{
  "implementation": "independently authored Node native HTTPS/crypto client",
  "protocol_version": "1.2.0-draft.2",
  "started_at": "2026-09-16T12:07:35Z",
  "origin": "https://127.0.0.1:60265",
  "certification": "internal implementation test; not external certification",
  "tests": [
    {
      "name": "authoritative discovery with independently pinned origin keys",
      "status": "passed"
    },
    {
      "name": "free offer scope, exact context bytes and preapproved human terms",
      "status": "passed"
    },
    {
      "name": "prohibited purpose cannot create an offer",
      "status": "passed"
    },
    {
      "name": "foreign principal cannot create an offer",
      "status": "passed"
    },
    {
      "name": "duplicate-member and noncanonical-integer HTTP bodies rejected",
      "status": "passed"
    },
    {
      "name": "wrong principal and wrong offer digest in signed acceptance rejected",
      "status": "passed"
    },
    {
      "name": "concurrent independently signed retries create one exact durable receipt",
      "status": "passed"
    },
    {
      "name": "changed retry payload and second offer acceptance rejected",
      "status": "passed"
    },
    {
      "name": "receipt cryptographic tamper and type substitution rejected locally",
      "status": "passed"
    },
    {
      "name": "foreign client cannot read offer/receipt, mint token or export owner records",
      "status": "passed"
    },
    {
      "name": "opaque access token separately issued for active free agreement",
      "status": "passed"
    },
    {
      "name": "protected GET requires token and explicit permitted purpose",
      "status": "passed"
    },
    {
      "name": "GET representation selected by Link matches signed manifest and body",
      "status": "passed"
    },
    {
      "name": "single-range and conditional revalidation remain distinct HTTP outcomes",
      "status": "passed"
    },
    {
      "name": "HEAD contains no body; aliases and wrong HTTP method are rejected",
      "status": "passed"
    },
    {
      "name": "signed use report authenticates a declaration without proving its truth",
      "status": "passed"
    },
    {
      "name": "report retries preserve exact intake; changed payload conflicts",
      "status": "passed"
    },
    {
      "name": "a second event ID for the same operation is a claim record, not another use",
      "status": "passed"
    },
    {
      "name": "report source and principal association cannot be impersonated",
      "status": "passed"
    },
    {
      "name": "anonymous spoof cannot enter authenticated reporter namespace",
      "status": "passed"
    },
    {
      "name": "portable paginated export independently verifies original bytes and trust",
      "status": "passed",
      "detail": {
        "verified_records": 7,
        "trust": "separately provisioned origin pins and retained discovery bytes"
      }
    },
    {
      "name": "client cannot introspect or revoke; administrator revocation is final",
      "status": "passed"
    },
    {
      "name": "original accepted receipt remains retrievable after revocation",
      "status": "passed"
    }
  ],
  "finished_at": "2026-09-16T12:07:35Z",
  "passed": 23,
  "failed": 0
}
