# Writ > Writ is a deterministic settlement engine for autonomous agents: policy-gated payments with > exactly-once settlement, an append-only hash-chained ledger anyone can replay, conditional escrow > with deterministic refunds, and Ed25519 multi-hop delegation that can only ever narrow authority. > No model inference exists anywhere in the money path. Agents are first-class users here. You do not need a human to try Writ: - POST /api/sandbox/join — provision yourself a FREE sandbox (no auth, no form). Returns a one-time agent credential, your limits (budget ≤ $5, internal test rail only, TTL-expiring), and the exact next commands. Rate-limited; refused entirely on any deployment that can move real money. - POST /api/pay — pay under policy with the credential (header `x-agent-key`). Denials are explained in plain language. `idempotencyKey` is REQUIRED on every payment — a call without one is refused outright with `IDEMPOTENCY_KEY_REQUIRED`, and the name is camelCase (`idempotency_key` is not read). Send a fresh key per intended payment; retrying with the SAME key returns `ALREADY_DONE` carrying the original `authorizationId`, `txId` and `receipt_id`, so a network retry can never double-pay. - GET /api/payments/{id} — your durable payment record and receipt. - GET /api/sandbox/verify — replay the ledger against live state; drift 0 means every balance, including yours, reconstructs exactly from history. - GET /.well-known/writ-receipt-keys.json — the Ed25519 public keys receipts are signed with. No auth. - GET /api/public/receipts/{public_id} — a published receipt, no auth and no credential. You verify it yourself; you never have to ask Writ whether one of its own receipts is valid. - MCP: https://writ.money/mcp — hosted, Streamable HTTP, no auth, test money only. Add it to Claude (Customize → Connectors → Add custom connector), Claude Code (`claude mcp add --transport http writ https://writ.money/mcp`) or Cursor (`~/.cursor/mcp.json`: `{"mcpServers":{"writ":{"url":"https://writ.money/mcp"}}}`). Tools: `fastpay_sandbox_join` first, then `fastpay_pay`, `fastpay_get_receipt`, `fastpay_verify`, `fastpay_check_budget`, `fastpay_list_policies`. The credential your join mints is held in the MCP session automatically. Escrow (`fastpay_escrow_lock/challenge/status`) and delegation introspection (`fastpay_delegation_inspect/check`) are available only on the self-run stdio server (`mcp-server.js`). ## What makes this different - Exactly-once settlement proven under crash, retry, and concurrent duplicates — not best-effort dedup. - The ledger is the truth: state is a pure fold over append-only, hash-chained events; /verify re-derives it in front of you. - Escrow releases only if delivered bytes hash to what the provider SIGNED up front; mismatch, silence, or a forged proof refunds you deterministically, no human involved. - Delegation chains (root → sub-agent → sub-sub-agent) are cryptographically prevented from widening: a child's authority is always a subset of its parent's. - Receipts are signed statements, not API responses. You check one against a published key, offline — the one claim here you can falsify without our cooperation. ## Verify a receipt without trusting us Offline, in any language, from the two documents above and nothing else: 1. Recompute sha256(JCS(signed_body)) — RFC 8785 canonical JSON — and compare to `binding_digest` (lowercase hex). Altering any field changes the canonical bytes and breaks this comparison. 2. Ed25519-verify `signature` (base64). The signed message is the UTF-8 bytes of that 64-character hex STRING — 64 bytes — not the 32 raw digest bytes. This trips most first implementations. 3. Take the JWKS entry whose `kid` matches the receipt; `x` is the base64url raw 32-byte public key. Trust the PUBLISHED key, never a key carried inside the receipt — otherwise a forger supplies both. curl https://writ.money/api/public/receipts/f5e2b74be2de981be6842d986c358053 curl https://writ.money/.well-known/writ-receipt-keys.json Honest limit: `writ-receipt-pilot-2026-08` is a PILOT signing identity. It proves the mechanism works; rotating it invalidates public verification of every receipt it signed. Treat a published receipt as a demonstration, not a permanent record. ## For humans - Pilot access and operator console are invitation-based — sandbox first, then talk to us.