Start with the buyer path. Seller and exchange examples are clearly separated because they are experimental local previews.
From any empty directory with Node.js 20+:
npx --yes https://github.com/InTheta/agent-capability-middleware/archive/refs/tags/v0.1.0-preview.24.tar.gz partner-check \
> acm-no-spend-report.jsonThis installs the pinned preview, reads Coinbase's public x402 Bazaar catalog, verifies all nine canonical Omni route templates and the current 0.010 Base Sepolia USDC market-risk quote, then exits without signing or paying.
Expected fields:
{
"ok": true,
"mode": "no_spend",
"packageInstall": "installed_cli",
"secretsIncluded": false
}npx --yes https://github.com/InTheta/agent-capability-middleware/archive/refs/tags/v0.1.0-preview.24.tar.gz demo buyerThis demonstrates the policy lifecycle without a chain transaction:
bounded grant → fresh synthetic result → revoke → denied retry
Any 0xmock_... receipt is intentionally synthetic.
Run only after an ACM operator provides a protected gateway URL and confirms its dedicated testnet payer is ready:
export ACM_GATEWAY_URL='https://provided-gateway.example'
export ACM_CONFIRM_TESTNET_SPEND=yes
npx --yes https://github.com/InTheta/agent-capability-middleware/archive/refs/tags/v0.1.0-preview.24.tar.gz partner-check \
> acm-paid-report.json
unset ACM_API_KEY ACM_CONFIRM_TESTNET_SPENDIf that deployment requires a workload key, enter it separately through the hidden prompt documented in the external developer checklist.
The flow binds one request to its resource, purpose, 0.010 USDC maximum, Base Sepolia network, USDC contract, Omni receiver, grant, and idempotency key. It accepts the result only when paid, receipted, fresh, and schema-matched. It then revokes the grant and proves another settlement cannot occur.
Required paid-report evidence:
mode: paid_testnet
freshness: fresh
denialReason: grant_revoked
secondSettlementCreated: false
secretsIncluded: false
The payer key stays inside the protected gateway.
git clone https://github.com/InTheta/agent-capability-middleware.git
cd agent-capability-middleware
npm ci| Command | Purpose | Payment |
|---|---|---|
npm run example:fresh-dev |
Pack, install in an empty project, grant, validate, revoke, deny | None; deterministic mock |
npm run example:bazaar |
List the live receiver-scoped Bazaar catalog | None |
npm run example:omni-recipes |
Build exact news, liquidation, trader, risk, snapshot, entity-resolution, and carry requests | None |
npm run example:omni-x402 |
Run the partner flow | No spend unless explicitly enabled |
npm run verify |
Type-check, test, package-smoke, and exercise public examples | None |
Expected markers include FRESH_DEV_MOCK_OK, BAZAAR_DISCOVERY_NO_SPEND_OK, and OMNI_AGENT_RECIPES_NO_SPEND_OK.
These examples create and evaluate local fixed-price offer objects. They do not custody keys, issue a real x402 challenge, settle payment, fulfil a live order, prove demand, or constitute a production marketplace.
| Command | Preview |
|---|---|
acm demo developer-seller |
Developer describes a paid API offer |
acm demo user-seller |
User offers a confirmed minimum-disclosure capability |
acm demo exchange |
Both offer types share Free, Paid, Ask, or Deny decisions |
The user-seller example locally minimizes an Amazon-shaped CSV into aggregate evidence. It explicitly reports that raw rows and product titles are not uploaded, cookies are not read, and settlement did not occur. See the user seller preview.
These captures are operator testnet evidence, not external validation, mainnet, or production claims.

