No slideware. Each capability below is driven live and shown producing a real result: a signed verdict, USDC released to the sources that verified and refused to the ones that didn't, and on-chain transactions you can open on ArcScan and check yourself. Merit's one rule holds throughout — money moves only if the cited work is correct.
Agents read creators' work and pay flat fees with no proof it was used or correct. Merit escrows USDC, verifies every citation with a deterministic numeric check, an NLI factual-consistency gate, and an adversarial judge — and releases payment only for citations that actually hold up, refunding the rest. The verifier is the settlement layer under a dozen capabilities; the rest of this deck shows each one working.

Give it a question and a USDC budget. The lead agent hires search / write / verify specialists, escrows against each candidate source, writes a cited answer, then releases sub-cent USDC to the sources whose citation verified, refunds the ones it didn't use, and slashes the stake behind a citation that fails. Every settlement is a signed receipt.

The Citation Verification Oracle runs a deterministic numeric check, a factual-consistency (NLI) score, and an adversarial LLM judge. A fabricated figure is REFUSED with no model at all; a genuinely supported claim is SUPPORTED — and every check returns a shareable, offline-verifiable signed receipt.



The premium high-assurance tier decomposes an answer into atomic claims and escalates the borderline ones to a panel of models from different families (DeepSeek / GLM / Qwen / MiniMax / Kimi), each TEE-attested. A reputation-weighted supermajority decides, settlement is graded per claim, and the whole panel is committed under a Merkle root in a signed merit.cvo/v3 certificate.

Before Merit settles to a payee, the recipient is screened against Circle's Compliance Engine, with an operator denylist as an authoritative hard floor. A denylisted address is blocked; a clean address is answered live by Circle — and the honesty is exact: a local approval is never presented as a sanctions clearance.


A single offline-verifiable statement composes the verification chain, the on-chain settlement total, compliance, and the jury. The headline is the refusal rate — money moved only for citations that verified; the refused ones were paid $0. The signer recovers offline; the audit chain is tamper-evident.

Mis-cite a source and watch the verifier refuse it before a cent moves. A fabricated figure is caught by the deterministic numeric verifier with no LLM call, and the on-chain settlement reverts — every failed attempt is harvested into the public gold set, so the verifier gets harder to fool as you attack it.

The MeritVerificationHook (an ERC-8183 IACPHook) binds the on-chain escrow release to the verdict. A verified citation lets complete() release the escrow; a failed one makes complete() revert and refunds — proven with two real job lifecycles below. Nobody else gates settlement on whether the WORK is correct.


Every creator has a Merit Link: a public citation toll. Onboard by pasting an RSS feed or proving a domain — no wallet, no key — and earn USDC every time an agent's citation of your work passes verification, with a "Cited by AI — Verified by Merit" badge no self-report agent can forge.



Every competing project built a payment and skipped the reason to release it — they gate on identity, reputation, uptime, relevance, or the generator's own say-so, because none has a ground-truth verifier. Merit does. So the same proof-of-citation gate becomes the score on any endpoint, the release on any escrowed job, the resolver of any market, and the match-check on any clip — with Circle rails carrying value in and out. Each capability below is live on the deployment and proven with a real outcome.






Beyond the flagship flows, Merit exposes the whole agentic payment stack over clean APIs — each shown here producing a real result on the live deployment. This is the breadth a verify-nothing tool can't match; the verifier sits under all of it.
A neutral gate any rail or publisher calls before releasing a per-citation payment — the correct-use check Cloudflare / TollBit / ProRata skip. Your rail settles on the signed verdict.
POST /api/toll/verify → SUPPORTED release $0.002 · conf 0.987 · 4 gates · signed · contradicted figure → REFUSE $0Resells the full live 0G roster — 13 TEE-attested chat models + a vision model, both trust modes and both API surfaces — and routes by pass-rate² ÷ price, not cheapest.
POST /api/inference {route} → picked deepseek-v4-flash · SUPPORTED · attested from 13 models0G's attested vision model reads a figure from an image; Merit grounds the answer in the model's own transcription — a fabricated figure is refused by the same numeric gate.
POST /api/inference {tier:vision} → read "42B" → SUPPORTED + TDX-attestedThe reusable evaluator any external escrow drops into the ERC-8183 evaluator slot: a signed accept/reject certificate its own hook settles on. Merit doesn't hold the escrow; a dispute is a deterministic re-grade.
POST /api/evaluator → on-brief release $0.05 · off-brief refund $0Pay any x402 seller, but keep the payment only if the delivered work verifies — a signed keep/dispute verdict on the content you paid for. A rail that pays on HTTP-200 trusts blindly.
POST /api/facilitator → keep on verified · dispute on unsupported · reuses payAndFetchSample an AI output's claims against a licensed source and flag misattribution — the audit layer bulk AI-licensing deals (OpenAI/Meta with publishers) lack.
POST /api/license/audit → 2 claims → 1 supported, 1 misattributed → signed royalty-true-up reportRanks buyable sources by verified quality per dollar and pays only the first whose delivered content actually verifies.
POST /api/buy → bought StableData $0.00531 · SUPPORTED · $0 wasted on a pay-on-delivery railA human-signed Intent→Payment mandate is a precondition of the gate: clears only when authorized AND verified.
POST /api/mandate/settle → authorized ✓ · verified SUPPORTED · cleared · bad signature → 403Dry-runs the transfer against Arc before broadcast, so a doomed payout is caught before it spends gas.
POST /api/simulate → wouldSucceed:false · "insufficient USDC: 16.85 < 999999"Authorize a basket of N cited lines; settle only the verified subset, quarantine the rest.
POST /api/settle/batch → verified subset settled, unverified quarantinedA portable, on-chain track record from release-vs-refund history; stronger records price higher.
GET /api/reputation/stabledata → merit 95 · portable release-rateA public directory + x402 manifest so an agent shortlists by a signal a price/latency listing can't emit.
GET /api/directory → 21 sources ranked by verified-quality-per-$Pay-per-tick with numeric-tier checkpoints — the stream auto-halts and refunds on quality drift.
POST /api/stream → per-tick settle · auto-halt + refund on driftFund once; burn down only on verified citations — refused ones are free — over gasless x402.
POST /api/verify/balance → burn-down only on verified · refused = $0A short-lived verify-only key spends the parent's balance up to a cap, and can be used nowhere else.
POST /api/session → scoped key · 403 at any other endpointOn a verified settlement, mints a signed, offline-recoverable proof-of-satisfaction a downstream rail can gate on.
POST /api/fulfillment → signed merit.fulfillment/v1, recovers offlineVerify an external seller's delivered content vs the claim; firewall hosts below the verified-delivery bar.
/api/procure + /api/sellers → verify delivery · firewall low-rep hostsA second settlement predicate: kill-switch, daily hard cap, and velocity auto-freeze on the settlement path.
/api/admin/freeze → one-call freeze · daily cap · velocity auto-haltSigned events on settle/refund whose payload carries the settlement reason — settled-because-verified vs refunded.
/api/webhooks → signed events + the settlement reasonA proven (claim+source) is never re-verified or re-paid; re-verifies automatically when the source changes.
reuse the signed verdict · re-verify on source change — the margin engineLearns its payout threshold from appeals while the decision stays gold-set-safe.
/api/learn → calibrates payout from appeals · decision untouchedThe verifier as an MCP tool (verify_citation) any agent installs via npx — pay only if the citation verifies.
verify_citation over MCP → signed verdict inlineThe verifier is measured on a fixed, hand-labeled gold set — reproducible from a fresh checkout, not a self-reported number — and co-evolves with live adversarial traffic. Every real settlement lands on a public ledger where each row is a signed receipt, most deep-linking a real Arc transaction.




The proof-of-citation hook lifecycle, twice — a verified job that released and a failed job that reverted then refunded. Every hash has a successful receipt on Arc testnet 5042002. Click through to ArcScan.