Revolution V2 is coming. A new chain, real proofs, and a verified identity stack. See what's changing

Protocol

Private Proof at the Point of Sale

On 19 August 2026, the Federal Trade Commission proposed an enforcement policy statement on personalized pricing. Under it, businesses “should clearly and conspicuously disclose” personalized pricing where consumers would reasonably expect a static price, including the basis for personalization and the types of data used.

Two weeks earlier, a Senate Judiciary subcommittee held a hearing on AI pricing. Lindsay Owens of the Groundwork Collaborative testified: “As agentic commerce reshapes how we shop online, with AI agents gaining access to your habits, purchases, and personal conversations, the risk of being ripped off will only grow.”

Both point at the same design flaw. An AI agent that shops for you carries instructions. If a merchant can read those instructions, it can price against them.

The problem: a mandate is a pricing signal

Surveillance pricing is not hypothetical. In January 2025 the FTC published initial findings from its surveillance pricing study. Then-Chair Lina Khan said retailers use personal information to set tailored prices, “from a person’s location and demographics, down to their mouse movements on a webpage.” The staff gave one example: “a consumer who is profiled as a new parent may intentionally be shown higher priced baby thermometers.”

Agents make this sharper. Google’s AP2 Intent Mandate captures the rules of a delegated task, including price limits, timing and conditions. That is the right thing to capture. It is the wrong thing to show a seller. A price limit is a budget. A deadline is urgency. A merchant that reads both no longer has to infer willingness to pay from mouse movements. It is written down.

Lawmakers are moving:

JurisdictionRuleStatus
New YorkAlgorithmic Pricing Disclosure Act requires the notice “THIS PRICE WAS SET BY AN ALGORITHM USING YOUR PERSONAL DATA.”In effect since 10 November 2025; upheld by a federal court
MarylandProtection From Predatory Pricing Act prohibits surveillance pricing by food retailersEffective 1 October 2026
New Jersey, ConnecticutPersonalized pricing bans (food pricing in New Jersey; general in Connecticut)Effective 2027
European UnionThe Consumer Rights Directive, as amended in 2019, requires traders to state “that the price was personalised on the basis of automated decision-making” (Directive 2019/2161)Applies since 28 May 2022
European UnionThe Digital Fairness Act targets “unfair personalisation practices, especially where consumer vulnerabilities are exploited”Proposal expected Q4 2026

The same Skadden analysis counts more than 50 surveillance pricing bills pending across 26 states. We describe these rules here. We do not advise on them.

For an agent economy, disclosure is a floor. The stronger answer is architectural: the merchant should verify that a purchase is authorized without ever seeing what the buyer would pay.

The building blocks are already mainstream

Zero-knowledge proofs have moved from research into national identity programs.

  • In July 2025 Google open-sourced its zero-knowledge proof libraries for age assurance, used with Google Wallet and aligned with the EU Digital Identity Wallet. Google’s summary: “A person visiting a website can verifiably prove he or she is over 18, without sharing anything else at all.”
  • The European Commission’s second age verification blueprint states that the proof of age “only informs that the user is over 18 years, not who the user is.” Denmark, France, Greece, Italy and Spain are the first member states in the pilot, as a step toward EU Digital Identity Wallets before the end of 2026.
  • W3C published Verifiable Credentials 2.0 as a Recommendation on 15 May 2025. Holders can give verifiers “a subset of a credential (providing selective disclosure of the private data).”
  • The IETF published RFC 9901, Selective Disclosure for JSON Web Tokens, in November 2025. It uses salted hashes so a holder reveals only the claims a verifier needs.

There are two levels here. Selective disclosure reveals some fields and hides the rest. A zero-knowledge predicate reveals no field at all, only that a statement about it is true. “Over 21” without a birthdate. “Within budget” without the budget. Commerce needs the second level.

How it works: facets, commitments, nullifiers

Revolution calls each provable attribute a facet. A facet is one fact about a Sigillum (verified identity), the verified identity behind a Nomen (name) such as rob.revo. Examples from the whitepaper: a verified human is behind this Agens (agent), the human is over 21, residence is in an allowed set, the Agens (agent) reputation exceeds a threshold, the mandate covers this purchase.

Four mechanisms make it work.

Merkle commitments. The Revolution Name Service verifies the holder off chain and commits each credential as a leaf in a Merkle tree. A Merkle tree hashes leaves in pairs, then hashes those results, until one value remains: the root. The root is a fingerprint of every credential. Change one leaf and the root changes. The chain stores only this root, the identity’s facet root. It never stores the attribute.

Zero-knowledge proofs. To prove a facet, the Agens (agent) generates a proof that some leaf under the facet root satisfies a predicate, such as age >= 21. The Proof Verifier checks the proof against the root. The verifier learns the predicate holds. It learns nothing about the leaf.

Revocation roots. Credentials get revoked. The issuer maintains a revocation set with its own root. Every proof must also show that the credential is not in that set. A revoked credential stops producing valid proofs, with no need to touch the holder’s data.

Nullifiers. Each proof carries a nullifier bound to the settlement it is used for. The chain records nullifiers per settlement. A proof presented once cannot be replayed into another deal.

Per identity, the chain holds one facet root, one reputation pointer and per-settlement nullifiers. Nothing else.

Proof of purchase intent

Facets prove who is buying. The mandate proves what they may buy. Revolution separates two forms of Mandatum (delegated authority).

The standing Mandatum (delegated authority) is the parent’s signed agent policy: spend cap per transaction and per period, allowed categories, a human-approval threshold, expiry and a kill switch. It never exceeds the parent’s Potestas (permissions). Its hash is on chain.

The transaction Mandatum (delegated authority) is an AP2 mandate for one purchase, held off chain as a verifiable credential. The Mandate Anchor records its hash with the Agens (agent) identity and expiry. An auditor holding the mandate can verify it. Anyone else learns only that an anchor exists.

Proof of purchase intent is a zero-knowledge proof over that mandate. It shows that the settlement’s category, counterparty class and amount fall inside the mandate’s bounds.

At settlementMerchant learnsMerchant does not learn
human.verified facetA verified human stands behind the Agens (agent)Who that human is
age.over.21 facetThe age threshold is metDate of birth
jurisdiction.in facetResidence is in an allowed setThe address or country
Proof of purchase intentThis purchase is authorizedThe budget ceiling or the deadline
NullifierThis proof is freshAny other settlement the buyer made

The price ceiling commitment

Discovery raises the same issue. In Revolution’s specified Intent Book, a buyer Agens (agent) posts a category, a hash of the specification and a commitment to the price ceiling, plus a zero-knowledge proof that escrow covers the hidden ceiling. Merchants see funded demand. They bid without seeing the number. A commitment binds the buyer to a value it cannot later change, while revealing nothing about that value.

The whitepaper’s compliance mapping states the goal in one line: ceiling commitment; merchant never sees willingness to pay.

What Revolution V2 does, precisely

Built and tested on a devnet. The account layer: ERC-4337 EntryPoint v0.8 on ZKsync OS, ERC-7579 Nexus smart accounts, and the Cornerstone Paymaster funded by the Cornerstone Budget. A zero-balance account has called a cornerstone service end to end with gas paid from the budget. Proof verification and mandate anchoring are designed as cornerstone calls, so proving is designed to cost the user nothing.

Specified, not built. The Facet Registry and Proof Verifier ship in Phase 2, with audited circuits for human.verified, entity.verified, age.over.18, age.over.21, jurisdiction.in and jurisdiction.not.in, plus credential issuance and revocation roots. The Mandate Anchor, proof of purchase intent and the Settlement contract are Phase 3. The Intent Book is Phase 5.

Open items. The credential format for circuits (Merkle commitments with revocation roots) is still to be confirmed with issuers. Circuits are audited before activation. Data protection obligations for verification data sit with the Revolution Name Service as issuer, and whether the on-chain record stays outside personal-data scope is flagged for counsel.

Virtus (V2 testnet), the successor to Libertas (V1 network), is not live yet.

What it means

For merchants. Under the specification, you can require proofs as conditions of settlement: a verified human, an age threshold, a jurisdiction, an authorized amount. The Settlement contract will not fund without them. You receive what you need to accept the order and nothing that describes the buyer’s willingness to pay.

For builders. Facets are protocol strings (age.over.21, mandate.covers). The SDK exposes them under revo.sigillum with the alias revo.identity. Proof verification is designed as a free cornerstone call, so privacy is the default path, not a premium feature.

For people. Under the design, your Agens (agent) shops inside the standing Mandatum (delegated authority) you set. It proves you are old enough, in the right place and within budget. It never hands over your birthdate, your address or your ceiling.

What is next

Phase 2 is identity: .revo names on V2, the Agent Identity Registry, and the first audited facet circuits. Its exit test requires facet proofs to verify on chain with published circuit audits. Phase 3 adds the Mandate Anchor and proof of purchase intent to the Settlement flow.

Regulators are asking merchants to disclose how personal data shapes price. Revolution’s answer is to keep that data out of the merchant’s hands entirely. Prove, do not store. Prove, do not show.

Sources

Build on V2.

Virtus (V2 testnet) opens in Phase 1. The SDK and APIs are in the developer docs.