FLAG SHIP USE CASE — E-COMMERCE

Live Proofs for AI agents in e-commerce.
See the evidence.

High-volume refunds, payouts and chargebacks executed by agents. Human in the loop. One tamper-evident composite receipt that any regulator, partner or customer can re-verify offline — with zero trust in us.

€49 real example 4 independent proofs Browser + CLI
E-commerce reality
Agent proposes refund on order:demo-7421
Human approves via credentialed dashboard
Composite receipt: action + credit-note PDF + HITL authorization
Anyone drops the file into the verifier — PASS or FAIL with named failure.
1 receipt3 layers bound4 proofs
Why e-commerce is the flagship

Agents already issue refunds and payouts. Regulators will ask: prove a human authorized it.

E-commerce is the highest-stakes, highest-volume, lowest-tolerance environment for agentic actions. A €49 refund looks small — until it's 18,000 of them, chargebacks spike, or an auditor arrives.

The old claim

Dashboard screenshot. Internal log entry. "Approved by admin-42". All inside your system. A motivated actor (or compromised agent) can rewrite it. Auditors have to believe you.

The live proof

One signed composite record: the exact agent intent, the generated credit-note artifact, and the human credentialed approval. Re-check the signature, the inclusion proof in the transparency log, the timestamp, and the Bitcoin anchor — entirely offline.

Typical e-commerce journey: Agent receives x402/AP2 payment instruction or customer service trigger → proposes refund + credit note → human reviews in dashboard and signs approval → PayBotFin witnesses the composite → receipt emitted. The receipt proves the three things happened together, unaltered since.
Unfolding demo

Watch the e-commerce proof unfold — and break when forged.

Full interactive (e-commerce)
Scenario: E-commerce refund — order:demo-7421, €49.00, credit note generated, human approved via HITL credential.
4 proofs • browser-native WebCrypto • no network
1. Agent action 2. Human approval 3. Composite receipt 4. 4-proof verify

The demo runs 100% in your browser. Flip a byte in the credit-note digest or the inclusion proof and it fails with the exact broken check named. Same verifier the CLI uses.

The four proofs — visual

Click any infographic for the full view + e-commerce caption.

Each proof is independent. Together they make a receipt that is extremely hard to fake after the fact.

✍️ Signed (DSSE + Ed25519)
The entire composite payload is signed. Any edit breaks the signature.
E-comm: proves the exact refund intent + credit note hash + approval were bound at signing time.
📜 Logged (RFC 9162 inclusion)
Inclusion proof in an append-only transparency log. You recompute the root yourself.
E-comm: the refund record cannot be omitted from the public log later without detection.
⏱️ Timestamped (checkpoint + OTS)
Signed checkpoint + Bitcoin-anchored time. Cannot be backdated.
E-comm: regulator sees the refund authorization existed on this date — not invented during audit.
🔎 Offline-verifiable (AWP)
Free open verifier. No call home. CLI or browser. Full transparency.
E-comm: your partners or customers can independently prove the authorization without trusting PayBotFin or you.

All four are exercised on the same e-commerce composite receipt in the demo.

Separated verifiers

Four independent checks. One of them failing is enough.

The verifier is deliberately separated. You see exactly which gate rejected the receipt. Perfect for e-commerce audits and partner reconciliation.

VERIFIER 1

Signature (Ed25519 over DSSE PAE)

Recomputes the signing payload and verifies the detached signature against the public key in the receipt.

VERIFIER 2

Inclusion proof (RFC 9162)

Folds the leaf hash up the sibling path. Must reproduce the signed Merkle root in the checkpoint.

VERIFIER 3

Checkpoint + timestamp

Verifies the checkpoint signature and that the log size at time of inclusion is consistent. OpenTimestamps anchor provides external time.

VERIFIER 4

Anchor & profile constraints

Structural validity of the composite profile, claim classes within honesty bounds, and Bitcoin time anchor.

Ready to see it in action?
The full unfolding demo defaults to the e-commerce refund scenario with live tampering controls.
Launch full verifier (e-commerce)
For prospects & auditors

This is what "proof" looks like for e-commerce platforms.

  • Agent proposes refund or payout
  • Human reviews exact intent + artifact
  • Record is witnessed by neutral third party
  • You ship the receipt with the transaction
  • Regulator / partner / customer verifies with zero trust in your logs
Honesty note (e-commerce)
This proves the record was unaltered after witnessing and that a recorded human credential approved it. It does not prove the human was the "right" person for the business rule, nor that the customer request was legitimate. Those are separate controls. What it does prove: you cannot rewrite history after the fact.

Make every consequential e-commerce action provable.

Pilots are open. Verifying is free forever. The neutral witness service is what you pay for.