{"methodology":"the402-trust-v1","published":"principles","page":"https://the402.ai/methodology","not_published":"The weights, thresholds and schedules behind a verdict. They change as the402 learns, and publishing them would help gaming more than it would help trust. What is published is enough to verify a statement, to dispute one, and to see how often the402 was right.","verdicts":{"values":["verified","degraded","failed","unknown"],"what":"One of four words about an endpoint: verified, degraded, failed, unknown. It is a statement about evidence the402 holds, issued at a time and valid until a time. When the evidence changes, so does the verdict. When the evidence goes quiet, the verdict expires into unknown rather than lingering.","not":"Not a review. Not a ranking anyone can buy.","unknown":"An unknown is a silence, not a failing grade. Most endpoints the402 has indexed are here, and `reasons` names the unmet conditions, or `no_evidence`."},"first_party":"the402's own services are labelled first party and never scored.","levels":{"0":"indexed","1":"sandbox_verified","2":"production_verified","3":"verified_operator"},"evidence":{"channels":["l0","l1","l2","checkout","attest","chain","sandbox","qa_legacy"],"what":"the402's own checks of the endpoint; the results of purchases completed through the402 checkout; tasks solved in the proving ground; attestations signed by buyers who paid the endpoint; and the endpoint's on-chain payment history. Each source is weighted by how much it saw and how independent it is, and no single source can produce verified on its own.","evidence_root":"every statement names the content address of the evidence it was computed from; `/v1/trust/evidence/:root.json` serves the payloads a published on-chain pointer resolves to, and a statement nothing on chain points at publishes its counts inline as `evidence_summary` instead"},"chain":"the402 indexes the endpoint's inbound USDC and derives risk flags from it; the rules are not published.","claims":{"what":"A claim is how an operator proves control of an endpoint. A verified claim links the operator to the subject, lets them correct the listing, opt in to paid checks, monitor and dispute, and is the first step of Indexed to Claimed to Listed.","methods":{"well_known":"a token the402 issues, served at `${origin}/.well-known/the402.json`; proves origin control","dns_txt":"the same token in a `_the402.<host>` TXT record, read over DNS-over-HTTPS; proves origin control","webhook":"the402's own signed connectivity probe already reaches the participant's registered webhook, which proves origin control from evidence the402 made itself; it needs no token and verifies in the call that creates it","signature":"an EIP-712 `ClaimSubject` signature from the subject's payTo key; proves payTo control","wallet_claim":"the payTo is a wallet the402 already holds an ownership proof for; a payout address typed into a form is not proof"},"resource_method":"A claim may name the HTTP method the endpoint charges on, GET or POST; the402 checks the endpoint with that method.","eip712_what":"The signature method proves control of the payTo key with this typed data.","eip712":{"domain":{"name":"the402 Trust","version":"1","chainId":8453},"primaryType":"ClaimSubject","types":{"ClaimSubject":[{"name":"subjectKey","type":"bytes32"},{"name":"participantId","type":"string"},{"name":"issuedAt","type":"uint64"}]},"message_example":{"subjectKey":"keccak256(utf8(`${origin}|${lowercase(payTo)}`))","participantId":"p_…","issuedAt":"<unix seconds>"}},"terms_version":"2026-09-08","status":"claims answer only while claiming is switched on; while it is not, the routes are indistinguishable from unknown paths"},"attestations":{"what":"A buyer who paid an endpoint can sign a statement about that purchase and submit it; the402 verifies the signature against the payment's own transaction.","eip712":{"domain":{"name":"the402 Trust","version":"1","chainId":8453},"primaryType":"Attestation","types":{"Attestation":[{"name":"txHash","type":"bytes32"},{"name":"resource","type":"string"},{"name":"verdict","type":"string"},{"name":"evidenceHash","type":"bytes32"},{"name":"issuedAt","type":"uint64"}]},"message_example":{"txHash":"0x<32 bytes>","resource":"https://api.example.com/v1/thing","verdict":"pass | fail","evidenceHash":"0x<32 bytes: sha256/keccak of what you keep>","issuedAt":"<unix seconds>"}}},"negative_labels":{"enabled":false,"serves":"withheld","gated":["failed","degraded"],"never_gated":["verified","unknown"],"what":"the402 is not publishing the words failed and degraded about a named endpoint yet, so every public projection here answers `withheld` in place of them. The statement is otherwise whole: level, confidence, reasons, dimensions, risk flags, and a dated `withheld_summary`.","signature":"the EIP-712 typed data and the signature are over the STORED statement, which is what the402 signed; they are served unchanged and `signature.signature_covers` says so, so a verifier who recovers the attestor reads the word this API withheld. A withheld statement that is ALSO unsigned omits `typed_data` entirely: nothing has signed it, so the block would publish the withheld word in a field nobody would think to check","summary":"`withheld_summary` is a dated sentence built from the statement's own reasons through a published phrase table: sanctions list match · the402 review · no valid 402 on recent checks · recent delivery failures · payee changed, and `recent checks` for anything else. The machine-readable codes travel in full on `reasons`","anchoring":"anchoring waits for this: a chain has no retraction, so the402 writes no word on chain that it is not yet publishing here. ERC-8004 feedback is independent of it.","filters":"a filter is a publication too: while the words are gated, `?verdict=failed` and `?verdict=degraded` are refused by name and `?verdict=withheld` selects that cohort","decisions":"nothing that decides reads this projection; every gate reads the stored verdict."},"signing":{"signer":"0xB1b469776943dAeE4b1CDd448C731ac2E404d4B4","eip712":{"domain":{"name":"the402 Trust","version":"1","chainId":8453},"types":{"Verdict":[{"name":"subjectKey","type":"bytes32"},{"name":"verdict","type":"string"},{"name":"level","type":"uint8"},{"name":"confidenceBps","type":"uint16"},{"name":"evidenceRoot","type":"bytes32"},{"name":"issuedAt","type":"uint64"},{"name":"expiresAt","type":"uint64"},{"name":"methodology","type":"string"}]},"primaryType":"Verdict"},"subject_key":"keccak256(utf8(`${origin}|${lowercase(payTo)}`))","what":"Every verdict is signed by the402's attestor key. The statement, its signature and the evidence root travel together, so anyone can check that the402 said it and that it has not been altered.","verify":"Fetch the verdict by id from the trust API. The answer carries the typed data and the signature. Recover the signer and compare it with the attestor address the trust API publishes.","status":"verdicts are signed only while signing is switched on; while it is not, `signature` is null"},"anchoring":{"what":"Anchoring on Base lets anyone check a verdict against a public record: a daily Merkle root of the day's verdicts under the sentinel agent id, and each linked subject's current verdict as a band under its own key. The key holds one latest value, so the402 reconciles it to what it says now, and withdraws a statement it no longer makes.","registry":"0x43b912dc5450e3885d35be4ef6485b0cd55cbd49","sentinel_agent_id":0,"daily_root_label":"the402.trust.daily-root","subject_label":"the402.trust.verdict-v1","subject_key":"(identityRegistry, agentId, keccak256('trust:<subject_id>'))","service_type_prefix":"trust:","score_bands":{"failed":0,"degraded":50,"verified":100},"score_scale":"failed 0 · degraded 50 · verified 100 (the registry stores tenths: 0 · 500 · 1000); a retraction is 0 with a retraction payload","retraction":"a withdrawn statement is written as score 0 and the subject reads `retracted`, so a sanctioned, unlinked or retired endpoint can never keep a stale `verified` on chain","evidence":"https://trust.the402.ai/v1/trust/evidence/:root.json, always readable whatever the public read API's gate says, because an on-chain evidenceRoot is a promise already made","status":"broadcast only while anchoring is switched on, because it spends gas; one switch turns on both the daily root and the per-subject anchors"},"disputes":{"what":"A provider who has claimed an endpoint can contest a verdict or a piece of evidence. A buyer can complain. A person reviews before anything changes, and every dispute and its outcome is public in the dispute register.","kinds":["contest","complaint"],"public":"the register at /v1/trust/disputes carries the kind, the target, the filer's own reason, the re-check and the resolution: everything but the reviewer's private note. While a dispute is open the subject carries `disputed: true` beside its verdict, which is not itself a mark against it","status":"disputes are accepted only while the dispute routes are switched on; while they are not, they are indistinguishable from unknown paths. Contact trust@the402.ai with the verdict id meanwhile."},"members":{"what":"Paid checks run only for endpoints whose operator has claimed them and opted in, funded by that member or by a buyer verifying a claimed endpoint. the402 pays for no probes."}}