> ## Documentation Index
> Fetch the complete documentation index at: https://docs.autolayer.fi/llms.txt
> Use this file to discover all available pages before exploring further.

# Rfp proof 2026 08 16

# x402 RFP implementation evidence — 2026-08-16

This report records reproducible implementation evidence. It does not claim the excluded third-party Audit Bank deliverable.

## Canonical exact settlement and native automatic cataloging

Command:

```bash theme={null}
pnpm --filter @autolayer/api evidence:testnet
```

The runner imports the stock `x402Client`/`x402HTTPClient` from `@x402/core@2.21.0` and `ExactStellarScheme` from `@x402/stellar@2.21.0`. It creates and Friendbot-funds a disposable payer, reads the native resource's `PAYMENT-REQUIRED`, signs the canonical `{ transaction }` payload, retries, decodes `PAYMENT-RESPONSE`, and then queries the Bazaar.

* Network: `stellar:testnet`
* Scheme: `exact`
* Asset: native XLM SAC `CDLZFC3SYJYDZT7K67VZ75HPJVIEUVNIXF47ZG2FB2RMQQVU2HHGCYSC`
* Sponsored fees advertised: `true`
* HTTP result: `200`
* Transaction: [`ed9fa12d30ed28e5c478f9ee158e0eb7148069236504e06cfd55d718d95b2e34`](https://stellar.expert/explorer/testnet/tx/ed9fa12d30ed28e5c478f9ee158e0eb7148069236504e06cfd55d718d95b2e34)
* Native Bazaar declaration present in the signed payment: `true`
* Automatically cataloged after successful settlement: `true`
* Resource: `http://localhost:5001/examples/protocol-spec`

This path uses `paymentMiddleware` plus `declareDiscoveryExtension`; it does not create or update an xWrapper.

## Search evaluation

The checked-in judged corpus contains 10 natural-language queries and 12 HTTP/MCP resources. Run `pnpm search:seed` followed by `pnpm search:evaluate` against the live discovery service.

| Metric | Result |
| - | -: |
| nDCG\@10 | 0.9983 |
| MRR | 1.0000 |
| Recall\@10 | 1.0000 |
| Mean latency | 8.20 ms |
| p50 latency | 4.04 ms |
| p95 latency | 44.07 ms |

These are local-loopback measurements and must not be represented as public-host latency. The corpus and evaluator are versioned so later production runs can be compared without changing judgments after seeing results.

## Stellar `upto`

* Contract: [`CAKEONFVADOVQW2GSS4KW7QJNSJTTREECOG4WWTXBVZRL63IGKIDYTAJ`](https://lab.stellar.org/r/testnet/contract/CAKEONFVADOVQW2GSS4KW7QJNSJTTREECOG4WWTXBVZRL63IGKIDYTAJ)
* Wasm hash: `b22c6c8d1d7ebcbe82b0edbfee18728f8e289cc56e1d7e2c5f12863a7c2c9dfa`
* Deploy transaction: [`ac9378767a55d7384a270dbb4d73588eb5b6b7b3f28c4c3c5ddc1cd3602b729c`](https://stellar.expert/explorer/testnet/tx/ac9378767a55d7384a270dbb4d73588eb5b6b7b3f28c4c3c5ddc1cd3602b729c)
* Successful settlement transaction: [`694d41f99865a418184b810c126cc7950f50df42b58040f560c1f011983a695b`](https://stellar.expert/explorer/testnet/tx/694d41f99865a418184b810c126cc7950f50df42b58040f560c1f011983a695b)
* Authorized maximum: `200000`; actual settlement: `100000`
* Replay key: persistent `(payer, nonce)` marker
* Payer and facilitator authorization: enforced by the contract

The upstream spec candidate is `specs/schemes/upto/scheme_upto_stellar.md`; the contract source is `contracts/upto-settlement`.

## Verification transcript

* API: 32 tests passed
* SDK: 11 tests passed
* Soroban contract: 2 tests passed
* API, SDK, and web production builds passed
* Live wire conformance check passed for `stellar:testnet` and `stellar:pubnet`
* License gate: 193 production packages checked; 0 strong-copyleft; 0 uncertain

Publishing the upstream PR and hosted CI URL requires a valid GitHub credential. At report time, every account in local `gh auth status` had an expired token; no PR URL or GitHub CI run is fabricated here.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.