A-Identity at the Arbitrum Open House Singapore Buildathon
Before an AI agent pays on Robinhood Chain or Arbitrum One, three questions should have answers: who gets paid, is the dollar real, and how much may the agent spend. A-Identity answers all three at the moment of payment, on mainnet, with a receipt or a live read behind every claim. On 2026-09-30, 900 tokens on Robinhood Chain’s public explorer had the symbol USDG or the name “Global Dollar”; 45 of them showed more than 10,000 holders, and the biggest,0xA913C4C2F28AA7b0B15A7C6008a6e19Ff8Bf85c0, showed 194,589 against the real USDG’s
401,824. A symbol is not an identity. That is the problem this entry is about.
Try it
- a-identity.xyz/check/robinhood: paste a token, a wallet, an agent id or an x402 link. /check/arbitrum is the same check for Arbitrum One and native Circle USDC.
- For agents:
GET https://a-identity.xyz/api/robinhood/check?q=<input>(no key), the reason codes at/api/robinhood/check/codes, or the MCP toolevm_pay_checkonhttps://a-identity.xyz/mcp. - The evidence: /proof/robinhood and /proof/arbitrum list every transaction we claim and re-read agent #0 and agent #1259 from the chain on every load.
Built during the Buildathon (from Sep 14, 2026)
What the pay check does, in detail:
- A token. It must be the settlement dollar our chain registry names (Paxos USDG on
Robinhood Chain, native Circle USDC on Arbitrum One), and its EIP-712 signing domain must
reproduce the token’s live
DOMAIN_SEPARATOR. USDG exposes noversion(), so the domain is proven from candidates, never pasted. A token that copies the name and symbol is a fake; one that only shares the symbol (Arbitrum’s bridged USDC.e) is “not the dollar this chain settles in”, never “fake”. The answer always names where the real one is. - A wallet. Does it hold an ERC-8004 agent id on this chain, and was it ever used.
- An agent id. Is it registered, and does the registration file it points to list that id back. Token #1 on Robinhood Chain was minted 7 seconds after our #0, pointing at our agent card; the check flags it.
- An x402 link. Which asset its 402 challenge asks for, which signing domain it hands the buyer, and who it pays.
- The chain. It reads
arbChainID()from the ArbSys precompile at0x64(4663 and 42161) instead of trusting a name. - Safety of the check itself. A pasted link is fetched with the address screen inside the connection’s own DNS lookup, so DNS rebinding cannot reach a private network, and redirects are not followed. Nothing unproven is called safe: an unprovable domain reads “Could not verify”, and a registration is labeled identity, not a review.
Already there before Sep 14 (the baseline, not claimed as Buildathon work)
- 2026-08-12: agent #0 minted on Robinhood Chain mainnet’s canonical ERC-8004
IdentityRegistry, tx
0x602ce85ad044836b39918311a3031dcd689e4be0d23aed9ed0ac9227d46ec79e. - 2026-08-13: our x402 facilitator settling in USDG on Robinhood Chain; agent #1259 on
Arbitrum One, tx
0x23275840eb9a8b85a752769c113109a753f39b592236c85093cf94f6a517b2f3. - 2026-08-28: the two AgentSpendPolicy vaults deployed, Robinhood Chain
0x05a6aad7124c2f1c7b82b03e0bbe3867bc500073and Arbitrum One0xac6c5c9af62bc482ffeef882a6ac4678513be6db.
Numbers (2026-10-01)
- 1,480 unit tests declared across 98 files, all passing, plus 48 end-to-end and 149 guardrail assertions against a running server.
- Vault policy on both chains: 1 USDG or USDC a day and 0.25 per payment for the agent key;
above that the contract refuses with
AboveAutoApproveand the payment is the owner’s to make. - Each vault operation on 2026-10-01 cost about 31,000 gas, about 0.0000006 ETH.
Bugs found and fixed
We audited our own Arbitrum and Robinhood Chain surfaces during the Buildathon. What we found was wrong, and is now fixed:- Both mainnet vaults’ session keys had lapsed on 2026-09-04, so every agent payment reverted, while the proof pages still described a working 7-day key. Renewed, and the agent key now differs from the owner key, which it did not before.
- The facilitator rejected every stock x402 v2 request (the
amountfield). /supportedadvertised one chain’s minimum on every chain.- The proof’s gas total added Arc’s USDC-denominated gas to ETH gas; 99% of the figure was the former.
- Nine public surfaces said no published facilitator served Robinhood Chain. Others do. The surfaces now say why we run our own instead: one code path and one receipt standard on every chain we sell on.
- A doc called agent #0 “the first agent ever registered on this chain”. It is the first token the canonical registry minted, which is narrower and true.
Known limits
- Every settlement so far is our own buyer wallet paying our own address. It shows the rail works, not that there is demand, and the proof pages label it internal.
- We did not deploy the ERC-8004 registries; their authors did.
- The vault owner is a server-held key, and the contract has no owner transfer. The split limits what the agent key can do; it does not make the owner a hardware wallet.
- There is no ValidationRegistry in this mainnet registry family, so a KYA result cannot be anchored on chain here.
- These are L2s: we wait for confirmations and record the block, and we do not claim Ethereum finality.
- A-Identity also runs on Arc, Base, Stellar and Algorand. This page is only about Robinhood Chain and Arbitrum One.
Prior art
Other x402 facilitators serve Robinhood Chain, hosted and open-source, some predating our August launch; Coinbase and thirdweb serve Arbitrum One. Gasless EIP-3009 relaying on USDG predates us. Other projects verify stock tokens by bytecode and deployer. We do not claim to be first at any of these. What this entry combines is the payment moment: who, is the dollar real, and how much, in one flow, on mainnet.Verify it yourself
mcp/src/evm-pay-check/, the rail in mcp/src/x402-3009/, the vault in
mcp/contracts/AgentSpendPolicy.sol.