Skip to main content
Each target below names what it proves, the network it applies to, and the marker it prints. “Local” means the hermetic Anvil localnet (Anvil borrows chain ID 91342; it is not public GIWA Sepolia). “Public” means a check against real GIWA Sepolia. A local target proves the mechanism; a public one proves it on the live chain, and Live Evidence keeps the two separate.
These are maintainer-run harness results. The gateway stack and its harness are not publicly available, so the markers here are attributed evidence rather than reader instructions. The shipped client surface is the open-source CLI (see Quickstart: Track Your Usage).

2026-08-05: Hosted payment lane (public write and attributed application evidence)

The hosted lane served the public console at https://giwa.tokscale.ai and the gateway at https://api.giwa.tokscale.ai; both passed their health checks. Stage A exact was exercised with the dedicated macOS Keychain payer 0x02cdd4a6f1308d310d624292a731c2d276310dc5. Fresh authorizations settled on GIWA Sepolia; representative transactions include 0xf6093345… and 0xfe84d874…. The hosted Upto harness then obtained valid 402 challenges, signed the exact challenge-issued expiry, and passed Permit2 allowance preflight. Requests reached the embedded claude-gw provider, but claude-haiku-4-5 and claude-sonnet-4-5 returned Unavailable before durable Upto admission. No Upto binding, payment row, adapter journal row, or settlement transaction was created. Accordingly, no hosted Upto success marker was emitted. This pass proves hosted challenge/signing compatibility and fail-closed no-charge behavior, not terminal hosted Upto delivery. For this lane, 202 means admitted and settling, never complete. A transaction by itself is also insufficient: success requires the terminal completion body and a receipt verified against the pinned signer.

2026-07-31: Public GIWA Sepolia re-verification (public read)

A read-only pass against the public RPC https://sepolia-rpc.giwa.io confirmed GIWA Sepolia chain ID 91342 at observed head block 32133446. Every address and transaction it covers is listed with its explorer link on Live Evidence; this entry records the result of re-checking them rather than restating them.
  • Transactions: all 6 transactions linked on that page are confirmed on-chain with status 0x1, at the blocks recorded there.
  • Addresses: every address linked on that page holds contract code. The pass covered 11; the tUSD deployer has since been listed there explicitly, and it was already covered below as one of the 5 checked runtime code hashes.
  • Deployment records: all 5 runtime code hashes recorded in the deployment records match the live chain: the tUSD deployer and token, the CREATE2 deployer, Permit2, and the Upto Permit2 proxy. Those manifests are public in junhoyeo/tokscale-giwa-contracts under deployments/, so this row is independently re-checkable without the product repository.
The deployed contracts are therefore current, not stale, and no redeployment was performed. Redeploying would produce identical bytecode and invalidate the pinned runtime hashes the test fixtures assert against. This entry records a read-only on-chain verification pass only. It does not establish a public product route or an end-to-end payment lane.

The authoritative full proof (local)

The complete hermetic proof: gateway, Stage A credit top-up, Stage B x402 settlement, receipts, attestation pipeline, and browser checks, all inside Docker. Pass marker: GIWA_LOCAL_E2E_OK. Browser artifacts carry verified=receipt,passport,transactions. For what one pass covers stage by stage, see Gateway Overview.

Crash and fault recovery (local)

Proves Stage A credit recovery survives a crash after settlement: the reconciler resumes from durable state instead of double-crediting or losing the top-up. Pass marker: GIWA_LOCAL_STAGE_A_CRASH_E2E_OK ... authorization_used=1 credited=1.
Proves Stage B fault behavior through a settlement fault proxy: a failed or ambiguous adapter response never becomes a double settlement, and recovery replays read-only. Pass marker: GIWA_LOCAL_X402_FAULT_E2E_OK.

Installed AI clients (local)

Runs the acceptance suite against really installed clients rather than mocked HTTP: the native SDK, Codex, and Claude Code each complete a paid request through the gateway. Pass marker: GIWA_INSTALLED_CLIENT_ACCEPTANCE_OK clients=2 ... accounting=verified privacy=verified. Scoped variants exist for one surface at a time:
Every mode ends by verifying that each terminal request produced a settled ledger entry and a fetchable receipt.

Interactive topology (local)

Brings up a disposable stack that publishes only the API-key gateway and the console on loopback, leaving payment and chain services internal. Ready marker: GIWA_LOCAL_GATEWAY_READY. This is maintainer tooling for driving the stack by hand, not a proof.

Public GIWA Sepolia contract validation (public)

Re-reads the tUSD deployment record against live GIWA Sepolia state through the public RPC: address, runtime code hash, domain separator. Pass marker: GIWA_TUSD_LIVE_VALIDATION_OK.
Read-only validation of the Multicall3 deployment at its canonical address. Pass marker: GIWA_MULTICALL3_READ_ONLY_VALIDATION_OK. Addresses and records: The Public Chain.
Verifies the localnet contract deployments against their source-locked hashes (local).

Protocol vectors (local)

The wire formats are verified three ways: Rust (Alloy), TypeScript (viem), and Solidity (forge). Three independent implementations must reproduce identical bytes, so no single library is trusted twice.
Runs the receipt vector suite: cargo test -p giwa-onchain --test receipt_vectors, then the web-side verifier. Proves UsageReceiptV1 encoding and EIP-712 signing match across implementations. It exits non-zero on a digest or signature mismatch; the leaf, root, and commitment checks belong to attestation-vectors:verify below.
Runs the attestation vector suite: Rust vectors, TypeScript vectors, then forge test --match-contract ReceiptAttestationV1Test. Proves the EAS attestation encoding matches across all three.
Runs the web-side protocol vector verifier end to end.

Dojang on GIWA (public read)

Reads GIWA’s Dojang attestation surface on public Sepolia: resolves the Testnet Faucet attester, calls isVerified(address, attesterId) on DojangScroll, decodes the attestation, and runs negative controls (a random wallet and attester ID must read unverified). Prints Dojang GIWA validation: valid informational evidence at block <n> plus the artifact path. This validates the read path; gating Passport eligibility on Dojang is Phase 2.
Validates the issuer-label metadata handling used when rendering Dojang evidence (labels are display-only, never a verification input).

Topology validators (local, static)

Each validator fails loudly on a regression and exits 0 with a summary line on success.
Validates the default localnet Compose file: loopback-only web console, web excluded from the private Anvil network, bounded read-only RPC proxy, internal payment services, pinned facilitator and Playwright images, immutable migration snapshots. Pass line: Compose topology is valid: loopback web console only, web excluded from private Anvil, bounded read-only RPC proxy, internal payment services, local deployment manifest, pinned facilitator and Playwright, immutable migration snapshots.
Validates the public-chain topology definition without starting it (service count, fail-closed secrets, no stray ports). Pass marker: GIWA_SEPOLIA_TOPOLOGY_OK services=6 database_service=giwa-sepolia-postgres volume=giwa-sepolia-postgres secrets=redacted.
Validate the loopback-gateway overlay and the two fault-injection overlays used by the recovery proofs above (bounded markers, single fault proxy, no extra published services).

Next steps

  • For which of these proves a public claim and which proves a local one, see Live Evidence.
  • For a walkthrough of the authoritative full proof, see Gateway Overview.
  • For the contract records the public validators check against, see The Public Chain.