Five layers. One settlement contract.
How Revolution turns verified identity, private proofs, committed funds, and programmable settlement into a trust layer any agent can use.
Everything on this page builds on Revolution V2 primitives: ZKsync OS with Airbender proofs, the Cornerstone Paymaster, an ERC-4337 paymaster run by the network, smart accounts, Creator Pool distribution, staking emissions, and the Revolution Name Service.
The unit of commerce
Every ACommerce transaction on Revolution resolves to one Settlement Contract instance. It carries the buyer agent, the seller agent, the transaction Mandatum (delegated authority) hash, the verified facet proofs, an optional proof of intent, the accepted offer, the escrow, the payee splits, and the delivery terms.
Four principles govern the design. Prove, do not store. Free to prepare, paid to settle. Accept every rail. Bond the seller.
Layer 0: Chain and gas
Revolution is an Ethereum Layer 2 built on ZKsync OS, with rollup data published to Ethereum in blobs. Every batch carries a validity proof. The chain provides four things for ACommerce that a general-purpose Layer 2 does not.
Detail Why eligibility is the Sybil gate
Every cornerstone call requires an active Agens (agent) identity, and every Agens (agent) identity requires a Sigillum (verified identity) parent. Free execution is available only to accountable actors. Per-identity allowances and rate limits bound any drain. Budget exhaustion degrades to standard gas, never to denial of service.
A third-party paymaster can be turned off by the application that runs it. The Cornerstone Paymaster is run by the network and funded by governance-set emissions, so no single application can turn it off. That reliability is what makes the trust layer a platform rather than a feature.
Layer 1: Agens (agent) identity
An Agens (agent) identity is a subdomain of a verified .revo Nomen (name). An agent cannot exist without a Sigillum (verified identity) parent. The parent creates it. The parent can revoke it. The child cannot be transferred.
ERC-8004 today
- Identity is a transferable NFT. A good record can be bought
- Re-registration is free. A bad record can be discarded
- No link to a human or legal owner. A technical handle, not an identity
- Public reputation, evidence-free, Sybil-dominated in measurement
RNS Agens (agent) identity
- Soulbound. No transfer function
- Records attach to the verified parent. Revocation is permanent
- Parent verified at L1 to L3 Entity by RNS and its data partners
- Reputation is stake-bonded and computed from settlements and disputes
Detail Identity record and policy
| Field | Description |
|---|---|
| agentId | Namehash of the agent name |
| parentId | Namehash of the parent .revo name |
| agentAccount | The agent's smart account on Revolution |
| controllerKey | Public key the agent signs with. Rotatable by the parent |
| policyHash | Hash of the standing Mandatum (delegated authority) for this agent |
| facetRoot | Merkle root of facet commitments the agent may prove |
| reputationRef | Pointer into the Reputation Registry |
| status | Active, Suspended, Revoked |
| erc8004Id | Mirror registration in the ERC-8004 Identity Registry on Revolution |
The parent's policy is the standing Mandatum (delegated authority). Fields at minimum: spend cap per transaction, spend cap per period, allowed categories, optional counterparty allow-list, a threshold above which a human co-signature is required, expiry, and a kill switch. Policy follows the caveat model of ERC-7710 delegation.
Detail Verification levels
| Sigillum (verified identity) level | Meaning | Unlocks |
|---|---|---|
| L1 Basic | Email and device bound, uniqueness checked | Agent creation, low-value settlement |
| L2 Verified | Government identity checked against data partners | Age and jurisdiction facets, standard settlement |
| L3 Enhanced | KYC and AML screening completed | Accredited-investor facets, RWA-linked settlement |
| L3 Entity | Legal entity verified with authorized signatory | Merchant agent registration, bonded reputation pools |
Facets and zero-knowledge proofs
A Sigillum (verified identity) facet is a single provable attribute attached to an identity. Facets are proven, not disclosed. The verifying party learns that the statement is true. It does not learn the underlying value.
The human authenticates once with RNS. RNS issues credentials. Each credential is a leaf in a Merkle tree whose root is the identity's facet root. When a transaction requires a facet, the agent generates a zero-knowledge proof that a leaf under the root satisfies the required predicate. The chain verifies the proof. Every proof carries a nullifier bound to the settlement, so it cannot be replayed.
| Facet | Predicate | Issuer |
|---|---|---|
| human.verified | A Sigillum (verified identity) at level L2 or above controls the parent identity | RNS |
| entity.verified | A verified legal entity controls the parent identity | RNS |
| age.over.18 / age.over.21 | Date of birth earlier than the threshold | RNS via data partner |
| jurisdiction.in / not.in | Residence country in an allow-set or outside a deny-set | RNS via data partner |
| investor.accredited | Accreditation credential valid | RNS or licensed partner |
| sanctions.clear | Screening credential valid within window | RNS KYC module |
| reputation.above | Reputation score above a threshold | Reputation Registry |
| mandate.covers | Transaction Mandatum (delegated authority) covers category and amount | Buyer agent with standing Mandatum (delegated authority) |
| kya.certified | Valid certification under a recognized Know-Your-Agent framework | Card or wallet network |
Proof of purchase intent
Models can misinterpret an instruction. An agent told to buy a blue pair of shoes under a set budget may order a red pair, or a jacket. Proof of intent is a zero-knowledge proof over the transaction Mandatum (delegated authority) that establishes the settlement's category, counterparty class, and amount fall inside its bounds. The merchant learns the purchase is authorized. It never learns the budget ceiling or the urgency. A merchant cannot price against information it never receives.
Detail Storage footprint and data protection
Per identity the chain stores one facet root, one reputation pointer, and per-settlement nullifiers. No attribute, no document, no Mandatum (delegated authority). This is the storage discipline that allows the model to scale to millions of identities and keeps the onchain record outside the scope of personal-data processing. Credentials are held by RNS and the human's agent runtime, with revocation supported at the issuer level.
Layer 2: Agentic payments
Accept every rail. Own the settlement contract. Revolution is the record of who authorized what, under which proofs, with which funds committed, paid to whom.
Merchant names price, USDC, chain: revolution, and required facets
Buyer agent attaches facet proofs, intent proof, and the transaction Mandatum (delegated authority) hash
Escrow locks. The contract reverts unless every proof verifies
Seller marks delivered with evidence. Dispute window opens
One transaction pays merchant, creator, network, withholding
Detail Programmable splits
The settlement contract carries a payee list. On settlement, funds are distributed to every payee in the same transaction: merchant, the affiliate creator or expert agent whose recommendation was accepted, the network fee, and any tax or duty withholding indicated by the buyer's jurisdiction facet. Splits are fixed at funding and cannot be altered after. This reuses the deterministic distribution logic of the Creator Pool contracts.
Detail Fees
| Operation | Fee |
|---|---|
| Identity creation, facet proof, mandate anchor, intent post, escrow creation | None. Cornerstone services |
| Settlement | Governance-set basis points on settled value, in USDC or REVO |
| Stream tick | Governance-set flat fee per release |
| Dispute filing | Refundable deposit in REVO |
Layer 3: The Intent Book
In eCommerce the merchant publishes and the buyer searches. In ACommerce the buyer publishes and the merchant searches. A buyer agent posts a need with funds committed. Merchant agents respond with offers. The buyer agent reasons over the offers and accepts one. The merchant pays nothing to be found and pays only when it wins.
| Field | Visibility | Description |
|---|---|---|
| category | Public | Merchant category from a governed taxonomy |
| specHash | Public | Hash of the structured specification, shared with responders through an authenticated channel |
| ceilingCommitment | Public | Commitment to the maximum price. The ceiling itself is private |
| fundsProof | Public | Zero-knowledge proof that escrow balance meets the hidden ceiling |
| requiredFacets | Public | Facets the buyer requires of the seller, such as entity.verified or reputation.above |
| responderFilter | Public | Minimum seller bond, category reputation threshold |
Layer 4: Enforcement
A reputation that costs nothing to create is worth nothing. Revolution makes reputation cost something to hold and something to lose. Reputation is backed by stake and attached to a verified parent.
| Event | Consequence |
|---|---|
| Dispute resolved for buyer, non-delivery | Refund to buyer from bond plus governance-set penalty |
| Dispute resolved for buyer, misdescription | Partial refund from bond per adjudicator ruling |
| Offer withdrawn after acceptance | Fixed penalty |
| Facet proof found fraudulent after settlement | Full bond. Identity suspended |
Detail Why whitewashing fails
A merchant that wants to escape a bad record has two options and both fail. Revoking the agent forfeits any bond subject to open disputes and attaches the record to the parent's history. Creating a new agent under the same parent inherits the parent's aggregate until the child has its own record. Creating a new parent requires a new verified legal entity. A human whose parent identity is suspended by RNS for fraud loses all child agents at once.
Adjudication is pluggable. The initial adjudicator set is governance-appointed. Revolution can route disputes to external arbitration consortia that accept delegation records and settlement contracts as evidence.
Interoperability
Revolution does not compete with payment networks or catalog standards. It is the trust and settlement layer that sits between the agent and the money. Every external protocol connects at a defined point.
| Protocol | Function in market | Connection point on Revolution |
|---|---|---|
| Know-Your-Agent framework (Ant, Mastercard, Visa) | Operator traceability, shared certification, continuous monitoring | RNS Agens (agent) identity is a KYA credential. Credential export, kya.certified facet import, monitoring feed |
| x402 | HTTP 402 payment challenge and stablecoin response | Revolution facilitator, chain: revolution, facets extension |
| AP2 | Signed Intent, Cart, and Payment Mandates | Mandate Anchor records each AP2 mandate as a transaction Mandatum (delegated authority). Intent proofs are generated over it |
| UCP | Merchant catalog discovery and checkout | Merchant agents read catalogs to form offers. The Intent Book is a second channel |
| Trusted Agent Protocol, Web Bot Auth | Agent authentication to merchant edges | Agent controller key is the signing key. .revo name in metadata |
| Machine Payments Protocol | Session-based micropayments | Stream mode maps session cap and rate to escrow cap and rate |
| ERC-8004 | Agent identity, reputation, validation registries | Read-only mirror of every RNS Agens (agent) identity. Transfer disabled |
| ERC-4337, ERC-7579, ERC-7710 | Smart accounts, modules, scoped delegation | Agent accounts and policy caveats |
| MCP, A2A | Agent tool and messaging protocols | Identity, proofs, Intent Book, and settlement exposed as tools and agent cards |
Compliance posture
Compliance is a property of the architecture rather than a policy layered on top. Each expectation now forming is met by a specific component.
| Expectation | Component |
|---|---|
| Know Your Agent (Ant, Mastercard, Visa framework) | Verified parent, facets, settlement record |
| Consumer authorization | Mandate anchor, proof of intent, policy caps |
| Age assurance (EU wallet deadline, Dec 2026) | Age facets. No date of birth disclosed |
| Personalized pricing (FTC statement, Aug 2026) | Ceiling commitment, proof of intent |
| Agent duty of loyalty (draft US legislation) | Action log via mandate anchor. No sub-delegation by design |
| Sanctions and securities | sanctions.clear and investor.accredited facets. Custody through licensed partners |
| Data protection | Commitments only onchain. No personal data |
This page describes design intent. It is not legal advice. Participants are responsible for their own obligations in their own jurisdictions.
Token economics
ACommerce introduces no new emission. It adds four uses of REVO and directs a share of existing emission to productive work.
| Use | Mechanism | Effect on REVO |
|---|---|---|
| Cornerstone Budget | A governance-set share of staking emissions (5% proposed) funds the Cornerstone Paymaster | Directs existing emission. No new emission |
| Reputation bonds | Merchant and expert agents stake REVO. Delegators can co-stake and share fees and slashing | New demand for locked REVO proportional to merchant participation |
| Settlement fees | Basis points on settled value in USDC or REVO, with a discount for REVO | Settlement fees paid to verifying node operators, pro rata by node weight |
| Dispute deposits | Refundable REVO deposit on filing | Temporary lock. Forfeited deposits go to the counterparty |
All parameters are governance-set. Proposed initial values are in Whitepaper V2, section 8.10. Values may change before mainnet activation of ACommerce features.
Read the full specification.
Whitepaper V2, section 8 carries the interfaces, state machines, threat model, and governance parameters.