Published 2026-09-01. Binding specification, frozen after publication.
This document is the binding specification for the settlement verification envelope, schema version settle_v1. It is frozen after publication. Changes happen only at an announced version boundary with a new schema_version.
The service answers one question about one Solana mainnet transaction and returns one signed verdict: did transaction tx credit amount atomic units of mint to payee, and optionally was payer a signer. It reads only public on chain data over the mainnet-beta JSON RPC. The paid call is 0.01 dollars in USDC on Base.
One call, one subject, one verdict. There is no composition and no aggregate score. The envelope carries the asserted claim, the verdict, a per field breakdown when the transaction is finalized, and the observation context (commitment, slot, confirmations), all signed.
The amount check is exact and at the token account level: the observed amount is the net of the asserted mint credited to the payee across the transaction's pre and post token balances. VERIFIED requires that total to equal the asserted amount exactly, not merely to be at least it.
GET /settle with query parameters:
tx: the Solana transaction signature, base58. Required.payee: the Solana address expected to be credited, base58. Required.amount: the expected atomic units of the mint credited to payee, a non negative integer. Required.mint: the SPL mint, base58. Optional, defaults to canonical USDC EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v.payer: an address expected to be a signer of the transaction, base58. Optional.schema_version: the constant "settle_v1".request: tx, and asserted with payee, amount as a string, mint, and optional payer.verdict: one of VERIFIED, REFUTED, UNCONFIRMED, NOT_FOUND, not_evaluated.chain: the constant "solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp".observed_at: RFC3339 timestamp of this observation.limitations: a non empty list of honest notes, always present.signer: the constant 0x57fF0F084Cba33e6761503f90eEF0Da9F159350c.manifest: url the constant proof manifest URL, and entry the constant "settle".signature: EIP-191 personal_sign over the canonical envelope.Present depending on verdict:
fields: for VERIFIED and REFUTED, one entry per asserted field, each with field, asserted, observed, and match. VERIFIED means every match is true. REFUTED means at least one is false, and every asserted field is still listed with its observed value.commitment, slot, confirmations: the observation context. For finalized verdicts commitment is "finalized". For UNCONFIRMED commitment is the current level and confirmations is present.searched_as_of_slot: for NOT_FOUND, the finalized slot the search was performed as of.reason_codes: for not_evaluated, at least one of rpc_timeout, rpc_error.Two refusals are part of the contract from the first version, both before any RPC read, both no charge, both no envelope:
Signer: 0x57fF0F084Cba33e6761503f90eEF0Da9F159350c, published in the proof manifest as the signer of the settle service entry. Signing is Ethereum EIP-191 personal_sign over canonical JSON: json.dumps with sort_keys true and separators of a comma and a colon, which escapes non ASCII as backslash u sequences.
To verify an envelope offline:
JSON Schema validation is necessary but not sufficient. A document can be schema valid and still be wrong or tampered. A consumer MUST also perform these checks in code, because the schema cannot express them:
0x57fF0F084Cba33e6761503f90eEF0Da9F159350c before trusting the verdict.If any of these fail, treat the envelope as untrusted, the same as a signature mismatch.
Every verdict is point in time evidence at its observed_at. A finalized Solana transaction is irrevocable, so VERIFIED and REFUTED over a finalized transaction do not decay. UNCONFIRMED and NOT_FOUND are snapshots that can change as the chain advances. This verifies that a transfer happened, not what it was for; binding a request to a payment is the facilitator layer, not this service.
This is the verified fixture, a real historical finalized USDC transfer on Solana mainnet. The signature is truncated here; the published fixture carries it in full.
{
"schema_version": "settle_v1",
"request": {
"tx": "5ygvXjuYao3MtHQkWzBvgXxjg9vWAoG6rMM6qVjPDLym...",
"asserted": { "payee": "8SfS2XEedD595GqpNGjgYpRhSAUidThXQHznExpbDwEX", "amount": "415803", "mint": "EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v" }
},
"verdict": "VERIFIED",
"chain": "solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp",
"observed_at": "2026-09-01T...Z",
"limitations": ["verifies the transfer happened, not what it paid for; request-to-payment binding is the facilitator layer", "..."],
"signer": "0x57fF0F084Cba33e6761503f90eEF0Da9F159350c",
"manifest": { "url": "https://x402.nsgoods.org/proof/index.json", "entry": "settle" },
"fields": [
{ "field": "payee", "asserted": "8SfS2XEe...", "observed": "8SfS2XEe...", "match": true },
{ "field": "mint", "asserted": "EPjFWdd5...", "observed": "EPjFWdd5...", "match": true },
{ "field": "amount", "asserted": "415803", "observed": "415803", "match": true }
],
"commitment": "finalized",
"slot": 443406404,
"confirmations": null,
"signature": "0x..."
}
GET /settle/preview is free and returns a locked preview of a real historical verification: the verified envelope above, frozen once. Three fields, preview, note and demo_note, are added after signing. To verify the preview, strip preview, note and demo_note, then remove signature and keep signer, canonicalize, and recover.
verified and refuted-amount are the same real transaction: the first with the correct asserted amount, the second with the asserted amount off by one atomic unit, a real REFUTED run with the amount field mismatch shown. not-found is a valid format signature that does not exist, a real NOT_FOUND run. invalid-subject is the real HTTP 400 refusal body. signing-unavailable is the HTTP 503 refusal body.
The paid /payable and /screen endpoints and the preflight composite are unrelated to this service. Signed report manifest at /proof/index.json.