# Vaultfire V3 x402 Partner Readiness Summary

**Partner status:** Evaluation-ready; production activation pending  
**Last updated:** 2026-08-30

## Executive summary

Vaultfire V3 x402 is built as a future payment and API integration foundation. A capable partner can clone the immutable tested-tooling release, verify that it contains the exact frozen V3 source subtree, run the SDK and sandbox, inspect the V3 APIs and schemas, and begin deployment planning now.

It is not currently a live Vaultfire-operated V3 payment service. Payment-dependent V3 routes intentionally fail closed until contracts, governance, payment infrastructure, monitoring, audit evidence, and partner acceptance are configured and approved. Vaultfire V2 remains the active production x402 surface.

This distinction gives partners a complete technical starting point without representing an unaudited or undeployed system as production-ready.

## What is available today

- **Frozen V3 source:** Public, immutable source candidate with exact tag, commit, tree, archives, and SHA-256 manifests.
- **V3 API contract:** 20 documented route identities with versioned schemas and OpenAPI definitions.
- **V3 x402 interfaces:** Discovery, challenge status, challenge lookup, and receipt lookup interfaces.
- **Safety boundary:** Deployment- and payment-dependent routes return `503 v3_x402_release_gate_closed`.
- **Retired write protection:** The historical V3 partnership-bond action is permanently non-executing.
- **SDK:** 68 of 68 tests pass offline under Node 20 with network access blocked.
- **Protocol tests:** 136 of 136 PR7 tests pass.
- **Partner sandbox:** 11 of 11 tests pass without a wallet or RPC connection.
- **Settlement recovery:** Tested handling for successful settlement followed by receipt-store failure, including no second charge, reconciliation, cross-resource replay rejection, fail-closed behavior, and operational alert generation.
- **Request binding:** Payment identity and receipts bind the canonical HTTP method, exact resource, network, asset, amount, and payee.
- **Evidence release:** Secret-free logs, machine-readable results, archives, and checksums are published for partner verification.

## What a partner can do now

A partner engineering team can:

1. Clone the tested-tooling tag and verify the exact frozen V3 source identity and subtree.
2. Run the deterministic test suites and no-wallet sandbox.
3. Review the contract architecture, APIs, schemas, receipt model, and security controls.
4. Map V3 trust and bond data into an internal application.
5. Design a Base-first V3 x402 route catalog and pricing model.
6. Prepare infrastructure, governance, monitoring, and incident-response plans.
7. Build an isolated proof of concept or Base Sepolia rehearsal.
8. Conduct its own security, legal, privacy, and operational reviews.

A partner cannot use the public Vaultfire V3 endpoints to make or collect live V3 payments today. Those routes are intentionally disabled.

## Readiness assessment

| Area | Status | Partner interpretation |
|---|---|---|
| Source implementation | Ready for review | V3 code exists and is frozen at an exact source identity. |
| SDK and sandbox | Ready for evaluation | Deterministic offline tests and a no-wallet sandbox are available. |
| API and schema contract | Ready for integration design | Routes and schemas can be integrated against without implying live settlement. |
| Payment security design | Implemented and tested | Exact request binding, replay rejection, idempotency, and recovery controls are present. |
| Vaultfire-operated V3 x402 | Not active | Public payment-dependent routes fail closed. |
| V3 contract deployment | Not complete | No Vaultfire V3 production deployment or activation is claimed. |
| Independent human V3 audit | Required | Existing AI-assisted work is not a substitute for an independent human audit. |
| Governance and roles | Required | Multisig, guardian, treasury, payee, and operating roles must be finalized. |
| Base Sepolia rehearsal | Required | The exact candidate needs an end-to-end deployment and recovery rehearsal. |
| Production monitoring | Required | Alert delivery, incident ownership, failover, and recovery must be exercised. |
| Legal and privacy approval | Required | Public-chain data, receipts, retention, payment, and partner terms require approval. |
| Partner acceptance | Required | The adopting partner must reproduce evidence and accept the bounded deployment risk. |

## Recommended first deployment

The recommended first deployment is a tightly capped Base-only pilot:

- One approved design partner.
- A minimal approved route set.
- x402 v2 `exact` payments using Base USDC.
- A multisig-controlled payee rather than a deployer account.
- Governance-controlled activation with writes disabled by default.
- No Solana payment rail or cross-chain value movement.
- No unsupported rewards or modules.
- Strict limits, rate controls, and receipt-retention policy.
- Primary and fallback RPC providers.
- Durable Redis-compatible storage with no in-memory fallback.
- Tested settlement-recovery alerts and an incident runbook.
- A human-approved real-payment canary before broader availability.

This approach limits exposure while proving the full challenge, authorization, settlement, receipt, reconciliation, paid-response, monitoring, pause, and recovery lifecycle.

## Partner responsibilities

The adopting partner should provide or approve:

- Technical integration owner.
- Security-review owner.
- Infrastructure and on-call owners.
- Legal, privacy, and commercial contacts.
- Approved Base addresses for governance and operations.
- Multisig signer and guardian policy.
- Treasury or payment-receiving account.
- Facilitator and RPC provider selection.
- Pricing, route scope, rate limits, and service objectives.
- Data classification, retention, and incident requirements.
- Base Sepolia acceptance criteria.
- Production canary limit and rollback authority.

Vaultfire and the partner should jointly approve a checksummed deployment manifest that binds these decisions to one exact source candidate.

## Conditions for a production-ready claim

Vaultfire V3 x402 should be called production-ready only when:

- The exact candidate completes an independent human security audit.
- Base Sepolia deployment and recovery rehearsals pass.
- Production contract bytecode, addresses, constructors, and roles are verified.
- The route registry, OpenAPI, SDK, discovery, pricing, network, asset, payee, and implementation agree.
- Production storage, facilitator, RPC, secrets, monitoring, and alerting are configured.
- Replay, concurrency, finality, persistence-failure, reconciliation, and rollback tests pass.
- Legal, privacy, commercial, and incident responsibilities are accepted.
- A capped real-payment canary succeeds with no second settlement on retry.
- The partner independently reproduces the evidence and signs acceptance.
- Governance explicitly authorizes activation.

## Exact source and evidence

- **Frozen V3 tag:** `v3-source-2026-08-27`
- **Frozen V3 tag object:** `d9757c125d547968f80d4c61bea08f6638b33dd6`
- **Frozen V3 commit:** `bf4b97f65b7032c778d137bb52a432afc4615b51`
- **Frozen V3 tree:** `a1fd90c26ae676c87a10e7d3e614e84961b2990c`
- **Frozen `v3-src` subtree:** `0a521a25501cd9fe6a74401c99fde450128b22c9`
- **Tested tooling tag:** `v3-tooling-2026-08-30-r2`
- **Tested tooling tag object:** `49b520805f543d72dcaae6d285fade0ec0fc4025`
- **Tested tooling commit:** `241ce24db4c1417acbf936c5b412352531aba2f1`
- **Tested tooling tree:** `4486751cce5bcf3dfdbd34d124d72384916f77e0`
- **Evidence publication tag:** `v3-evidence-2026-08-30-r3`
- **Evidence publication tag object:** `6f39cb9428e1f265164736812e02fd84a42152eb`
- **Evidence publication commit:** `1be0f7e791ffc4ea68bb35228bc8fcac0ff302da`
- **Evidence publication tree:** `e401714961b852aeb54cdf0b2ef62e615ae9e0b7`
- **Public V3 page:** https://theloopbreaker.com/v3
- **Canonical release status:** https://theloopbreaker.com/.well-known/release-status.json
- **Immutable evidence release:** https://theloopbreaker.com/v3/releases/v3-production-evidence-2026-08-30-r3/
- **Evidence checksums:** https://theloopbreaker.com/v3/releases/v3-production-evidence-2026-08-30-r3/SHA256SUMS
- **Complete tagged Git bundle reconstruction:** https://theloopbreaker.com/v3/releases/v3-production-evidence-2026-08-30-r3/tooling/README.md
- **Deployed website source identity:** https://theloopbreaker.com/api/health
- **Deployed website release record:** https://theloopbreaker.com/.well-known/production-release.json

The frozen source, tested tooling, evidence publication, and deployed website are separate identities. The SDK, PR7, sandbox, settlement-recovery, and portable-verifier results belong to the tested-tooling commit and are retained by the evidence-publication commit. The website identity is resolved at deployment time and does not replace either immutable tag.

## Partner-facing statement

> Vaultfire V3 x402 is a built, tested, and frozen integration foundation available for partner evaluation and deployment planning. Partners can verify the source, run the SDK and no-wallet sandbox, inspect the complete API contract, and prepare a Base-first implementation today. Vaultfire-operated V3 payments remain intentionally disabled until the exact deployment passes independent human audit, governance approval, Base Sepolia rehearsal, production infrastructure validation, monitored canary settlement, legal review, and partner acceptance.
