First unattended generic Assurance proof — Keyronne JSON Repair
Observed: 7 September 2026
Service: POST https://keyronne.com/api/json-repair
You can pay to be tested. You cannot pay to be trusted.
Atinamos doesn't score trust. It publishes evidence.
Why this proof matters
This is the first production run in which an already-frozen external Assurance Run was taken from PLAN_FROZEN to COMPLETE by one internal Runner command, without an operator manually stepping through challenge acquisition, signing, payment, settlement observation, fulfilment evaluation or publication.
It is also the first completed production proof of the generic fulfilment strategy rather than a bespoke deterministic service adapter.
The product question was deliberately narrow:
We bought X. Did the seller deliver X?
The run did not ask Atinamos to prove that the returned repaired JSON was factually or semantically correct.
Frozen run
Assurance Run: 1b5bc844-368c-445a-8f84-e62be6d88baa
Submission: 2175d749-edb2-4f4f-94ec-521598a6d1d4
Adapter: generic-transaction-fulfilment v1.0
Adapter match: GENERIC_FULFILMENT
Target: POST https://keyronne.com/api/json-repair
Frozen plan SHA: 8d282950de8cbc627d69cfbfcf561e01a2181acf1cfc04c7ff6801b1ca7bbb7f
Discovery SHA: f16a4f3f5ac2877917a9588b5586e94252e8903f9f2fa481c657b2cda425291a
Funding method: atinamos_research
The documented invocation material came from public machine-readable metadata. It was invocation material only, not an expected answer and not proof of correctness.
One-command production execution
The internal production primitive was invoked once for the existing frozen run:
atinamos-assurance-execute 1b5bc844-368c-445a-8f84-e62be6d88baa
The executor returned:
status: OK
outcome: COMPLETE
state: COMPLETE
exit: 0
The durable Runner event count moved from 5 to 13.
No automatic paid replay was performed.
Paid observation
Wallet balance immediately before the run:
1.351169 USDC
Wallet balance immediately after the run:
1.350169 USDC
Observed difference:
0.001000 USDC
Verification recorded:
amount: 0.001 USDC
network: eip155:8453
protocol: x402 v2
scheme: exact
recipient: 0xb86f95ef5fa904318ea9df3b59adce099b478fc4
payment made: true
settlement: independently observed
paid HTTP: 200
Independent Base settlement evidence retained by the Runner:
transaction: 0xc42bb177c41d21a56e9d3c02546fa8ebeda911cff3bc1139169a61c89f7b495c
block: 50996015
chain id: 8453
amount: 0.001 USDC
payer: 0x1e3aa1aa619079630e97babf003c0134b4fe9891
recipient: 0xb86f95ef5fa904318ea9df3b59adce099b478fc4
matching USDC transfers: 1
authorization used observed: true
settlement evidence SHA-256: 711830a5b9babe574e3a85a021036fbcb63811bdd96321597bbf557ab724d120
The transaction hash is a public chain reference. Settlement alone does not establish fulfilment or correctness.
Fulfilment observation
The advertised generic deliverable was JSON Repair output.
The frozen delivery contract expected JSON media and advertised the response fields:
repairs
value
Observed response:
initial HTTP: 402
paid HTTP: 200
media type: application/json
media type matches: true
advertised fields present: repairs, value
deliverable shape matches: true
fulfilment: FULFILLED
The returned output included a repairs list and a parsed value object.
Atinamos did not treat that seller output as proof of correctness.
The buyer-facing generic observation classification is therefore:
paid_fulfilment_correctness_not_evaluated
rather than treating unevaluated correctness as missing fulfilment.
Correctness boundary
The generic validation record is explicit:
correctness_evaluated: false
factual_accuracy_evaluated: false
quality_evaluated: false
status: NOT_EVALUATED
reason: CORRECTNESS_NOT_EVALUATED_BY_FULFILMENT_ASSURANCE
seller output as proof: false
This distinction is the core Assurance product boundary:
Payment settled: YES
Advertised deliverable returned: YES
Factual correctness: NOT EVALUATED
Quality: NOT EVALUATED
Trust score: NONE
Immutable package and publication
Runner Verification package:
package id: 234449cc-50da-4504-8a73-c03553cdfe0f
package SHA-256: 1734e2c5d9ed6aacc8c59d65771235fc535d29587167c5037146674b27a0694f
controls: 1
validated: 0
validation failed:0
not evaluated: 1
Verification publication:
publication id: 1f69bf45-5ca5-4bd1-95d4-5229f58e8d77
publication key: atinamos:assurance-publication:c4e785c82f55f03e3e584e64a2626f41b4908f7e94f513f124e69186a1952a8f
status: CONFIRMED
HTTP: 200
result SHA-256: 8e221d45f544a87ac2554142548a2da4dd40b37255cb9aa2bf913ba3d1bc01bc
Signed Assurance Evidence Receipt
Receipt:
atinamos:receipt:10e40afd-f6b1-57bd-9c1e-0a4a1695a428
Observed interval:
started: 2026-09-07T11:42:53.565564Z
completed: 2026-09-07T11:42:56.448751Z
issued: 2026-09-07T11:42:57.000596Z
Receipt outcome:
class: settled_fulfilment_correctness_not_evaluated
attribution: none
summary: Payment settlement and the advertised kind of deliverable were observed.
Factual correctness and quality were not evaluated.
Integrity:
status: signed
algorithm: Ed25519
issuer key: atinamos-assurance-ed25519-202609-002
content hash: sha256:5c323567ce6e97d858153d0403ed93182db8fc1b502b9103d356e282abe77d76
canonicalisation: RFC8785
Public receipt surfaces:
The already-issued signed receipt is immutable. Later presentation/summary improvements do not rewrite its signed content.
Authority lifecycle
The proof began from the normal least-authority production posture:
Runner signer: OFF
Runner live paid execution: OFF
Runner Verification publication: OFF
Verification publication writes: OFF
Verification receipt signing: OFF
Exactly those five gates were temporarily enabled for the bounded proof.
After the executor returned COMPLETE, the saved configuration was restored immediately. Final health confirmed all five gates were OFF again while read-only settlement/evidence/reconciliation capability remained configured.
What this proves
This record supports the narrow claims that:
- the Runner can execute an existing frozen Assurance Run through the routine production stages without manual stage stepping;
- an externally controlled machine service can be tested using the generic fulfilment strategy rather than a bespoke deterministic adapter;
- a real bounded x402 payment of 0.001 USDC was made;
- Base settlement was independently observed at transaction
0xc42bb177c41d21a56e9d3c02546fa8ebeda911cff3bc1139169a61c89f7b495c; - the advertised kind of JSON Repair deliverable was returned;
- correctness and quality remained explicitly unevaluated;
- Verification published a signed, buyer-readable Assurance Evidence Receipt;
- temporary production signing/spending/publication authority was restored OFF after the run.
What this does not prove
This record does not establish:
- that Keyronne's repair was factually or semantically correct in this run;
- permanent reliability of Keyronne;
- future service behaviour;
- that verifier traffic was indistinguishable from ordinary buyer traffic;
- a universal recommendation to purchase;
- a trust score, certification or approval;
- that every machine service exposes enough public metadata for generic Assurance;
- that seller-funded commercial Assurance is generally open to the public yet.
Product conclusion
The production architecture has crossed an important boundary:
seller / service
↓
public machine contract
↓
Atinamos freezes a generic fulfilment test
↓
one bounded unattended Runner execution
↓
real purchase + independent settlement observation
↓
was the advertised kind of deliverable returned?
↓
signed evidence
↓
buyer applies its own policy
The remaining product work is primarily submission/funding/queue UX and operational hardening around this proven primitive, not another rebuild of the Assurance execution model.