Skip to content

Can the action gateway and the receiving system agree on what happened?

This fixed demonstration records one authorization decision before dispatch, one receiver observation after dispatch, and one direct effect that bypasses the receipting path.

The gateway can show which requests it permitted or refused. The receiving system can show which effects it observed. Comparing those two records exposes an effect that reached the receiver without a matching gateway receipt.

bulla.control-plane-alpha/0.1-experimental defines one synthetic MCP sandbox. The implementation is experimental, the package surface remains SOURCE_ONLY, the target surface is PUBLIC_ALPHA, and deployment is NOT_DEPLOYED. Control is team-operated and the data classification is synthetic-public. Production status is BLOCKED_NO_REMOTE_MUTATION_AUTHORIZED.

What this check cannot tell you

The public-alpha contract defines one synthetic MCP sandbox. Bulla controls the authorization, receiver, denominator, witness, and publication keys. A deployment establishes execution across path-separated services; it does not establish customer authority, denominator completeness, organizational independence, production safety, or incident truth.

Hosted experimental proof

Run the complete synthetic control loop.

ALPHA ENDPOINT UNAVAILABLENEXT_PUBLIC_BULLA_ALPHA_URL is not configured for this deployment.

One run records a permitted request, a refused request, one mediated receiver effect, one declared direct effect, per-anchor coverage, witness evidence, and packet publication.

ALPHA ENDPOINT UNAVAILABLE

NEXT_PUBLIC_BULLA_ALPHA_URL is not configured for this deployment.

No request is attempted. The specification, commands, and trust boundary remain available below.

What the demonstration runs

The manifest accepts the mediated_append and refused_append scenarios, the tools/list and tools/call MCP methods, the sandbox.append tool, and the fixed values alpha-mediated, alpha-refused, alpha-direct-bypass. Tool discovery operates in READ_ONLY_DISCOVERY mode. The closed contract rejects arbitrary receipts, uploads, prompts, paths, urls, credentials, free text. Values outside the declared lists are not accepted.

The reviewed MCP pin is the final 2026-07-28 schema at commit 271ecc9accafdd9b83a3c869fa67c22953b2af80 with digest sha256:ef70b61f99b6d2e5e3b46863822eab08dff6a45bedc7a08914e0e5b133f40203. Its RC-to-final impact on this closed subset is NO_CHANGE_SUBSCRIPTIONS_LISTEN_RESULT_ONLY. MCP request headers and body metadata use revision 2026-07-28. The closed decision policy is pinned at sha256:fe2a76d9dc104e3a4b97fd173e3670e05fd8b79123f5e7126d76e4331b8e810d.

  1. Authorize. Record one permit and one refusal before any mediated dispatch.
  2. Observe. Dispatch the permitted request and record the receiver-assigned observation.
  3. Expose bypass. Execute one fixed test-only direct effect against the same receiver action list.
  4. Reconcile. Report decision coverage 2/2 and effect coverage 1/2 without combining anchors.
  5. Witness. Read the signed checkpoint and inclusion proof for the mediated observation.
  6. Publish. Finalize and download the packet manifest with every exact member byte.

Result supported by the supplied records

Boundary-ingress decision coverage is 2/2. Receiver-effect coverage is 1/2. The direct effect remains outside the mediated receipt set and inside the receiver action list. An uncovered effect is a coverage finding, not a packet-integrity failure.

The browser sends the permitted action through POST /mcp. That route requires agreement among the Streamable HTTP Accept and protocol headers, the MCP method and name headers, the JSON-RPC body, and namespaced permit metadata. The POST /dispatch route is a convenience that synthesizes the same closed envelope and does not establish client-supplied header and body enforcement.

The browser recomputes the permit, refusal, and mediated-observation ActionReceipt v0.4 proof sets; their closed profile, run, request, anchor, decision, and lineage bindings; witness inclusion; checkpoint consistency; per-anchor coverage; and every packet-member digest before reporting completion. Server-reported coverage is compared with the browser result. Run creation uses a fresh cryptographically generated UUIDv4 idempotency key. That key is a secret-equivalent, one-time creation capability. An exact replay returns the same run bearer only while the capability key remains unchanged. After a capability-key change, replay fails closed without returning a replacement token. The browser does not display or persist either creation capability or bearer. Later write operations use the run-scoped bearer and a distinct idempotency key. Neither credential is included in the packet download.

Checkpoint consistency is NOT_APPLICABLE on a first visit because no earlier checkpoint exists in local storage. The browser verifies one signed current checkpoint before requesting inclusion and consistency at that exact tree size. A later run must verify a consistency proof against the retained checkpoint before the browser reports completion.

Packet-member bundle

The browser reads the published manifest, checks each declared byte length and SHA-256 digest while downloading the exact members, and produces a JSON bundle with base64-encoded member bytes. The original relative paths, media types, lengths, and digests remain in the manifest. Strict JSON and resource limits apply before bundling. Unsafe paths, duplicate members, private-key material, bearer credentials, secret-bearing fields, and host paths fail closed.

The bundle is a transport container, not a checker directory. Materialize its members into a new directory before running the standalone Python or Node packet verifier.

The hosted download is a generic glyph.agent-incident-packet/0.1-draft packet. It does not include the deterministic control-plane fixture outer archive and is not input to verify_control_plane_fixture. The live service manifest, run summary, witness checkpoint, inclusion and consistency proofs, and exact witnessed receipt bytes remain separately retrievable and separately verified.

The following commands apply to a loopback run authenticated by the deterministic repository context. A hosted run requires its separately published ceremony context.

$ pnpm --dir packages/bulla-control-plane-alpha packet:materialize -- \
  --bundle /absolute/path/control-plane.packet-members.json \
  --out /absolute/new/packet-directory
$ python3 -I bulla/spec/agent-incident-packet/verify_packet.py \
  /absolute/new/packet-directory \
  --context bulla/spec/control-plane-alpha/contexts/incident-context.json
$ node bulla/spec/agent-incident-packet/verify_packet.mjs \
  /absolute/new/packet-directory \
  --context bulla/spec/control-plane-alpha/contexts/incident-context.json

Trust and limits

The following boundary applies if the public alpha is deployed.

The public-alpha contract defines one synthetic MCP sandbox. Bulla controls the authorization, receiver, denominator, witness, and publication keys. A deployment establishes execution across path-separated services; it does not establish customer authority, denominator completeness, organizational independence, production safety, or incident truth.

Evaluation authority, boundary/receiver, target action-list observer, incident commander, witness, and publisher use distinct team-controlled role keys. This is technical role separation, not organizational independence. External evidence remains A0/J0/I0/W0 · r0.

  • A permit authenticates a policy decision. It does not establish policy legitimacy.
  • The boundary-signed observation receipt authenticates the boundary's report of the receiver result; it does not authenticate the target or establish worldly success.
  • Coverage is relative to the supplied backend action list. A controlling observer can shorten that list.
  • The witness is team-operated. Its output increments neither the external witness count nor the external implementation count.
  • Reliance remains NOT_COMPUTED. Disclosure safety remains NOT_COMPUTED.

Published packet and evidence artifacts contain no bearer credential, secret-equivalent creation key, customer action, host path, arbitrary payload, or private model reasoning. A successful run verifies the declared synthetic loop. It does not promote the profile into Bulla’s stable API or package exports.

Witness verification uses a repository-pinned issuer and public key supplied outside the run and packet. A checkpoint-carried key cannot establish its own trust.

The checked-in trust context is DETERMINISTIC_FIXTURE_ONLY and its endpoint policy is LOOPBACK_ONLY. A public HTTPS endpoint requires a separately generated ceremony context; deterministic fixture keys cannot authenticate a hosted Worker.

The source-only manifest pins repository://bulla/spec/control-plane-alpha/contexts/alpha-context.json at sha256:4a7978ad30cfff1a85408c178c388006fb734d0a09c70d149a24ad994961ccbd. Standalone packet commands use the separate DETERMINISTIC_FIXTURE_ONLY context at bulla/spec/control-plane-alpha/contexts/incident-context.json. A hosted release requires a separately published full control-plane context and a separate three-field incident context produced by the same ceremony.

No tracked service-deployment evidence is present. Endpoint status is not inferred from NEXT_PUBLIC_BULLA_ALPHA_URL.

Public data policy

The active-alpha contract would classify retained records as PUBLIC, accept writes, provide no deletion API, require at least 180 days of retention after the final accepted write, and move final checkpoints and the synthetic corpus to STATIC_REPOSITORY_RELEASE before retirement. Current deployment status is NOT_DEPLOYED; no hosted write or retention availability is established.

The key rotation and retirement gate remains BLOCKED_KEY_ROTATION_RETIREMENT_NOT_IMPLEMENTED. The current ceremony records a versioned keyset, but no production rotation or retirement procedure is implemented.

The retirement export gate remains BLOCKED_OPERATOR_EXPORT_NOT_IMPLEMENTED.

Production remains blocked on external reconciliation, Glyph deployment binding, key rotation and retirement, a signed release-asset manifest, retirement export, and a known-compatible read-recovery release. The machine-readable states are BLOCKED_EXTERNAL_RECONCILER_NOT_IMPLEMENTED, BLOCKED_EXACT_OVERLAY_PROJECT_DEPLOYMENT_BINDING_NOT_IMPLEMENTED, BLOCKED_KEY_ROTATION_RETIREMENT_NOT_IMPLEMENTED, BLOCKED_COMPLETE_SIGNED_MANIFEST_NOT_IMPLEMENTED, BLOCKED_EXPORTER_SOURCE_TESTS_EVIDENCE_NOT_IMPLEMENTED, and BLOCKED_KNOWN_READ_COMPATIBLE_RELEASE_NOT_IMPLEMENTED.

Declared capacity is 10,000 runs and 90,000 receipts. Per-minute limits are 3 run creations and 60 run mutations. Request bodies are limited to 16,384 bytes, generated receipts to 65,536 bytes, each packet member to 65,536 bytes, and packet downloads to 32 files totaling 2,097,152 bytes.

Commands and API

The service contract makes the public manifest readable without a run capability. If an endpoint is configured, the browser is the first-contact runner for the complete write sequence.

$ export BULLA_ALPHA_URL="${NEXT_PUBLIC_BULLA_ALPHA_URL}"
$ curl --fail --silent --show-error \
  "$BULLA_ALPHA_URL/experimental/v1/manifest"
MethodPathResult
GET/experimental/v1/manifestRead the profile, maturity, distribution, deployment gate, and limitation.
POST/experimental/v1/runsCreate an isolated synthetic run. The required UUIDv4 idempotency key is a secret-equivalent one-time creation capability because an exact replay returns the same bearer while the capability key is unchanged. A key change fails closed without returning a replacement token.
POST/experimental/v1/runs/{id}/requestsRecord the closed mediated_append or refused_append scenario.
POST/experimental/v1/runs/{id}/mcpEnforce the client-supplied Streamable HTTP MCP headers, JSON-RPC body, namespaced metadata, tool name, and permit attestation.
POST/experimental/v1/runs/{id}/dispatchConvenience route that synthesizes the same closed tools/call envelope. It does not test client-supplied MCP header and body agreement.
POST/experimental/v1/runs/{id}/test-only/direct-effectCreate the fixed bypass used by the coverage demonstration.
POST/experimental/v1/runs/{id}/finalizeFinalize denominators, coverage, witness evidence, and packet publication.
GET/experimental/v1/runs/{id}/coverageRead separate decision and effect coverage.
GET/experimental/v1/witness/checkpoints/latestRead the current signed witness checkpoint.
GET/experimental/v1/witness/consistency?from={prior}&to={selected}Read consistency evidence between the retained and selected signed checkpoints.
GET/experimental/v1/witness/inclusion/{attestation}?at={selected}Read one receipt-inclusion proof at the selected signed checkpoint.
GET/experimental/v1/witness/receipts/{attestation}Read the exact witnessed receipt bytes.
GET/experimental/v1/runs/{id}/packet/manifestRead packet member paths, lengths, media types, and digests.

The packet profile and standalone verification path remain documented under the Agent Incident Packet.