Not "an agent." Infrastructure for safely selling to agents.
A resource server that serves only requests which are paid (x402 on Sui) and backed by a proven unique human (Proof of Real) — then lets the agent remember (Walrus Memory) and reason about its spending (a local LLM). The stack is trust-minimized: non-custodial payments, on-chain-verifiable identity and settlement, and local inference (see Trust model for what's still hosted).
Payment proves funds. It does not prove who is behind the request. A paid endpoint is still trivially sybil-farmed. This gate adds "one real, unique human per agent" — verified on-chain, no KYC, no captcha, no allowlist.
flowchart LR
A[agent] -->|GET| R[resource]
R -->|402 + terms + personhood req| A
A -->|signed Sui payment| R
R -->|derive payer from signature| P{PoR: unique human?}
P -->|no| X[403 — never charged]
P -->|yes| S[settle via facilitator]
S --> V{recompute on-chain?}
V -->|net != terms| X2[402]
V -->|matches| D[200 + data]
Personhood is checked before settlement (an un-verified agent never pays), and the settlement is recomputed on-chain (don't trust the facilitator). The paying key is the identity we check — no client-claimed addresses.
| Layer | What | Built on |
|---|---|---|
| 🪪 Identity | unique-human gate (sybil-resistant, ZK uniqueness) | por-sdk on Sui |
| 💸 Payment | x402, settled on Sui, recomputed on-chain | live sui-facilitator.onrender.com |
| 🧠 Memory | portable, encrypted, on-chain-owned, cross-session | Walrus Memory (@mysten-incubation/memwal) |
| 🤖 Brain | memory-driven spend control (pay only for the unknown) | local Ollama (qwen2.5-coder:14b) |
pnpm install
node --env-file=.env --import tsx src/demo.ts # the flagship demo (all four layers)Per-layer demos: src/demo-b0.ts (gate), src/demo-b1.ts (memory), src/demo-b2.ts (brain).
Setup helpers: src/init.ts (identities + faucet), src/brain-check.ts (model sanity).
The brain defaults to local Ollama; set BRAIN_PROVIDER=anthropic + ANTHROPIC_API_KEY to swap.
This composition wants to be a standard, not a one-off. See
spec/x402-personhood-gated-resource.md —
a sketch for an x402 extension where any resource can require a personhood proof
alongside payment, composable with the settlement-receipt binding work
(#2666).
Verification is trustless: the settlement is recomputed on-chain (don't trust the facilitator), and the credential + uniqueness proof are on-chain objects anyone can read. Liveness and issuance are not (yet) decentralized: the x402 facilitator and the Walrus Memory relayer are hosted services, and credential issuance depends on a trusted attestor. Only inference is fully local. So "trust-minimized" here means non-custodial + on-chain-verifiable + local reasoning — not "no servers."
- Testnet. Real settlements, test funds.
- Personhood ≠ authority. This proves a unique human is behind the agent — not that the agent is authorized to act for them, and not KYB/KYC. Don't use it as an authorization or compliance primitive.
- Assurance is a spectrum. L0 = live human + device;
unique:trueis what makes it sybil-resistant. A resource should require the level its threat model needs.
The agent itself isn't the product — it's the keystone demo that ties together a zero-fee x402 facilitator (the wedge) and PoR (the proof-of-personhood product). It exists to show that Sui's primitives compose into an open, verifiable substrate for the agent economy.