Observer Protocol / Enforcement Record
Maxi · Trading Mandate
Agent maxi-0001
Rail solana-jupiter
Settled 2026-06-23
Schema delegation/v2.2
The principal delegates authority.
The evaluator attests compliance.
Two signatures. Two trust anchors. No self-attestation.

Each signature comes from a distinct key at a distinct domain. A relying party verifying both cannot be fooled by either alone. The principal cannot clear its own transactions; the evaluator cannot grant itself a mandate.

Zero self-attestation (architectural). Two keys at two domains: bitcoinsingularity.ai and observerprotocol.org. The agent cannot grant its own mandate. The evaluator cannot self-deal. Neither party can complete the trust chain alone.
Deny-before-signing (mechanical). The evaluator runs before the transaction is signed or broadcast. A DENY short-circuits with swap_calls == 0 — the swap step is provably never entered. Enforcement locus is the pre-signature boundary, not a post-facto flag.
Enforcement holds without agent cooperation. The cooperative ALLOW used dexes= to pre-filter to allowed venues. But enforcement does not depend on that filtering. An agent that routes without filtering hits a venue DENY from the evaluator when Jupiter's default routing includes a non-allowlisted AMM. An agent that skips pre-filtering gets blocked.
Principal
Boyd Cohen
did:web:bitcoinsingularity.ai
Signing key: #key-1 (Ed25519VerificationKey2020)
DelegationCredential · eddsa-jcs-2022
Agent
Maxi #0001
did:web:observerprotocol.org:agents:maxi-0001
Mandate: $10 max/order · Raydium CLMM · Raydium AMM · Orca · Whirlpool · Meteora DLMM · Phoenix
EvaluationInput (proposal + delegation)
Evaluator
Observer Protocol
did:web:observerprotocol.org
Signing key: #key-3 (Ed25519VerificationKey2020) · policy-core v0.1.0-draft
PolicyEvaluationCredential · eddsa-jcs-2022
Settlement
Solana Mainnet Live
tx 61FKp9AGh33TCHP4GowB2YXRJT1RDvYa8bbxPr4QWffdkWXm2WsA51MVZffuB9fz1T5PjXm4r1EMMUu3evEZgJMX
slot 428476359 · finalized · 0.05 SOL → 3.4682 USDC via Raydium CLMM
Tier 1 Live Enforcement

Three tiers of enforcement maturity — a gradient from live on real money to the moment a mandate declares a rule to when live state feeds the evaluator. Signatures on both credentials verify against published DID documents at bitcoinsingularity.ai and observerprotocol.org, independent of Solana. The ALLOW settled on-chain (slot 428476359, finalized). The DENY blocked before /swap was called; no lamports moved.

Delegation Credential
Boyd Cohen
Issuer DID
did:web:bitcoinsingularity.ai
Subject DID
did:web:observerprotocol.org:agents:maxi-0001
Valid
2026-06-23 → 2026-08-04
Max notional / order
$10 USD
Allowed venues (6)
Raydium CLMM · Raydium AMM · Orca · Whirlpool · Meteora DLMM · Phoenix
Allowed instruments
SOL · USDC · USDT-SOL
Credential ID
urn:uuid:0a1b47d9-bf85-4c10-ba32-4f653e2a90f7
Proof
did:web:bitcoinsingularity.ai#key-1
eddsa-jcs-2022 · DataIntegrityProof
z3Q233j42GhXprF9uwmt6UwnZWMsGuW7oBM2hevP6dih2GSa1hdqEA1et7sbCcs918RqYbfj6JZBXfXx1rhTR8tsv
Full credential JSON
{ "@context": ["https://www.w3.org/ns/credentials/v2"], "id": "urn:uuid:0a1b47d9-bf85-4c10-ba32-4f653e2a90f7", "type": ["VerifiableCredential", "DelegationCredential"], "issuer": "did:web:bitcoinsingularity.ai", "validFrom": "2026-06-23T23:21:36.322732Z", "validUntil": "2026-08-04T23:21:36.322586Z", "credentialSubject": { "id": "did:web:observerprotocol.org:agents:maxi-0001", "authorizationLevel": "policy", "enforcementMode": "pre_transaction_check", "delegationScope": { "may_delegate_further": false }, "tradingMandate": { "maxNotionalPerOrder": 10, "unit": "USD", "allowedVenues": [ "Raydium CLMM", "Raydium AMM", "Orca", "Whirlpool", "Meteora DLMM", "Phoenix" ], "allowedInstruments": [ "So11111111111111111111111111111111111111112", "EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v", "Es9vMFrzaCERmJfrF4H2FYD4KCoNkY11McCe8BenwNYB" ] } }, "credentialSchema": { "id": "https://observerprotocol.org/schemas/delegation/v2.2.json", "type": "JsonSchema" }, "proof": { "type": "DataIntegrityProof", "cryptosuite": "eddsa-jcs-2022", "created": "2026-06-23T23:21:36.322697Z", "verificationMethod": "did:web:bitcoinsingularity.ai#key-1", "proofPurpose": "assertionMethod", "proofValue": "z3Q233j42GhXprF9uwmt6UwnZWMsGuW7oBM2hevP6dih2GSa1hdqEA1et7sbCcs918RqYbfj6JZBXfXx1rhTR8tsv" } }
Policy Evaluation Credential
Observer Protocol
Issuer DID
did:web:observerprotocol.org
Decision
allow
Evaluated at
2026-06-23T23:44:57.297Z
Delegation credential hash
3e8abc4b19bdf58a479fd128f96f922d1db0165681940fd57685cfe925665745
Proposal hash · rail
86ea53ec…ab300 · solana-jupiter
evaluatedWithAttestations
false
Evaluator version
0.1.0-draft
Credential ID
urn:uuid:9b795c89-d7a9-4cfa-8569-cf38ebbe6ddd
Proof
did:web:observerprotocol.org#key-3
eddsa-jcs-2022 · DataIntegrityProof
z2ak3jbeZPqAAP9VfAWRAFjshPi3aw1YNKWPrPke1CouFK6oHxQoSckyCShzqyQFXMX9ExwUJzWYXSGrtGmWQZYf2
Full credential JSON
{ "@context": ["https://www.w3.org/ns/credentials/v2"], "id": "urn:uuid:9b795c89-d7a9-4cfa-8569-cf38ebbe6ddd", "type": ["VerifiableCredential", "PolicyEvaluationCredential"], "issuer": "did:web:observerprotocol.org", "validFrom": "2026-06-23T23:44:57.297Z", "validUntil": "2027-06-23T23:44:57.297Z", "credentialSubject": { "decision": "allow", "evaluatedAgainst": { "delegationCredentialId": "urn:uuid:0a1b47d9-bf85-4c10-ba32-4f653e2a90f7", "delegationCredentialHash": "3e8abc4b19bdf58a479fd128f96f922d1db0165681940fd57685cfe925665745" }, "proposal": { "proposalHash": "86ea53ec4d6ec3452d5cb59ba993652bbe5fa7fc6af02dad762902fc063ab300", "rail": "solana-jupiter" }, "evaluator": { "id": "urn:observer-protocol:evaluator:policy-core-v1", "version": "0.1.0-draft" }, "evaluatedAt": "2026-06-23T23:44:57.297Z", "evaluatedWithAttestations": false }, "proof": { "type": "DataIntegrityProof", "cryptosuite": "eddsa-jcs-2022", "created": "2026-06-23T23:44:57.297Z", "verificationMethod": "did:web:observerprotocol.org#key-3", "proofPurpose": "assertionMethod", "proofValue": "z2ak3jbeZPqAAP9VfAWRAFjshPi3aw1YNKWPrPke1CouFK6oHxQoSckyCShzqyQFXMX9ExwUJzWYXSGrtGmWQZYf2" } }
● mainnet-proven (this tx) ○ pipeline-verified, not declared here ◌ state subsystem pending → Tier 2 below
Enforced live in this mainnet tx
Per-order cap blocked $10.40 over $10 cap · swap_calls == 0 · no broadcast
Venue allowlist restricted live route · 6 AMMs · settled Raydium CLMM dual-hop
Instrument allowlist evaluated SOL, USDC, USDT-SOL mints against credentialSubject.allowedInstruments
Built + pipeline-verified · not declared by this mandate
Temporal trading-hours window · the evaluator enforces this; this mandate did not declare it
Counterparty allow/blocklist · the evaluator enforces this; this mandate did not declare it
A mandate that declares either enforces identically to the three above. Not mainnet-broadcast-proven in this record; the absence is the mandate's choice, not a gap in the evaluator.
Built + supplied-state · live feeding in development
Drawdown enforces against real P&L once the position-tracking subsystem is live · see Tier 2 below
Denied
Over-cap proposal blocked
Proposed order
150M lamports (~$10.40 USD)
Mandate cap
$10 USD
Rule fired
amountLimits.maxNotionalPerOrder
Stage reached
sidecar eval · /swap never called
Broadcast
none
swap_calls == 0 confirmed on mainnet. The evaluator blocked at the pre-signature boundary. /swap was never entered. No lamports left the wallet.
Allowed
Within-cap order settled on-chain
Proposed order
50M lamports (0.05 SOL, ~$3.47 USD)
Agent routing (pre-filter)
dexes= Raydium CLMM, Raydium AMM, Orca, Whirlpool, Meteora DLMM, Phoenix
Route taken
Raydium CLMM · dual-hop
Output
3.4682 USDC
SOL spent (swap + fees)
0.052047 SOL
Slot
428476359 (finalized)
Enforcement does not depend on agent pre-filtering. The dexes= parameter above is agent-aware routing — a courtesy, not a security control. If an agent skips it and Jupiter routes through a non-allowlisted AMM, the evaluator catches the venue mismatch and returns DENY.
Why Jupiter for this demonstration

OP enforcement is rail-agnostic by design. Jupiter was the first execution surface we built and proven against; adapting to a different rail is adapter work, not architecture work. The choice was deliberate:

  • routePlan exposes per-venue routing pre-signature. routePlan[].swapInfo gives the evaluator exactly what venue enforcement needs to inspect before the gate. This is an unusually well-designed surface for pre-execution policy — most execution layers don't expose route decomposition at quote time.
  • The quote→swap split is a natural pre-signing hook. Enforcement sits between quote and swap — a clean boundary that doesn't require patching the transaction format or intercepting at the signing layer.
  • Jupiter is where agentic Solana trading already concentrates. It's the default routing layer for automated strategies on Solana. Enforcement matters most where agents actually operate.
  • DEX-agnostic routing mirrors rail-agnostic enforcement. Jupiter aggregates across many AMMs; OP enforces across many rails. Both are neutral coordination layers. The structural analogy is precise, not rhetorical.
Tier 2 Drawdown Rule

Rule verified against supplied state. The rule is built and enforces correctly against the evaluator's 8-rule pipeline. Live position feeding (mark-to-market, P&L aggregation) is in development. This section is not live-enforced.

The evaluator enforces dailyDrawdownCap when context.currentDailyDrawdown is supplied. The boundary is at or above (≥): a reading exactly at the cap (e.g. 5.0% vs a 5% cap) blocks, per the DenyReason message "has reached the cap." If no figure is supplied, the rule is dormant — not fail-closed. It activates the moment live position data arrives.
Dry-run DenyReason (supplied state: currentDailyDrawdown=7.2%, cap=5%)
{
  "ruleType":     "drawdown",
  "ruleField":    "dailyDrawdownCap",
  "currentValue":  7.2,
  "proposedValue": 5,
  "message": "Daily drawdown of 7.2% has reached the 5% cap
              (24h window, type: percent). No further orders
              permitted until the window resets."
}
7.2% supplied vs 5% cap — DENY (swap_calls=0)
5.0% supplied vs 5% cap — DENY at boundary (≥ semantics)
4.8% supplied vs 5% cap — ALLOW (under cap)
No state supplied — dormant, ALLOW
No cap declared in mandate — rule skips, ALLOW
Status: rule built, 7/7 scenarios passing against supplied state. The state subsystem (price feed, P&L aggregation, mark-to-market) is in development. This section moves to Tier 1 when live position data feeds the evaluator. Drawdown is not live-enforced in this record.
Verify it yourself

Both DID documents are static files at their respective domains. Neither step touches api.observerprotocol.org. Verification requires only curl and python3.

What this establishes, precisely: that the signature on each credential is sound against the key its issuer publishes. That is a real check and it needs nothing from us. It is not verification of the credential as a whole — one of the two is a PolicyEvaluationCredential, and no verifier exists for that type in the published engine, the hosted service, or the schema set. Checking a signature and verifying a credential are different operations, and only the first is available here.

1
Resolve the principal's key
Fetch the DID doc at bitcoinsingularity.ai. Confirm #key-1 is listed in assertionMethod.
curl -s https://bitcoinsingularity.ai/.well-known/did.json \ | python3 -c " import json, sys doc = json.load(sys.stdin) k = next(v for v in doc['verificationMethod'] if '#key-1' in v['id']) am = doc.get('assertionMethod', []) print('id: ', k['id']) print('type: ', k.get('type','')) print('in assertionMethod:', k['id'] in am or any('#key-1' in str(x) for x in am)) print('key: ', k.get('publicKeyMultibase','')[:40], '...') "
2
Resolve the evaluator's key
Fetch the OP DID doc. Confirm #key-3 is in assertionMethod — a different domain, a different key from #key-1.
curl -s https://observerprotocol.org/.well-known/did.json \ | python3 -c " import json, sys doc = json.load(sys.stdin) k = next(v for v in doc['verificationMethod'] if '#key-3' in v['id']) am = doc.get('assertionMethod', []) print('id: ', k['id']) print('type: ', k.get('type','')) print('in assertionMethod:', k['id'] in am or any('#key-3' in str(x) for x in am)) print('key: ', k.get('publicKeyMultibase','')[:40], '...') "
3
Fetch the delegation credential this evaluation cites
Confirm issuer is bitcoinsingularity.ai (the principal, not the evaluator), $10 cap, no drawdownCap declared.
Read what you are fetching. This credential is superseded and its structure is incomplete. It expired on 4 August 2026. It declares authorizationLevel: policy without the authorizationConfig.policy that level requires, so our own verifier denies it: [schema] structure: authorizationLevel policy requires authorizationConfig.policy. It is typed DelegationCredential where every other delegation on this site is an ObserverDelegationCredential. It carries no credentialStatus, and it pins schema v2.2 while v2.7 is the current one.
It stays published, and this step keeps pointing at it, because the evaluation credential binds this exact document. The PEC records delegationCredentialHash 3e8abc4b, so substituting the current mandate would break the binding this section exists to demonstrate. The hash check below establishes that the two are the same document. That is the only claim being made about it here. The register carries the same status at registry.html.
curl -s https://observerprotocol.org/credentials/maxi-0001-trading-mandate.json \ | python3 -c " import json, sys, hashlib c = json.load(sys.stdin) print('issuer: ', c['issuer']) print('vm: ', c['proof']['verificationMethod']) print('suite: ', c['proof']['cryptosuite']) m = c['credentialSubject']['tradingMandate'] print('cap: ', m['maxNotionalPerOrder'], m['unit']) print('venues: ', len(m.get('allowedVenues',[])), 'venues') print('drawdown:', 'dailyDrawdownCap' in m) # Verify credential hash matches the eval credential's recorded hash no_proof = {k:v for k,v in c.items() if k != 'proof'} jcs = json.dumps(no_proof, sort_keys=True, separators=(',',':')).encode() h = hashlib.sha256(jcs).hexdigest() expected = '3e8abc4b19bdf58a479fd128f96f922d1db0165681940fd57685cfe925665745' print('hash match:', h == expected, '(', h[:16], '...' ,')') "
Expected hash: 3e8abc4b19bdf58a479fd128f96f922d1db0165681940fd57685cfe925665745
4
Confirm the on-chain transaction
The finalized Solana tx at slot 428476359 proves the ALLOW scenario reached settlement. From-address is the demo agent wallet; route is Raydium CLMM.
explorer.solana.com/tx/61FKp9AGh33TCHP4Gow…EZgJMX