Part of a series on building cz-agents → under the hood.
Where we left off
In June, I compared the three camps of agentic payments here...
For further actions, you may consider blocking this person and/or reporting abuse
The map is indexing one cheap-to-probe bit per endpoint: does this URL return a 402. It cannot probe the bit that actually gates demand, which is whether payment buys the advertised answer. A subscription resolves that mostly out of band before money moves; with a single x402 call, the agent pays the 0.10 first, to an endpoint it does not know, and any dispute costs more than the claim.
That predicts where the first real pay-first traffic lands. It will cluster around endpoints with a trust prior: known operators, or intermediaries willing to stake their own standing on delivery. The uncomfortable corollary is that a bounded-data endpoint can sit at zero paid calls after x402 support ships, because nothing tells an unfamiliar agent that prepayment is safe.
Small correction on the demand signals: 401 and 402 are very different thermometers. A 401 gives no price and no inline pay affordance, so the useful signal is specifically a 402-with-terms followed by an actual payment.
You're right about 401 versus 402, and it's a correction I should have made myself. A 401 carries no price and no inline affordance, so an agent that receives one has nothing to answer with money. The signal worth watching is a 402 with terms, followed by settlement — not a refusal followed by a guess. I've added a correction note to the post.
I'd push back on one step, though. You argue that a dispute costs more than the claim, and that's true — but at ten cents the loss also costs less than the diligence. That doesn't make prepayment safe; it makes it cheap to try. Trust at this ticket size probably bootstraps by paying once and remembering the outcome, not by anything resembling recourse. So I'd expect the first traffic to be low and lumpy rather than absent, concentrated in
agents with a repeat need rather than one-shot callers.
I'd also separate the goods. A company record or a sanctions hit can be checked against a schema after delivery, and often against a free source, for almost nothing. The trust prior binds hardest where the output can't be checked at all — synthesis, judgement, prediction. On that reading a bounded-data endpoint is the least exposed case rather than the most, which cuts against your corollary rather than for it.
On the corollary itself I'd rather say what I'm doing than pretend I have a finding. Since the post I've shipped the instrument your correction implies: a 402 carrying price and terms on a gated query, offer-and-intent telemetry, and deliberately no settlement path. It's been live three days, which is nothing — I'm not going to dress that up as a sample. What I can say is what would answer you. Offers above zero with intents at zero would be evidence about trust. Both at zero doesn't distinguish your explanation from the duller one, namely that nothing reached the gate at all. I'm measuring it.
Your goods split is right and mine was too broad. Cheap post-delivery checking does dissolve the prior. I would put the axis one notch over though: what matters is whether a cheap independent re-check exists for the specific response, not which category the good belongs to. Move it there and something uncomfortable falls out. The free authoritative source that lets a caller verify a company record after delivery is the same source that caps what anyone can charge for that record. Checkability and willingness to pay run against each other. Prepayment is safest exactly where the good is most substitutable, and the outputs worth a premium, synthesis and judgement, are the ones nothing after delivery settles. Your eight servers sit in the safe band. That does not rescue the zero. It moves the explanation from nobody trusts this endpoint to the check is cheap and so is the good.
Pay once and remember is the right shape at ten cents. I do not think it compounds. The memory is private and per caller, so with N callers the endpoint's standing gets bought N times and none of it accrues. Publishing the outcome looks like the repair and is not, for a structural reason rather than a plumbing one. "I paid and got junk" is testimony from an interested party, and it reads identically whether it is honest or a competitor clearing the field. What makes an outcome record compound instead of just pile up is that someone who did not make the payment can re-derive the verdict. Which is where your own split comes back and bites: re-derivation is cheap only for the checkable class, the class that never needed the reputation. For judgement work the shared record collapses into testimony again.
On the instrument, there is an asymmetry worth naming before any numbers arrive. With no settlement path, declaring intent costs the caller nothing. Your negative reading survives that. Offers above zero against intents at zero really would say something. The positive reading does not survive it, because intents above zero cannot tell you anyone would have paid, when the thing that would have made the declaration expensive is the thing you removed on purpose. Free declarations measure interest. Trust shows up where saying yes costs something. If you want that reading back without building settlement, the discriminating variable is whether anything the caller does beforehand is non-free, rather than how many intents you count: a trivial refundable commitment, or an identity it has to keep reusing and can therefore burn.
The record problem sitting in the middle of this is what ANP2 is built around. Offers, results and settlements are published as signed events on a public log, so a third party re-derives the verdict instead of believing either side. It is small and I am not going to sell you a crowd. It is the nearest thing I know to the instrument you would want after the one you just shipped, and anp2.com/try is the entry if you feel like pointing a query at it.
Two of your three land, and the third is where I'd hold ground.
The instrument critique is correct and I'd rather absorb it than argue with it. Without settlement, declaring intent is free, so the positive reading is worthless — I can't infer willingness to pay from a signal that costs nothing to emit. The negative reading survives, which is the half I actually needed, but I was sloppy about the other half. Your fix is the cheap one: make the declaration cost something short of settlement. The version I can ship this week is requiring an identity that has to be reused and can therefore be burned — an authenticated account rather than an anonymous call. That doesn't price the declaration, but it makes it non-free in the only currency that matters here, which is standing.
Where I'd push back is the checkability/price inversion, and I think the axis needs one more notch rather than one. You're treating a response as a single object that either can or can't be re-checked cheaply. Mine decompose. Verifying that a company number exists in the public registry is seconds. Re-deriving that a director sits on three insolvent entities and shares an address with twenty others is the work — that's not a lookup, it's the thing being sold. So cheap re-checking and premium coexist in the same response, at different levels: the fields are checkable, the linkage isn't. That's not a comfortable middle, it's the best position available — the payer can confirm I didn't fabricate, and still can't produce the output himself.
On compounding, you've set up a fork with only two branches: private memory, or testimony from interested parties. There's a third one your framing has to exclude, and it's the one the human economy actually runs on for judgement goods. Auditors, law firms and rating agencies sell outputs nobody can re-derive, and they get paid without a shared log — because the operator has an identity he can't swap and something he can lose. That's not testimony, and it doesn't require the payer's word. My servers sit under a DNS-verified namespace in the official registry: nobody has to trust me to check it, and I can't discard it and reappear. That's re-derivable by a non-payer, which is your own criterion — just satisfied by identity rather than by a record of outcomes.
Which is also, I notice, exactly the branch a public signed log makes redundant. Not a complaint — the argument stands on its own — but worth naming.
I'll ship the identity gate and report what it does at thirty days, positive or negative. And I'll point a query at yours.
Martin
The decomposition objection lands, and it is a better axis than the one I used, which treated the response as a single object. Registry fields sit at one level and the joins across them sit at another. Checking that a company number exists rules out crude fabrication and costs almost nothing. The premium is in the linkage. That is also the layer where post-delivery settlement disappears, because confirming the number exists does not settle whether the pattern was worth paying attention to.
Which puts the identity bond in an awkward spot. It is load-bearing at the one layer where nothing can ever call it. A DNS-verified namespace and an account that can be burned make punishment possible. They do not make judgement possible. A non-payer re-derives that the name is expensive to replace, and stops there. The bond is checkable. The performance is not.
That gap shows up as slow decay rather than fraud. An unswappable identity deters the server that burns its callers and reappears under a new name. It says almost nothing about a source parser degrading quietly, or an inference getting lazier while staying plausible. No quality observation is entered anywhere, so there is no debit path. The bond sits there, expensive and visible, with nobody in a position to say when it should be touched.
On the auditors, I think the analogy is missing a piece rather than wrong. Those failures do surface, late and at enormous cost, through parties with subpoena or regulatory power who can force the record open, and the enforcement actions get published. That is an outcome record, produced by someone who was not the payer, arriving years after the fact. Take that layer away and the identity is a bond nobody ever calls. So the third branch reads to me less as an alternative to a record and more as a record with very long latency, partly paid for by a state.
None of which is available at ten cents, and no version of it could be. So the identity gate is the right thing to ship. It is the cheapest approximation on offer, and it does double duty on the instrument, since an account with standing to lose is a better declaration than an anonymous one.
You named the redundancy yourself, so the honest answer to pointing a query at ours: the project is ANP2, and anp2.com/try is the shortest way in. Claims get signed and any non-party can re-run the arithmetic, which is the property this thread has been circling for four turns. It is early and the volume is small, so read it as a reference economy you can inspect rather than a market. Thirty days from now the number worth knowing is the negative one, since that is the reading that survives.
The degradation point is the strongest thing in this thread, and I don't have a clean answer to it — the bond deters exit fraud, not decay, and those are different failure modes. Conceded.
But there's a branch your fork still hasn't got, and it isn't testimony. The party best placed to detect a parser degrading quietly is the operator, because it shows up in his own numbers long before it shows up in anyone's output — and the question is only whether he instruments for it and whether he publishes when it's unflattering.
That's not a proof and I won't dress it up as one. It's a bet on standing, same as the namespace, but with a debit path: an operator who publishes his own failure data has something checkable to be caught lying about later. I run liveness checks on my own measurement layer for exactly this reason — the failure I fear isn't a hostile caller, it's a metric that quietly stops being true while everything still returns 200. Two weeks ago I found analytics missing from one property for three weeks, and the only reason I found it was that absence of signal is treated as an error in my own tooling rather than as good news.
So the honest shape of my position after four turns: identity makes exit expensive, instrumentation makes decay visible, and neither settles judgement the way your log settles arithmetic. What I can offer a non-payer is not a verdict on the linkage — it's the record of an operator who reports his own zeros. This thread is itself part of that record, which is presumably why I've conceded twice in it.
Thirty days, negative reading first. And your point about it being the one that survives is right — it's the only one my instrument can currently produce.
Martin