Revolution V2 is coming. A new chain, real proofs, and a verified identity stack. See what's changing

Ecosystem

The Trust Layer Agentic Commerce Is Missing

In September 2026, Ant International, Mastercard and Visa agreed on a shared Know Your Agent interoperability framework. It aligns Visa’s Trusted Agent Protocol, Mastercard’s Verifiable Intent and Ant’s Agentic Mobile Protocol on operator traceability, shared certification and continuous transaction monitoring. Visa’s Rubail Birwadker put the stakes plainly: “Without trusted identity and explicit permissioning, AI agents cannot participate in commerce at scale.”

The same report notes what the framework still lacks: technical specifications, governance bodies and rollout timelines. That gap is the subject of this post. The rails for agent payments are arriving fast. The trust layer underneath them is not finished.

The rails are already here

Agent payment infrastructure arrived fast over the past year.

  • x402. The Linux Foundation announced the operational launch of the x402 Foundation on 14 July 2026 with 40 member organizations, including Coinbase, Google, Visa, Mastercard, Stripe, Shopify, Circle and Cloudflare. A founding member framed the gap x402 fills: the web “has never had a native mechanism for one program to pay another.” Chainalysis counted more than 100 million x402 transactions on Base in about three quarters.
  • AP2. Google’s Agent Payments Protocol launched with more than 60 organizations. It introduced Intent and Cart Mandates: “tamper-proof, cryptographically-signed digital contracts that serve as verifiable proof of a user’s instructions.”
  • Card networks. Visa introduced the Trusted Agent Protocol, aligned with Web Bot Auth and built on HTTP Message Signatures, so merchants can tell trusted agents from malicious bots. Mastercard followed its Agent Pay program with Agent Pay for Machines on 10 June 2026, with more than 30 partners and settlement across cards, accounts and stablecoins.
  • Checkout and catalogs. Stripe and OpenAI released the Agentic Commerce Protocol with a Shared Payment Token scoped to a merchant and a cart total. Google, with Shopify, Etsy, Wayfair, Target and Walmart, published the Universal Commerce Protocol, which is compatible with AP2.

Demand signals are real. Adobe reported that AI-referred traffic to US retail sites grew 138% year over year in May 2026 and converted 54% better than other sources. McKinsey estimates agentic commerce could generate as much as $3 trillion to $5 trillion globally by 2030.

The problem: trust at the point of settlement

Rails move money. Catalogs describe goods. Neither answers the question a merchant faces at the moment an agent pays: who is behind this agent, is it acting inside its authority, and will the deal be enforced?

The market data shows the cost of leaving that open. CoinDesk reported analysis from Artemis that roughly half of observed x402 transactions reflected artificial activity, such as the same wallet acting as buyer and seller. That is not a flaw in x402. It is what happens when payment is permissionless and identity is optional.

Consumers feel it too. Mastercard’s August 2026 report Encoding Trust found that 74% of consumers would let agents complete specific tasks, but only 10% would allow autonomous purchase completion. It named three pillars: verifiable intent, agent identity and permission frameworks.

Revolution’s whitepaper names four gaps:

  1. Identity. ERC-8004, the Ethereum agent identity standard, does not bind an agent to a human or legal owner. Its specification makes agents “immediately browsable and transferable” as ERC-721 tokens and states that “Sybil attacks are possible.”
  2. Privacy. Mandates in the market are plaintext. A merchant that reads one learns the buyer’s budget.
  3. Discovery. Buyers still pull from catalogs. No live system lets a buyer post funded demand for merchants to bid on.
  4. Enforcement. When two agents agree, something must hold both to the agreement.

How it works: one vocabulary, five layers

Revolution names its identity and authority stack in Latin, after the Roman legal order it echoes. One sentence carries the architecture:

Nomen (name) tells the network what you’re called. Sigillum (verified identity) proves who you are. Potestas (permissions) determines what you’re permitted to do. Mandatum (delegated authority) defines the authority you delegate. Agens (agent) acts within it.

TermWhat it isBuilt on
Nomen (name)A .revo name from the Revolution Name Service, such as rob.revoENS-style naming
Sigillum (verified identity)Verification level plus facets proven in zero knowledgeVerifiable credentials, ZK proofs
Potestas (permissions)What a principal may do, from its level and account classERC-7579 policy hooks
Mandatum (delegated authority)Standing: the parent’s signed agent policy. Transaction: an AP2 mandate anchored on chainERC-7710, AP2
Agens (agent)A soulbound agent identity under a verified parent, such as shopping.rob.revoERC-4337, ERC-8004 mirror

The rules are strict. A Mandatum (delegated authority) never exceeds the Potestas (permissions) of the principal who grants it. Every Mandatum (delegated authority) is revocable. An Agens (agent) has no authority of its own. Agents cannot create agents.

The ACommerce stack (whitepaper section 9.2) sits on these terms:

LayerComponents
4. EnforcementDispute contract, Reputation Registry, bonds
3. DiscoveryIntent Book
2. PaymentsSettlement contract, Mandate Anchor, Escrow, Splits, x402 facilitator
1. IdentityAgent Identity Registry, Facet Registry, Proof Verifier
0. Chain and economicsZKsync OS, ERC-4337 accounts, Cornerstone Paymaster, staking

The Settlement state machine

Every ACommerce transaction resolves to one Settlement contract. It holds the buyer Agens (agent), the seller Agens (agent), the mandate hash, the required facet proofs, the offer hash, escrow, splits, delivery terms and state.

A Settlement starts Open. It moves to Funded only through fund(), and fund() is the gate. It reverts unless every required facet proof verifies, the transaction Mandatum (delegated authority) is anchored, any required intent proof verifies, and escrow covers the price. Once funded, the seller marks it Delivered with evidence. The buyer then confirms, or a timeout passes, and it becomes Settled. If the buyer disputes instead, it becomes Disputed, and resolution sends it to Settled for the seller or Refunded for the buyer. If the seller misses the delivery deadline, a Funded settlement goes straight to Refunded.

The merchant never has to trust the agent. It trusts the gate.

Free to prepare, paid to settle

A buyer will not pay to post an intent that may never fill. A person will not pay to register an agent that has done nothing yet. So Revolution V2 is designed to make preparation free. Identity, facet proofs, mandate anchoring, intent posting, offers and escrow creation are specified as cornerstone calls. The Cornerstone Paymaster, a standard ERC-4337 paymaster, covers their gas from a Cornerstone Budget set aside from staking emissions. Settlement is the step that pays the network fee.

What Revolution V2 does today, precisely

Status matters, so here it is without rounding.

Built and tested on a devnet. The account layer: the canonical ERC-4337 EntryPoint v0.8 deployed on ZKsync OS, ERC-7579 Nexus smart accounts, the Cornerstone Paymaster and the Cornerstone Budget. A zero-balance smart account has called a cornerstone service end to end on the devnet, with gas paid from the budget. 51 contract tests pass, including four stateful invariants.

Specified, not built. The identity layer (Nomen (name), Sigillum (verified identity) facets, Agens (agent) registry) is Phase 2. The ACommerce contracts (Settlement, Mandate Anchor, Escrow, Splits, Intent Book, Reputation Registry and Disputes) are specified in the whitepaper. Payments ship in Phase 3.

Not live yet. Virtus (V2 testnet), the public V2 testnet, launches in Phase 1. It replaces Libertas (V1 network). There are no merchants, partners or settlement volume on V2 today.

Interoperate, do not replace

Revolution is not another rail. It is the identity and settlement record those rails can call. The whitepaper is explicit: Revolution does not issue cards, run a catalog, custody fiat or replace a merchant’s processor.

ProtocolConnection point
x402Open-source Revolution facilitator with a facets extension and .revo names in payTo
AP2Canonical format for the transaction Mandatum (delegated authority); hashes anchored on chain
UCPMerchant Agens (agent) reads UCP manifests to price offers
TAP and Web Bot AuthThe agent’s controller key signs HTTP requests; .revo name in metadata
Card agentic tokens, Shared Payment TokensAuthorization reference written to the Settlement record
Know Your Agent frameworkParent binding meets operator traceability; facets meet shared certification; the settlement record meets continuous monitoring

On the stablecoin path, a merchant’s HTTP 402 response can name its requirements directly:

{
  "scheme": "exact",
  "network": "revolution",
  "asset": "USDC",
  "amount": "4999",
  "payTo": "sales.acme.revo",
  "facets": ["human.verified", "age.over.18", "jurisdiction.in:US,CA,GB"],
  "requireIntentProof": true
}

On the card path, card money never touches the chain. The Settlement contract records the identity, proofs and mandate hash, and the processor’s authorization reference is written to it.

What it means

For merchants. A funded settlement means a verified human stands behind the buyer Agens (agent), the purchase sits inside a signed Mandatum (delegated authority), and the funds are in escrow. Checkout stays yours. OpenAI’s move toward merchant-controlled checkout shows why that matters.

For builders. One identity resolves across rails. The SDK exposes each term with a plain-English alias, such as revo.mandatum (revo.delegation). Preparation calls are free, so an agent can register, prove and anchor before it earns anything.

For people. Under the specification, your agent is shopping.yourname.revo. It cannot outspend your standing Mandatum (delegated authority). You can revoke it at any time, permanently, and its history stays attached to you.

What is next

Phase 1 brings Virtus (V2 testnet) online with real Airbender proofs, verifying nodes co-signing batches, and a zero-balance account making a free cornerstone call on a public network. Phase 2 delivers identity: .revo names on V2, the Agent Identity Registry, and audited circuits for the first facets. Phase 3 delivers payments. Its exit test is concrete: x402 merchants accept USDC on Revolution with facet requirements, and end-to-end settlements with proofs and splits complete on testnet.

The rails are being built by the largest payment companies in the world. Revolution’s job is narrower and harder: make every settlement provably human-backed, provably authorized and provably enforced.

Sources

Build on V2.

Virtus (V2 testnet) opens in Phase 1. The SDK and APIs are in the developer docs.