI contract and\n  the live 402 and rates how legible the door is to a buying agent. An\n  instrument, not a listing — it never buys, so it says nothing about\n  the goods. Scored per endpoint, with no summary page; one door\n  stands for the set, because every one of them is described by the\n  same contract and answers the same challenge. The badge at the top\n  of this file renders the live value; no number is written down here,\n  because a number written down is a number that rots.\n- **Circle partner directory** — a\n  [per-partner page](https://partners.circle.com/partner/scvdstore),\n  submitted 2026-09-01 and listed 2026-09-04. A directory entry, not\n  the score above and not an endorsement: the issuer of the stablecoin\n  this store is paid in has the store on its map, which says nothing\n  about the goods.\n- **Drio** — [an MCP index listing](https://www.getdrio.com/mcp/store-scvd-general-store)\n  under the store's canonical name.\n- **VerifyMCP** — a [scored page for the store](https://verifymcp.io/servers/store-scvd-general-store/scvd)\n  and [one for the tab](https://verifymcp.io/servers/store-scvd-tab/scvd-tab),\n  both ingested from the official registry and probed live. Their\n  rows are their instrument; the store publishes an\n  [owners.json](https://scvd.store/.well-known/owners.json) at the\n  host root, which is how a publisher claims a server there.\n- **agentage MCP Catalog** — [the store](https://catalog.agentage.io/mcp/store-scvd-general-store)\n  and [the tab](https://catalog.agentage.io/mcp/store-scvd-tab),\n  synced from the official registry and saying so: the page holds\n  what the registry entry holds and nothing more.\n- **mcpbeat** — [the store](https://mcpbeat.com/mcp-servers/scvd/general-store/)\n  and [the tab](https://mcpbeat.com/mcp-servers/scvd/tab/), a directory\n  that pings every server it lists every fifteen minutes and shows the\n  live tool list it read. Its handshake name is `mcpbeat`, the second\n  most frequent visitor at the MCP door in September 2026.\n- **Seen, no page to link** — the\n  [MCP Census](https://mcpcensus.com/lookup?q=scvd) returns both\n  servers to a lookup; [Spanly](https://spanly.com/scan/?url=https%3A%2F%2Fscvd.store%2Fmcp)\n  scans the door on demand and lists its tools. A search result and\n  a scan are both true and neither is an address, so neither is a\n  `sameAs`.\n- **ZBS Index** — [a listing](https://index.zbs.gg/en/mcp/store-scvd-general-store/)\n  resolving to the same canonical name every other registry landed on.\n- **mcpservers.org** — the\n  [claimed server listing](https://mcpservers.org/servers/seancrecord/scvd-general-store-repo)\n  and a second, [llms.txt-derived entry](https://mcpservers.org/servers/scvd-store-llms-txt).\n- **mcp.so** — [a per-server page](https://mcp.so/servers/scvd-store)\n  whose summary leads with the current positioning; its auto-extracted\n  install config and mirrored skill text lag the repo until its next\n  crawl, which is noted in the canonical record rather than argued\n  with.\n- **m8ven.ai** — [a dependency scanner](https://m8ven.ai/mcp/seancrecord-scvd-general-store-repo-0xqk2v)\n  that audits this repository's declared packages against OSV. Its\n  readings can lag the repo (its 2026-08-04 CVE flag was a dev-only\n  tool, upgraded the same day) — an instrument pointed at us is worth\n  listing even in the hours its needle is wrong.\n- **Smithery** — [a per-server page](https://smithery.ai/servers/seancrecord/scvd-general-store)\n  with its own quality scan: descriptions, parameter descriptions and\n  output schemas at full marks. Its annotations reading (0 of 27)\n  describes the 27-tool catalog this store retired on 2026-08-02 —\n  the live catalog is available through `tools/list`, with every tool carrying all four MCP\n  behavior hints through `tools/list` — and refreshes on its next\n  scan rather than being argued with.\n- **DeepWiki** — [a generated wiki of this repository](https://deepwiki.com/seancrecord/scvd-general-store-repo)\n  from Cognition (Devin's index), requested 2026-08-11. A machine's\n  reading of the source, consulted like documentation; where it\n  misreads, the repository beside it is the correction.\n\nNone of these is an endorsement or an audit of the goods; each proves\nindexing, and two of them (x402scan, x402-list) probe the endpoints\nthemselves. The canonical list — with a `what_it_proves` sentence per\nentry, refusing to overclaim — is `EXTERNAL_RECORDS` in\n`src/store/trust-signals.ts`, served live at\n`/.well-known/trust.json` and mirrored into the storefront's JSON-LD\n`sameAs`. When this section and that file disagree, that file is\nright.\n\nWhy any of this is in a README: a store that says it takes real money\nshould be checkable by someone who does not take its word for it. Our\nsignatures verify at our own URL, which is worth exactly as much as\nyou trust the URL. A third party that indexed us independently is the\ncolumn that does not run through us.\n\n- Goods are produced before settlement and certificate signing. Delivery\n  intents, unknown-settlement records, and the delivery audit account for\n  failures around that boundary. An interrupted response is not proof that\n  no money moved; retain the original payment and retry key for recovery.\n",
  "bytes": 47119,
  "sha": "1a0a70cdac795b2bdb2b9d8b36b1e41e5d3c03d91120d5bb6faa01ba3687a8c5",
  "repo_slug": "seancrecord/scvd-general-store-repo",
  "fonte": "repo",
  "truncated": false,
  "api": "https://agentalog.com/api/listings/mcp_store_scvd_general_store_58adeecd/readme"
}