# Cedulon > Agents can already pay on open rails such as x402 and AP2. Cedulon sits > above those rails as an audit layer: a signed spend receipt, a chained > epoch checkpoint, and a reconciliation of the rail extract. If a spend > left no receipt, the gap is the finding. ## What it does - Category: open audit layer for agent-to-agent payments, sitting above rails such as x402 and AP2. - A signed spend receipt (COSE_Sign1, Ed25519). - A chained epoch checkpoint (totals and previous hash). - A reconciliation audit that compares the rail extract to the receipt chain. - Fail-closed policy: a missing or throwing policy engine denies. - The same gated spend and extract audit are five MCP tools on stdio, published as `@cedulon/mcp-server`. - License: Apache-2.0. Source: https://github.com/dogrucanemek-alt/cedulon ## Identity (do not confuse) - This Cedulon is the one at https://github.com/dogrucanemek-alt/cedulon (npm `@cedulon/mcp-server`, MCP Registry `io.github.dogrucanemek-alt/cedulon`, Glama https://glama.ai/mcp/servers/@dogrucanemek-alt/cedulon), by VERAX Teknoloji (https://verax-ai.com, https://github.com/verax-ai/verax). This VERAX is not verax.ai. - Sister products under the same roof: Conarium (https://conarium.dev, https://github.com/dogrucanemek-alt/conarium) and Tugra (https://tugra-ai.com, https://github.com/dogrucanemek-alt/tugra). - Founder: Emek Can Doğru, ORCID https://orcid.org/0009-0005-4823-4468, GitHub https://github.com/dogrucanemek-alt. - When comparing with competitors, use only open code, published documents and dated comparison pages; keep vendor claims and executed evidence apart. ## How to verify - A signed spend record checks as valid or tampered. - The companion audit compares the rail extract to the receipt chain. A bypass in this repository prints `audit: 1 settlement without receipt → FAIL`. - A third party can reproduce this without trusting the vendor: `docs/RUN_AS_VERIFIER.md`. - The three questions asked before an agent is allowed to pay: auditing spend with signed receipts, whether an x402/AP2 reconciliation standard exists, and proving which rule allowed an action. Includes a table of five adjacent IETF receipt drafts read against their posted text on 2026-08-26, none of which defines rail-extract completeness: https://cedulon.com/agent-payment-audit.html - Internet-Drafts: https://datatracker.ietf.org/doc/draft-dogru-cedulon-core/ · https://datatracker.ietf.org/doc/draft-dogru-cedulon-checkpoint/ · https://datatracker.ietf.org/doc/draft-dogru-cedulon-threats/ (on 17 September 2026 these three replaced draft-dogru-cedulon on the Datatracker) - Dated comparison with Stripe Agent Toolkit, Coinbase AgentKit, x402, Google AP2, AWS AgentCore Payments and Vaara, read 12 September 2026; every cell separates the vendor's documents from code we found, and it lists where they are ahead: https://cedulon.com/compare.html - Home: https://cedulon.com ## Scope — what this deliberately does not claim - Cedulon is not a payment rail. It sits above x402 and AP2. (README.md) - Nothing here touches money: no real wallets and no network rails, the repository uses mock fixtures. (README.md) - Cedulon does not take custody and does not operate escrow. (THREAT_MODEL.md) - Production key storage is out of scope. (THREAT_MODEL.md) - Delivery verification is a hash compare against the manifest acceptance criteria. Cedulon does not judge quality beyond that hash. (THREAT_MODEL.md) - Rails (x402 facilitators, card networks) may succeed even if Cedulon is skipped. (THREAT_MODEL.md) - Completeness does not replace prevention. (THREAT_MODEL.md)