CHAINVERDICT INSPECTOR KIT 0.1.1 — FREE DEVELOPER PREVIEW

Unofficial local diagnostics for x401 draft 0.2.0 and selected x402-v2 fields.
Not credential verification, a proof exchange, certification, a security audit,
or proof of payment/delivery. No network requests or paid calls are made.

OFFLINE KIT
Unzip, then use Node 22 or newer. No npm installation is needed.
  node cli.mjs --example > before.json
  node cli.mjs before.json
  node cli.mjs --example browser-fixed > after.json
  node cli.mjs --compare before.json after.json

Inspection exits 1 if any covered check fails, 0 otherwise, 2 for unreadable or
invalid input. Exit 0 does not mean complete conformance or safety. Comparison
exits 0 when two inputs are valid; it does NOT fail CI for new failures. Use a
separate inspection command to enforce that gate. Warnings remain in the report.
The kit contains the same engine as the browser page and dependency licences.

CAPTURE FORMAT
Use a JSON object with:
  kind: "request", "response", or "preflight" (the OPTIONS RESPONSE)
  status: HTTP integer 100..599, required except for requests
  headers: [["Header-Name", "value"], ...]
  context: optional object described below

Preserve duplicate header lines as separate pairs. Do not turn headers into a
map: duplicate evidence would disappear. A capture that already combined or
removed duplicates cannot establish how many lines were originally on the wire.
Only one HTTP message per file; 128 KiB total, 100 pairs, 32 KiB per value.
Do not include response bodies, request bodies, cookies or unrelated headers.
Unknown extra fields are ignored, not checked. No HAR import or raw HTTP parser.
Use your normal debugger to create a SANITISED TEST capture. Do not submit a
capture to ChainVerdict; it is inspected locally. The input may contain sensitive
material, so keep the original file under your own controls.

CONTEXT
  browser: "none" (server-side), "cross-origin", or "unknown"
  credentials: "include" or "omit" (required to assess wildcard semantics)
  origin: the calling browser origin, e.g. "https://app.example"
  requestedHeaders: array of header names from the preflight REQUEST; omit if
    unknown. Only PROOF-RESPONSE permission is assessed, not the full list.
  safeToCache: true only if your deployment explicitly established cache safety
  representationVaries: true/false if you know whether PROOF-RESPONSE selects
    a different representation; omit when unknown

Context is supplied by the developer, not independently authenticated. Origin
and header exposure are separate checks. A successful CORS header check is not
a live browser/preflight test. Methods and the full requested-header list are
outside this profile. A 200 response with PROOF-REQUEST is legitimate in x401;
Inspector cannot tell whether that body accidentally included protected content.

EXACT SCOPE
Official @proof.com/x401-node 0.3.2 checks wire objects. Its embedded OpenID4VP
request and credential result are opaque: no cryptographic or trust evaluation.
Unsupported versions and extension result objects are inconclusive. Legacy
header names are warned about but their payloads/direction are not validated. The 8 KiB
header warning is deployment advice, not a universal protocol limit. Cache
findings distinguish SHOULD guidance and exceptions from structural failures.
PAYMENT-REQUIRED is assessed only for base64 JSON and basic v2 offer fields;
address formats, schemes, network rules and legacy v1 bodies are not validated.
SDK acceptance is not complete specification compliance. JSON duplicate member
handling follows JSON.parse; this tool does not certify a canonical JSON form.

PRIVACY AND REPORTS
No capture values, credential claims, tokens, nonces, URLs, exception strings or
input hashes are put in generated reports. Reports contain fixed rule IDs,
outcomes and explanations; the outcome itself can reveal that an issue exists.
The original capture is never written by inspection. Browser inputs/baseline
exist only in memory. Clear inputs to remove them; no analytics or localStorage.
Downloads happen only on your action. Browser extensions and the device itself
are outside the tool's control. Review any report before sharing it.

WHAT NEXT
Official SDK: https://github.com/proof/x401-node
End-to-end example: https://github.com/acordivari/x401-x402-proof-usdc-e2e
Credential tests: https://openid.net/certification/conformance-testing-for-openid-for-verifiable-presentations/
The offline kit contains the runnable diagnostic engine.
Independent tooling; not affiliated with Proof, OpenID Foundation or x402 Foundation.
Feedback: contact@chainverdict.xyz (no live credentials or private captures)
No paid plan is currently offered. See THIRD-PARTY.txt for dependency licences.

KIT CHANGELOG
0.1.1: Explicit .mjs engine works under CommonJS parent projects and early
Node 22 without adding a package.json that could collide with a project file.
The diagnostic profile remains chainverdict-transport-0.1.0; rules unchanged.
