1.2.0-rc.1 / Release and assurance

Validation

The executed checks, their scope and the corrected review findings.

The results below were recorded on 18 September 2026 and apply to the unchanged implementation included in RC1, frozen on 21 September. They support the stated reference capabilities; they are not external security certification, a production benchmark or proof of universal agent compliance.

Executed checks

Evidence Result and boundary
Python suite 644 methods passed, including HTTPS direct/delegated exchanges, paid state, storage, assets, persistence and refusal cases.
Separate Node implementations 206 tests passed across seven suites. These clients and executors are developed within the same project; they are not independent vendor certification.
Installed command flows 57 checks: 17 direct-free, 17 delegated-free and 23 synthetic-paid, from an isolated installation without source/test-fixture imports.
Current profile schemas 268 structural cases across 16 schemas: 153 positive and 115 negative. These results apply to unchanged schema and fixture bytes.
Native policy checks Seven structural cases for the separately versioned native policy.
Legacy schema checks 40 cases across 17 historical schemas; separate from the current profile set.
Requirement mapping 47 normative requirements with 180 explicit evidence references. A reference to a test is not itself a pass or a compliance score.

Counts overlap and must not be added together. Python integration methods can invoke the Node clients, and installed-flow checks reuse protocol capabilities. Structural schema acceptance does not establish signatures, semantics, authority or safe state transitions.

Behavior covered

The checks exercise exact terms and receipt bindings, separately scoped credentials, refusal after authority withdrawal, immutable history, concurrent retries, process-crash recovery and unresolved deliveries. Payment cases keep the accepted quote, payer mandate and authenticated verifier assertion distinct. Storage and asset cases retain original deadlines and exact dependency references; archives require separately trusted keys and preserve their selected scope.

Boundary regressions cover authority checks before credential transmission and response acceptance, rejection of raw request-target aliases, observation timestamps taken before retrieval, and storage checks immediately before custody. They do not establish every possible deployment or failure condition.

Packaging evidence

The packaging record compares all 73 packaged implementation files with the previously tested wheel. Those bytes are unchanged. The staged wheel adds the complete licence texts; four affected test-launcher cases passed after making the Node executable portable. This was not a new full-suite or fresh-dependency installation run.

The staging inventory hashes the actual packaged files. Declared evidence derivatives identify copies with local machine paths or private mailbox references removed and retain both original and packaged hashes. Earlier inventories describe their own historical files. Packaging inventories are unsigned file records, not signed protocol evidence exports.

Limits

Local HTTPS and synthetic payment assertions do not establish production availability, bank settlement, adoption, complete traffic capture or undisclosed downstream use. No external security audit or independent vendor certification is claimed. The owner has confirmed private security intake and the reviewed package is frozen for RC1. See release status and security and operation.

Odexa / Protocol explorer

This page. Your terms.

Inspect this website’s published policy and see how a proposed use is evaluated.

Current pagehttps://odexa.io/releases/1.2.0-rc.1/docs/validation/
Loading policy…

Published JSON
Open JSON

This is a local policy check, not a signed agreement or proof of agent compliance. Other published licences and applicable rights still apply. How policy evaluation works →

Odexa / Get in touch

Start a conversation.

Tell us what you have in mind. We’ll respond where we can.

We use these details to review and respond to your enquiry. Please leave out confidential information. Submitting does not subscribe you to marketing. Privacy policy.