Proof deck · Arc testnet 5042002

Every feature — working, with its real outcome.

No slideware. Each capability below is driven live and shown producing a real result: a signed verdict, USDC released to the sources that verified and refused to the ones that didn't, and on-chain transactions you can open on ArcScan and check yourself. Merit's one rule holds throughout — money moves only if the cited work is correct.

Live · merit-ecru.vercel.app Proof-of-citation gates on-chain settlement ▶ Watch the 2-min demo Jump to the on-chain proof ↓
01 · The one idea

Anyone can send money. Merit decides who earned it.

Agents read creators' work and pay flat fees with no proof it was used or correct. Merit escrows USDC, verifies every citation with a deterministic numeric check, an NLI factual-consistency gate, and an adversarial judge — and releases payment only for citations that actually hold up, refunding the rest. The verifier is the settlement layer under a dozen capabilities; the rest of this deck shows each one working.

The full Merit platform — a card grid of every capability
Surface The full platform, one verifier underneath — proof-of-citation gates settlement, the consensus jury, compliance, the statement, the verifier, AP2 mandates, metering/streaming/buy, and the benchmark. Every card is a live page.
02 · The signature journey

The autonomous agent loop settles real money — and refuses.

Give it a question and a USDC budget. The lead agent hires search / write / verify specialists, escrows against each candidate source, writes a cited answer, then releases sub-cent USDC to the sources whose citation verified, refunds the ones it didn't use, and slashes the stake behind a citation that fails. Every settlement is a signed receipt.

Escrowed
$0.298
held against 8 candidate sources
Released
to verified
cited + verified sources, per-nanopayment
Refused
paid $0
uncited / unsupported — refunded, with the reason
The live agent run: settlement ledger, receipts, per-source release/refuse decisions, and the cited answer
Live run One run on the homepage: the live settlement ledger, receipts (✓ RELEASE StableData +$0.0053, Chainletter +$0.018), every source marked Released or Refunded with an audit reason, the paid crew, and the cited answer.
03 · The verifier

Three gates. A claim passes only if the source really supports it.

The Citation Verification Oracle runs a deterministic numeric check, a factual-consistency (NLI) score, and an adversarial LLM judge. A fabricated figure is REFUSED with no model at all; a genuinely supported claim is SUPPORTED — and every check returns a shareable, offline-verifiable signed receipt.

A fabricated $40T figure returns a REFUSED verdict
Refused Claim says $40 trillion, source says $4.1T → REFUSED by the deterministic numeric check, with a signed receipt.
A genuinely supported claim returns a SUPPORTED verdict
Supported A claim the source genuinely backs → SUPPORTED, all gates confirm, signed and settleable.
A shareable, signed proof-of-citation receipt
Signed receipt Every verdict is a shareable receipt: the claim, source, the three gates that decided it, and a signer you recover offline — no need to trust Merit's server.
04 · The consensus jury

A diverse, TEE-attested panel grades truth vs lie, per claim.

The premium high-assurance tier decomposes an answer into atomic claims and escalates the borderline ones to a panel of models from different families (DeepSeek / GLM / Qwen / MiniMax / Kimi), each TEE-attested. A reputation-weighted supermajority decides, settlement is graded per claim, and the whole panel is committed under a Merkle root in a signed merit.cvo/v3 certificate.

Five diverse models vote per claim: a true claim supported, a false claim refuted
Consensus Two atomic claims, five models each. The true claim → 100% → ✓ SUPPORTED; "solar flares drove adoption" → 0% → ✕ REFUSED. Every ballot TDX attested; 10 ballots, Merkle-committed, signed.
05 · Compliance pre-gate

Compliance-cleared AND work-verified before any USDC moves.

Before Merit settles to a payee, the recipient is screened against Circle's Compliance Engine, with an operator denylist as an authoritative hard floor. A denylisted address is blocked; a clean address is answered live by Circle — and the honesty is exact: a local approval is never presented as a sanctions clearance.

A denylisted payee returns DENIED
Denied An operator-denylisted address → DENIED — the authoritative hard floor blocks the payout.
A clean address is approved live by Circle
Circle A clean address answered live by Circle Compliance Enginesource: circle, vendor-cleared.
06 · The verified-spend statement

One signed number no pay-on-retrieval tool can show.

A single offline-verifiable statement composes the verification chain, the on-chain settlement total, compliance, and the jury. The headline is the refusal rate — money moved only for citations that verified; the refused ones were paid $0. The signer recovers offline; the audit chain is tamper-evident.

The verified-spend statement: the refusal-rate headline and composed metrics
Statement ~76% of citations refused → paid $0. Real cumulative USDC settled on Arc, jury panels, compliance screenings, cache savings — signed, downloadable, and independently checkable.
07 · Break Arena

The only market that dares you to get a lie paid.

Mis-cite a source and watch the verifier refuse it before a cent moves. A fabricated figure is caught by the deterministic numeric verifier with no LLM call, and the on-chain settlement reverts — every failed attempt is harvested into the public gold set, so the verifier gets harder to fool as you attack it.

An attack on the verifier is HELD — the lie was refused
Held A fabricated citation → HELD — the lie was refused before any USDC moved. A lie is the one thing that cannot get paid here.
08 · On-chain settlement — the flagship

Proof-of-citation gates the escrow release, on-chain.

The MeritVerificationHook (an ERC-8183 IACPHook) binds the on-chain escrow release to the verdict. A verified citation lets complete() release the escrow; a failed one makes complete() revert and refunds — proven with two real job lifecycles below. Nobody else gates settlement on whether the WORK is correct.

Job #50 · verified
RELEASED
complete() released 0.01 USDC escrow
Job #51 · failed
REVERTED → REFUND
hook blocked complete(), then refunded
Finality
< 0.6s
Success on Arc testnet 5042002
ArcScan: complete() released 0.01 USDC from the MeritJob escrow, status Success
Arc · Success The operator called complete on MeritJob → ✓ Success, escrow 0.01 USDC released 0xdF…6A05 → 0x41…2333. Confirmed in 0.51s.
ArcScan: the deployed MeritJob contract
Arc The deployed MeritJob escrow contract that the hook gates — 0xdF81…6A05, live on Arc testnet.
09 · The creator side

Creators get paid — instantly, in USDC, only for verified citations.

Every creator has a Merit Link: a public citation toll. Onboard by pasting an RSS feed or proving a domain — no wallet, no key — and earn USDC every time an agent's citation of your work passes verification, with a "Cited by AI — Verified by Merit" badge no self-report agent can forge.

A creator's public Merit Link citation toll
Merit Link A creator's public citation toll — cite them here and Merit settles real USDC on Arc, gated by the same verification. Shareable, embeddable, QR-ready.
Domain passport and the Cited-by-AI badge
Passport Prove your domain → an owner-verified identity, the unforgeable "Cited by AI — Verified by Merit" badge, and withdraw earnings held in custody.
Onboard a creator from an RSS feed
Onboard Paste an RSS feed → become a citable, payable creator with an on-chain ERC-8004 identity in under a minute. No account, no key.
10 · The agentic-economy hub — one oracle, every hat

Everything an agent — or a human — needs, gated by the same verification.

Every competing project built a payment and skipped the reason to release it — they gate on identity, reputation, uptime, relevance, or the generator's own say-so, because none has a ground-truth verifier. Merit does. So the same proof-of-citation gate becomes the score on any endpoint, the release on any escrowed job, the resolver of any market, and the match-check on any clip — with Circle rails carrying value in and out. Each capability below is live on the deployment and proven with a real outcome.

Verified Inference: attested + verified AI over x402
Flagship · Verified Inference Don't sell AI tokens — sell AI proven to have run correctly and proven to be right. A 0G TEE-attested model answers, Merit's verifier (a deterministic numeric gate plus an adversarial judge that is itself an attested 0G model) checks it, and you pay per call in USDC on Arc only if it verifies. Live on prod: an attested DeepSeek-V4 completion carrying a real 0G handle (provider 0xB01EBd79…, TDX / TeeTLS), and a verified answer where both the generation and the verification are TDX-attestedSUPPORTED, charged $0.004; a wrong answer costs $0.
Endpoint scorecards leaderboard
Scorecards Score any x402 endpoint on the one axis a rail can't see — Merit pays the toll, verifies the answer, and publishes a verified-quality-per-dollar leaderboard. Live: a full three-gate SUPPORTED at 0.933 and a numeric REFUSE at 0. Turns every other agent into a data point.
Verified escrow board
Escrow board Post a bounty; a worker — human or agent — delivers; Merit's real grader releases escrow only if every requirement is met. Live: on-brief → ACCEPTED 3/3 → hook job #56 released on-chain; off-brief → REJECTED, $0. The evaluator three competitors shipped fake.
Ground-truth prediction market
Ground-truth markets A market on "will this claim verify?", settled by Merit's own verifier as the on-chain oracle — no human committee. Live: the Eiffel market resolved YES → stake→resolve→redeem on-chain; the strict gate settled the other NO.
Provenance-verified media licensing
Media licensing License a clip, image, or audio only if its provenance verifiably matches your request — the citation gate on a new modality. Live: a match at 0.973 → hook job #57 released the fee on-chain; a non-match → REFUSED, $0. You never pay for media that isn't what it claims.
Cross-chain payout via Circle Gateway
Cross-chain payout Withdraw verified earnings from Arc to Base, Arbitrum, Optimism, or Avalanche via Circle Gateway — the last mile of getting paid where you want it. Live: a real Arc Gateway settlement tx; the cross-chain leg settles the moment the payout wallet holds a little destination-chain gas.
11 · The full agent-facing surface

Every capability, one real outcome each.

Beyond the flagship flows, Merit exposes the whole agentic payment stack over clean APIs — each shown here producing a real result on the live deployment. This is the breadth a verify-nothing tool can't match; the verifier sits under all of it.

Verified Citation Toll — the moat door

A neutral gate any rail or publisher calls before releasing a per-citation payment — the correct-use check Cloudflare / TollBit / ProRata skip. Your rail settles on the signed verdict.

POST /api/toll/verify → SUPPORTED release $0.002 · conf 0.987 · 4 gates · signed · contradicted figure → REFUSE $0
Max-0G verified-quality-per-$ router

Resells the full live 0G roster — 13 TEE-attested chat models + a vision model, both trust modes and both API surfaces — and routes by pass-rate² ÷ price, not cheapest.

POST /api/inference {route} → picked deepseek-v4-flash · SUPPORTED · attested from 13 models
Verified vision extraction

0G's attested vision model reads a figure from an image; Merit grounds the answer in the model's own transcription — a fabricated figure is refused by the same numeric gate.

POST /api/inference {tier:vision} → read "42B" → SUPPORTED + TDX-attested
ERC-8183 evaluator-of-record

The reusable evaluator any external escrow drops into the ERC-8183 evaluator slot: a signed accept/reject certificate its own hook settles on. Merit doesn't hold the escrow; a dispute is a deterministic re-grade.

POST /api/evaluator → on-brief release $0.05 · off-brief refund $0
Verify-gated x402 facilitator

Pay any x402 seller, but keep the payment only if the delivered work verifies — a signed keep/dispute verdict on the content you paid for. A rail that pays on HTTP-200 trusts blindly.

POST /api/facilitator → keep on verified · dispute on unsupported · reuses payAndFetch
Licensing-compliance audit

Sample an AI output's claims against a licensed source and flag misattribution — the audit layer bulk AI-licensing deals (OpenAI/Meta with publishers) lack.

POST /api/license/audit → 2 claims → 1 supported, 1 misattributed → signed royalty-true-up report
Buy agent — verified-quality-per-$

Ranks buyable sources by verified quality per dollar and pays only the first whose delivered content actually verifies.

POST /api/buy → bought StableData $0.00531 · SUPPORTED · $0 wasted on a pay-on-delivery rail
AP2 signed-mandate chain

A human-signed Intent→Payment mandate is a precondition of the gate: clears only when authorized AND verified.

POST /api/mandate/settle → authorized ✓ · verified SUPPORTED · cleared · bad signature → 403
Tx-simulation pre-flight

Dry-runs the transfer against Arc before broadcast, so a doomed payout is caught before it spends gas.

POST /api/simulate → wouldSucceed:false · "insufficient USDC: 16.85 < 999999"
Verified net settlement

Authorize a basket of N cited lines; settle only the verified subset, quarantine the rest.

POST /api/settle/batch → verified subset settled, unverified quarantined
ERC-8004 two-sided reputation

A portable, on-chain track record from release-vs-refund history; stronger records price higher.

GET /api/reputation/stabledata → merit 95 · portable release-rate
Machine-readable discovery

A public directory + x402 manifest so an agent shortlists by a signal a price/latency listing can't emit.

GET /api/directory → 21 sources ranked by verified-quality-per-$
Verified streaming

Pay-per-tick with numeric-tier checkpoints — the stream auto-halts and refunds on quality drift.

POST /api/stream → per-tick settle · auto-halt + refund on drift
Prepaid balance + 402 metering

Fund once; burn down only on verified citations — refused ones are free — over gasless x402.

POST /api/verify/balance → burn-down only on verified · refused = $0
Session-key delegation

A short-lived verify-only key spends the parent's balance up to a cap, and can be used nowhere else.

POST /api/session → scoped key · 403 at any other endpoint
AP2 fulfillment credential

On a verified settlement, mints a signed, offline-recoverable proof-of-satisfaction a downstream rail can gate on.

POST /api/fulfillment → signed merit.fulfillment/v1, recovers offline
Procurement + seller firewall

Verify an external seller's delivered content vs the claim; firewall hosts below the verified-delivery bar.

/api/procure + /api/sellers → verify delivery · firewall low-rep hosts
Operator safety guard

A second settlement predicate: kill-switch, daily hard cap, and velocity auto-freeze on the settlement path.

/api/admin/freeze → one-call freeze · daily cap · velocity auto-halt
Verdict-carrying webhooks

Signed events on settle/refund whose payload carries the settlement reason — settled-because-verified vs refunded.

/api/webhooks → signed events + the settlement reason
Verified-citation cache

A proven (claim+source) is never re-verified or re-paid; re-verifies automatically when the source changes.

reuse the signed verdict · re-verify on source change — the margin engine
Self-improving Auditor

Learns its payout threshold from appeals while the decision stays gold-set-safe.

/api/learn → calibrates payout from appeals · decision untouched
MCP tool — one-line install

The verifier as an MCP tool (verify_citation) any agent installs via npx — pay only if the citation verifies.

verify_citation over MCP → signed verdict inline
12 · Falsifiable + the live ledger

Scored on a public gold set. Every settlement on a live ledger.

The verifier is measured on a fixed, hand-labeled gold set — reproducible from a fresh checkout, not a self-reported number — and co-evolves with live adversarial traffic. Every real settlement lands on a public ledger where each row is a signed receipt, most deep-linking a real Arc transaction.

The proof-of-citation benchmark on a fixed gold set
Benchmark Precision/recall on a fixed public gold set — reproduce with npm run judge-eval.
The live traction ledger: verified vs refused, USDC settled, signed receipts
Ledger The live ledger — verified vs refused, real USDC settled on Arc, every row a signed receipt.
The Citation Honesty Index
Honesty The Citation Honesty Index — a grounding rate you earn only by routing citations through the verifier.
The Merit landing page
Home The landing page — merit-ecru.vercel.app, live on Arc, settled in USDC.
13 · On-chain transaction index

Open any transaction and verify it yourself.

The proof-of-citation hook lifecycle, twice — a verified job that released and a failed job that reverted then refunded. Every hash has a successful receipt on Arc testnet 5042002. Click through to ArcScan.

Verified → RELEASED MeritJob #50

Failed → REVERTED → REFUND MeritJob #51

Deployed contracts Arc testnet 5042002