{
  "schema": "csoai.population-door/0.1",
  "kind": "preview",
  "id": "layer0",
  "title": "Layer-0 machine-surface ceremony",
  "population": "one row per protocol rail and per probe of the estate's own machine surface, with the HTTP status each returned at the ceremony's as_of, and the state of the ceremony artifact's own .ots proof",
  "state": "MEASURED",
  "n": 29,
  "n_unit": "live probes of the estate's machine surface in the ceremony",
  "as_of": "2026-09-03T05:10:26Z",
  "source": [
    "/interop/layer0-ceremony-2026-09-03.json",
    "/interop/ots/manifest.json"
  ],
  "reason": null,
  "unmeasured": [
    "reliability over time: this artifact is one dated ceremony, not a series; the hourly reliability slice is not published in this repository"
  ],
  "head": {
    "schema": "csoai.layer0-ceremony/0.3",
    "kind": "layer0.surface-attestation",
    "rails": 14,
    "rails_serving": 14,
    "rails_total": 14,
    "probes_by_http_status": {
      "200": 28,
      "400": 1
    },
    "digest_covers": "whole-artifact-except-sha256-and-seal",
    "sha256": "672bd5416c4c8d33fc0d03293495bcb3a5c5a0a95d8a13657f2e1d65661abbbc",
    "what_this_does_not_claim": [
      "CORRECTION (v0.3). v0.2 listed /api/intoto as a rail returning 404 and said 'the handler exists in master but is inside an undeployed window'. That was WRONG. functions/api/intoto.ts exports no onRequest handler at all — it is a helper module (subjectDigest, toInTotoStatement, toDsse) imported by functions/api/detect.ts and functions/api/detector-interop.ts, both of which serve 200. It was never a route and no deploy would ever have made it one. The only thing on the estate advertising /api/intoto as an endpoint was this artifact. It is removed from the rail list; in-toto capability is real and reachable through /api/detect and /api/detector-interop.",
      "Not a certification, conformity mark, or trust label. We measure; we never certify.",
      "A 200 means the door answered at as_of. It does not mean the content behind it is correct, current, or complete.",
      "The A2A card carries version 1.0.0 (the AGENT's version). protocolVersion is ABSENT; a strict A2A client may reject the card on that basis. Recorded, not hidden.",
      "x402 is challenge-only: pay_to is configured, facilitator_configured is FALSE. Nothing can currently be paid for. Stated by the rail itself.",
      "The signed card index was packaged 2026-08-28; it is STALE relative to as_of.",
      "This artifact carries NO Ed25519 seal. The board signing key is on an isolated signing node and is deliberately unreachable from any tool that could produce this file. seal.state is UNMEASURED until an owner ceremony signs it.",
      "The OpenTimestamps proof for THIS artifact is a detached sidecar at /interop/layer0-ceremony-2026-09-03.json.ots. At as_of it carries PENDING calendar attestations only. It becomes a Bitcoin proof after a calendar commits (~1-6h) AND scripts/ots-upgrade.py is run. An unupgraded stamp is not a proof."
    ],
    "ots": {
      "path": "/interop/ots/manifest.json",
      "manifest_as_of": "2026-09-28T07:32:14Z",
      "proof": "/interop/layer0-ceremony-2026-09-03.json.ots",
      "state": "BITCOIN",
      "subject_present": true,
      "sha256_of_proof": "9a7031bb38cefe42484700493ef896545eaabd0a661cbeccd3eb52cae2cc6d3c"
    },
    "identification": "a probe is one HTTP request the ceremony made to a named surface of this estate at as_of, recorded with its status; a rail is a protocol surface the ceremony names. Self-attestation: the estate probing itself."
  },
  "manifest": "https://councilof-ai.pages.dev/api/pop/layer0/manifest",
  "buy": {
    "resource": "https://councilof-ai.pages.dev/api/pop/layer0",
    "how": "GET the resource → 402 → pay accepts[] (x402) → retry with X-PAYMENT",
    "catalog": "https://councilof-ai.pages.dev/api/x402",
    "all_doors": [
      "https://councilof-ai.pages.dev/api/pop/stablecoins",
      "https://councilof-ai.pages.dev/api/pop/swift",
      "https://councilof-ai.pages.dev/api/pop/xrpl",
      "https://councilof-ai.pages.dev/api/pop/x402-bazaar",
      "https://councilof-ai.pages.dev/api/pop/mcp-registry",
      "https://councilof-ai.pages.dev/api/pop/a2a",
      "https://councilof-ai.pages.dev/api/pop/ots-proofs",
      "https://councilof-ai.pages.dev/api/pop/layer0",
      "https://councilof-ai.pages.dev/api/pop/corrections",
      "https://councilof-ai.pages.dev/api/pop/claim-watch"
    ]
  },
  "rail": {
    "mode": "live",
    "pay_to_configured": true,
    "facilitator_configured": true,
    "note": "A settled receipt (facilitator /verify then /settle) unlocks the paid artefact. Verification of every artefact stays free."
  }
}