{"id":51511833,"url":"https://github.com/kaiser-data/themis-trust-layer-for-agent-commerce","last_synced_at":"2026-07-08T07:03:11.288Z","repository":{"id":366136456,"uuid":"1274801883","full_name":"kaiser-data/themis-trust-layer-for-agent-commerce","owner":"kaiser-data","description":null,"archived":false,"fork":false,"pushed_at":"2026-06-20T13:07:09.000Z","size":1836,"stargazers_count":0,"open_issues_count":0,"forks_count":0,"subscribers_count":0,"default_branch":"main","last_synced_at":"2026-06-20T13:19:05.326Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"TypeScript","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/kaiser-data.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2026-06-19T22:57:56.000Z","updated_at":"2026-06-20T13:07:12.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/kaiser-data/themis-trust-layer-for-agent-commerce","commit_stats":null,"previous_names":["kaiser-data/agentmarket"],"tags_count":null,"template":false,"template_full_name":null,"purl":"pkg:github/kaiser-data/themis-trust-layer-for-agent-commerce","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/kaiser-data%2Fthemis-trust-layer-for-agent-commerce","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/kaiser-data%2Fthemis-trust-layer-for-agent-commerce/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/kaiser-data%2Fthemis-trust-layer-for-agent-commerce/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/kaiser-data%2Fthemis-trust-layer-for-agent-commerce/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/kaiser-data","download_url":"https://codeload.github.com/kaiser-data/themis-trust-layer-for-agent-commerce/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/kaiser-data%2Fthemis-trust-layer-for-agent-commerce/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":35255393,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-26T15:22:16.424Z","status":"online","status_checked_at":"2026-07-08T02:00:06.796Z","response_time":61,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2026-07-08T07:03:10.605Z","updated_at":"2026-07-08T07:03:11.281Z","avatar_url":"https://github.com/kaiser-data.png","language":"TypeScript","funding_links":[],"categories":[],"sub_categories":[],"readme":"\u003cdiv align=\"center\"\u003e\n\n# ⚖️ THEMIS\n\n### Trust layer for agent commerce — _who your agent should pay, and who to avoid._\n\n**[▶ Live demo →](https://themis-agent-trust.netlify.app)**  ·  Base · ERC-8004 · Circle x402\n\n\u003c/div\u003e\n\n---\n\nBillions of AI agents are about to spend real money on each other's APIs — autonomously. The\nproblem nobody solved: **how does an agent know which service to trust _before_ it pays?**\n\nStar ratings are free to fake. THEMIS makes a score that isn't: **no payment + independent\nverification, no reputation.** Every score is minted from a real USDC call that a second agent\ncross-verified, then written to **ERC-8004 on Base** — Sybil-resistant by requiring paid\ninteractions, independent verification, and wash-risk analysis.\n\n\u003e **Reviews are claims.** THEMIS requires a paid interaction, independent verification, and an\n\u003e on-chain attestation before reputation moves.\n\n---\n\n## Architecture\n\n![THEMIS architecture — the trust loop](docs/architecture.png)\n\nThe whole system is one **clockwise loop**:\n\n1. **Spend path** — the AI model *proposes*; it holds no key. The **Circle Agent Wallet (MPC)**\n   signs only what passes the wallet's on-chain policy, then pays a service via **x402**. A\n   prompt-injected model **cannot cross the trust boundary**.\n2. **Proof loop** — the paid output is **independently cross-verified** (Hunter checks Apollo);\n   `payTx + verifyTx + outcome` are bound into one attestation on the **ERC-8004** registry. Identity\n   is an **ERC-721**, so a track record is an ownable asset.\n3. **Trust feedback** — THEMIS reads reputation **keyless** and scores it on two axes, then the\n   wallet **refuses proven-bad services before a cent moves.**\n\n**The economics, honestly:** writing reputation costs a **verification premium (~2× a call** — you\npay an independent oracle to confirm the output). Reading is **free and permissionless** — because\nthe data lives on the public ERC-8004 registry on Base, *any* agent, wallet, or app can check a\nscore with **no key, no account, no payment.** So one agent pays once and **everyone benefits\nforever**: it's a public good, not a per-agent cost saver. The value isn't the cents saved on one\ncall — it's letting autonomous wallets spend on thousands of unknown services without getting\nscammed.\n\n## The one idea that makes it un-fakeable: two scores, not one\n\nSaying *\"payment proves quality\"* is attackable — a service can pay to manufacture its own\nreputation. So THEMIS never collapses trust into one number:\n\n| | **Quality Score** | **Wash Risk** |\n|---|---|---|\n| Answers | Was the output good? | Was the reputation manufactured? |\n| From | verified pass rate | circular payments, exclusive verifiers, buyer/verifier diversity, self-attestation |\n\nA service with a **100% pass rate but a circular buyer→seller funding loop** is flagged\n**Suspicious**, not Trusted — and the [policy engine](https://themis-agent-trust.netlify.app/policy)\nturns that verdict into a `PAY / TRIAL / REFUSE` decision your wallet can enforce (exportable as JSON).\n\n## 🟢 What's real vs. 🟡 what's simulated (hackathon honesty)\n\nWe'd rather you know exactly where the line is:\n\n| Real, on-chain (Base Sepolia) | Simulated / modeled for the demo |\n|---|---|\n| 3 ERC-721 service identities (`7100`–`7102`) | **Marketplace USDC payments** — Circle's marketplace is mainnet-only, so payments run under `SIMULATE=1` (the rail and code are real; the spend isn't executed) |\n| 9 `giveFeedback` attestations + `getSummary` reads | **Actor funding-root clustering** behind Wash Risk — modeled here; production reads tx senders via RPC (same engine math) |\n| Keyless Circle MPC signing of those attestations | **Helix \u0026 Nimbus** services — labeled *Simulated* in the UI; teaching examples for the Suspicious / Unproven categories |\n\nThe novel layer — payment-anchored, verification-backed **reputation** — is genuinely live and\nverifiable on-chain (links below). Reputation (`ONCHAIN_REPUTATION=1`) and payment (`SIMULATE=1`)\nare **decoupled by design**, so the on-chain part is real on free testnet while marketplace spend\nstays simulated. The three on-chain services (Apollo, Minerva, Clado) carry real receipts; the two\nsimulated services are badged as such everywhere.\n\n## See it in 90 seconds\n| Step | Where |\n|---|---|\n| **Trust Explorer** — services ranked by on-chain reputation, two scores each | [`/`](https://themis-agent-trust.netlify.app) |\n| **Catch a fake** — 100% quality, flagged Suspicious (wash risk 88) | [`/service/helix-signals`](https://themis-agent-trust.netlify.app/service/helix-signals) |\n| **Policy engine** — pay / trial / refuse, before spend | [`/policy`](https://themis-agent-trust.netlify.app/policy) |\n| **Live run** — agent refuses to pay the proven-bad service | [`/live`](https://themis-agent-trust.netlify.app/live) → **Replay** |\n| **Bounties + on-chain proof** | [`/about`](https://themis-agent-trust.netlify.app/about) |\n\n## ✅ Real on-chain (Base Sepolia — verify it yourself)\nNot a mock: 3 service identities are minted as ERC-721s and 9 payment-anchored attestations are\nwritten via keyless Circle MPC.\n\n| Service | ERC-8004 agentId | On-chain reputation |\n|---|---|---|\n| Apollo People Enrich | `7100` | **100%** · 3 verified attestations |\n| Minerva Enrich | `7101` | **100%** · 3 verified attestations |\n| Clado Contacts Enrich | `7102` | **0%** · 3 attestations, all failed verification |\n\n[identity NFT #7100](https://sepolia.basescan.org/token/0x8004A818BFB912233c491871b3d84c89A494BD9e?a=7100)\n· [register tx](https://sepolia.basescan.org/tx/0x500e24e18bf16d401b5b4f1bcfee2e83bfa9dab7050ad968c596d645d9ff6983)\n· ReputationRegistry `0x8004B663…` · IdentityRegistry `0x8004A818…`\n\n## Run it\n\n```bash\n# The infrastructure demo (headline) — two agents + real on-chain reputation, free (no keys, no USDC)\nnpm run network-demo:sim\n\n# The product frontend (THEMIS console) — reads the same on-chain data\ncd web \u0026\u0026 npm run dev          # http://localhost:3000\n\n# Reference consumer — a budget-governed lead-gen agent, 3 interchangeable drivers\nnpm run agent \"Series A fintech CTOs in Europe, 8 leads\"   # Nebius brain (free credits)\nnpm run consumer \"...\"         # deterministic fallback (reliable on stage)\n```\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cb\u003eReal on-chain attestations (free — Circle sponsors testnet gas)\u003c/b\u003e\u003c/summary\u003e\n\n```bash\n# Two Base Sepolia wallets (the registry blocks self-feedback, so they MUST differ)\ncircle wallet login \u003cemail\u003e --testnet\ncircle wallet create --testnet\ncircle wallet list --chain BASE-SEPOLIA      # copy both addresses into .env\n\n# .env: SIMULATE=1  ONCHAIN_REPUTATION=1  ERC8004_NETWORK=base-sepolia\n#       REGISTRAR_WALLET_ADDRESS=0x…   AGENT_WALLET_ADDRESS=0x…  (must differ)\nnpm run register-services                              # mint ERC-721 identities (keyless)\nSIMULATE=1 ONCHAIN_REPUTATION=1 npm run network-demo   # real attestations + on-chain read-back\n```\n\nNo private key is ever held by this code: the agent encodes the call, **Circle MPC signs it** behind\nthe wallet's policy, and **auto-deploys the SCA + sponsors gas**. Payments (`SIMULATE`) and reputation\n(`ONCHAIN_REPUTATION`) are **decoupled**, so the novel on-chain layer runs real on free testnet while\npayments stay simulated. Default LLM model `deepseek-ai/DeepSeek-V3.2` on Nebius (best tool-caller).\n\u003c/details\u003e\n\n## Bounties · Agents Hackathon 2026 (42berlin)\n| Track | Fit |\n|---|---|\n| **Circle — Agentic Commerce** ($1,000) | x402 USDC nanopayments from a keyless Circle Agent Wallet (MPC) behind an on-chain policy |\n| **Agent Infrastructure — ERC-8004** | ERC-721 identities + real reputation attestations; THEMIS is the trust/monitoring layer on top |\n| **Nebius TokenFactory** ($500×2) | the agent brain (DeepSeek-V3.2) — discover, decide, cross-verify |\n| **Tavily** ($500) | prospect discovery — the first step of every run |\n| **Blockchain for Good** ($500) | Sybil-resistant trust makes a trillion-dollar agent economy safe from wash-traded reputation |\n\n## Repo layout\n```\nweb/        THEMIS console (Next.js) — Trust Explorer · Policy Engine · Live Run · Feed\n            lib/intel.ts   the trust engine: quality + wash-risk + verdict + policy\nlib/        reputation (Proof-of-Quality attestations) · erc8004 (keyless encode + read) ·\n            circle-execute (keyless MPC boundary) · rail (real|sim payment) · policy · ledger\nagents/     network-demo (two agents + on-chain reputation) · leadgen-core (shared tools) ·\n            leadgen-agent-nebius (default) · leadgen-agent (Claude SDK) · consumer (deterministic)\nscripts/    register-services (mint ERC-721 identities) · spike-payment\nvendor/     official Circle kits + real ERC-8004 ABIs\ndocs/       architecture.png (+ architecture.html source)\n```\n\nSee **[PITCH_LIVE_DEMO.md](./PITCH_LIVE_DEMO.md)** for the demo script, **[HANDOFF.md](./HANDOFF.md)**\nfor full build state + gotchas, and **[web/README.md](./web/README.md)** for the frontend.\n\n---\n\n\u003cdiv align=\"center\"\u003e\u003csub\u003eA trillion-dollar agent economy can't run on reputation you can fake. So we made reputation you can't.\u003c/sub\u003e\u003c/div\u003e\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fkaiser-data%2Fthemis-trust-layer-for-agent-commerce","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fkaiser-data%2Fthemis-trust-layer-for-agent-commerce","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fkaiser-data%2Fthemis-trust-layer-for-agent-commerce/lists"}