# SITEBORNE Developers

Integrate around existing infrastructure. Do not rebuild it for SITEBORNE.

The production quickstart targets the **current live v2 runtime**. Release 3 is exposed separately as a candidate contract for inspection and qualification; do not invoke candidate services as though they were production.

## Release model

### Production contract — LIVE V2

Authoritative executable state: `https://utility.siteborne.net/`

1. Read `https://utility.siteborne.net/openapi.json`.
2. Inspect `/catalog` and `/services/{service_id}`.
3. Choose a production-enabled v2 mode.
4. Send the canonical request without `PAYMENT-SIGNATURE` to receive the x402 `402` challenge.
5. Validate the challenge locally, authorize/sign payment locally, and retry the identical request body with `PAYMENT-SIGNATURE`.
6. Preserve the returned result, PCC/receipt evidence, and `PAYMENT-RESPONSE`.
7. Re-read runtime metadata on deployment and whenever the release changes.

Current paid live v2 routes:
- `POST /v2/verify/agent-output` — `verify_agent_output.v2`, standard, **$0.017/request**, production enabled.
- `POST /v2/web/context` — `web_context_verified.v2`, direct, **$0.008/request**, production enabled.

Defined but not currently purchasable:
- `company_evidence_graph.v2` — `$0.0312/request`, disabled.
- `document_evidence_json.v2` — authorization maximum `≤$0.19/job`, disabled.
- rendered web — `$0.029/request`, not production admitted.
- independent reproduction — `$0.049/request`, not production admitted.

### Release 3 candidate — CANDIDATE / PRE-RELEASE QUALIFICATION

- Service Contract: `3.0.0`
- PCC schema: `2.0.0`
- PCC result: full proof-carrying result envelope
- Candidate services:
  - `company_evidence_graph.v3`
  - `web_context_verified.v3`
  - `document_evidence_json.v3`
  - `verify_agent_output.v3`

Result authorization in the candidate:
- public services — contract-governed output;
- `document_evidence_json.v3` — `BUYER_AUTHORIZED`;
- `verify_agent_output.v3` — `BUYER_AUTHORIZED`.

Candidate economics are governed release metadata and **not yet production-purchasable**:
- Company Evidence — `$0.0312/request`
- Web Direct — `$0.008/request`
- Document Evidence — native `$0.0098/page`; OCR `$0.0156/page`; table `$0.0238/page`; authorization maximum `$0.19/job`
- Verify Standard — `$0.017/request`

Release 3 machine-surface state:
- MCP — candidate execution wiring implemented; projection convergence **QUALIFYING**; not production activation.
- A2A — candidate projection tracked separately from the live Agent Card.
- OpenAPI — release-qualified candidate artifact `contracts/releases/3.0.0/openapi/service-contracts.openapi.json`; live `/openapi.json` remains production authority.
- Catalog / Registry — candidate convergence **QUALIFYING**.

No full 4×4 production-convergence claim is made.

## Canonical integration model

`VCM Capability Contract`
→ `Policy + Authority Decision`
→ `Causal Execution State`
→ `Assurance Decision`
→ `PCC two-proof envelope`
→ governed result handling where required
→ `Settlement Authority`

VCM defines what must be true. AVUF determines how to fulfill it. PCC proves what happened.

Keep these distinct:
- identity
- mandate
- policy
- payment authorization
- execution authority
- result authorization
- proof/evidence
- settlement authority

Invariants:
- result existence ≠ result authorization;
- payment receipt ≠ settlement authority;
- PCC ≠ permission;
- supplier capability ≠ qualification;
- payment ≠ identity;
- execution success ≠ contract satisfaction.

## Four machine surfaces

Production and candidate states must not be conflated.

- **MCP:** current published endpoint is `https://utility.siteborne.net/mcp`; an endpoint migration is in progress, so integrations should follow governed discovery metadata rather than assume this URL is permanent. Release 3 candidate wiring is qualifying for projection convergence.
- **A2A / Agent Card:** live runtime card at `https://utility.siteborne.net/.well-known/agent-card.json`; Release 3 candidate projection tracked separately.
- **OpenAPI:** live authority at `https://utility.siteborne.net/openapi.json`; Release 3 candidate contract is a release artifact, not the live default.
- **Catalog / Registry:** live runtime/catalog state remains authoritative; Release 3 candidate convergence is qualifying.

## Governing thin waist

Current governing architecture separates:

`AuthorityGrant → ExecutionLease + fencing → CommitGrant (where required) → Assurance → FinalPccDocument → Result Authorization + ResultBinding → Settlement Authority + SettlementGrant`

This is **GOVERNING DESIGN** unless fresh repository/runtime evidence establishes a stronger implementation state. It does not promote these primitives to production by documentation alone.

## Contract Lab

The rendered Developers page exposes a browser-only Contract Lab at `developers.html#contract-lab`.

It demonstrates one public concept without making a network call or exposing private qualification logic:
- matching claims/evidence → ACCEPT;
- material mismatch → REJECT;
- required evidence missing → REJECT.

The demo is explanatory, not production execution.

## Integration posture

Use existing gateways, identity systems, runtimes, orchestration frameworks, observability systems, discovery/catalog systems, provenance systems, and payment mechanisms where they fit.

External systems may remain authoritative for the jobs they already own. Within SITEBORNE they provide evidence, adapters, or projections rather than silently becoming canonical authority over contract satisfaction.

## Public discovery

- Product machine manifest: `https://siteborne.com/machine-manifest.json`
- Runtime root: `https://utility.siteborne.net/`
- Live OpenAPI: `https://utility.siteborne.net/openapi.json`
- Readiness: `https://utility.siteborne.net/ready`
- Health: `https://utility.siteborne.net/health`
- Catalog: `https://utility.siteborne.net/catalog`
- MCP: `https://utility.siteborne.net/mcp`
- A2A: `https://utility.siteborne.net/.well-known/agent-card.json`
- Network / release documentation: `https://siteborne.net`

No first-party SDK is claimed by this website.


## Fresh external propagation snapshot — 2026-09-24 UTC

Current public observation is intentionally kept separate from SITEBORNE authority.

- Fresh runtime readiness reports `status=ready`, `phase=production`, and paid production services active.
- `siteborne.net` still states that paid services are disabled by policy. This is first-party publication drift and should be reconciled; it does not override runtime state.
- Agenstry observes A2A 1.0, 8 declared skills, x402 metadata, machine/search discovery, and 100% 30-day uptime. Its mutable trust/owner fields have varied across current indexed views, so those scores are not canonical SITEBORNE facts.
- MCPMetrics observes 6 MCP tools and 79/79 successful probes over its current 30-day window, with p50 latency around 706 ms.
- Glama independently observes 6 tools and a healthy endpoint, but its longer-window uptime differs materially from MCPMetrics; the two measurements are preserved rather than averaged.
- Small Print tracks two registry versions, 11 semantic changes in one release, and 0 recorded public advisories at this observation.
- PluginBench exposes the official registry identifier `net.siteborne/utility` and direct Streamable HTTP configuration.
- Mcprush currently misinterprets the server as 0 tools / free. Treat this as observer/parser drift, not SITEBORNE runtime truth.
- FastDrop currently records repeated probe failures despite successful observations by other MCP observers. This is a monitoring/probe-compatibility conflict requiring re-check.
- Search indexes still expose some historical SITEBORNE paths/copy, so search identity convergence is incomplete.
- No confirmed public chain transaction, third-party package integration, or organic community adoption signal was established in the searched sources. Absence of evidence is not evidence of nonexistence.

Machine-readable evidence and monitoring configuration:
- `/osint-snapshot.json`
- `/monitoring-manifest.json`

External observers are evidence only. They never become execution, release, pricing, settlement, or semantic authority.
