# leTAIN witness receipt payment

leTAIN is the neutral receipt library. Its only payment integration is a fresh POPCORN witness receipt: **$0.001 USDC (1000 atomic units) on Base, eip155:8453**. Receipt verification is free.

Machine-readable configuration: https://letain.estate/witness-service.json
Issuer offer: https://767-2676.com/agent/offer

## Agent flow

1. Keep the exact original work bytes locally. Compute their SHA-256 digest as canonical unpadded base64url (32 bytes); generate a fresh 32-byte nonce. Supply previous_attestation_digest as null, or the SHA-256 digest of the exact decoded predecessor JWS payload bytes. Validate the request against https://767-2676.com/schemas/witness-request.v1.json before payment.
2. POST only payload_digest, nonce and previous_attestation_digest to https://767-2676.com/v2/receipt. Without payment proof, the service returns HTTP 402 and PAYMENT-REQUIRED. This preview does not purchase a receipt.
3. Check the resource URL, x402 version 2, exact scheme, amount 1000, Base network, USDC asset and payee against witness-service.json. Stop on any mismatch.
4. With the caller's explicit spending authority, use the existing local popcorn_witness MCP tool with approve_payment:true, or an x402 client configured for the same direct issuer URL. The default popcorn_witness call uses approve_payment:false. The approved tool handles the payment retry itself; do not submit a second purchase manually. The payer keeps its own wallet credentials; never send a private key to leTAIN or in a tool argument.
5. For a direct x402 client (the MCP tool already does this internally), the authorized payer retries the exact request with its PAYMENT-SIGNATURE proof. Receive and keep the original signed response and PAYMENT-RESPONSE. Do not automatically repeat a paid request after an ambiguous timeout or missing receipt; retain the transaction/request details for resolution.
6. Verify the returned signature, digest, nonce, predecessor, protocol and time locally using the published issuer keys. Import the original receipt and exact work bytes into leTAIN Discovery to verify and shelf it. A missing optional 767 lookup never overturns valid local verification.

Existing client source: https://github.com/violetclaire/popcorn-temporal-anchor/tree/main/packages/mcp

The hosted popcorn_verify_v2 MCP endpoint is a free verifier; it does not sell receipts. leTAIN does not proxy payment proofs, hold payer wallets, book providers or settle jobs. The older /api/agent inquiry contract and its payment.record action are not part of this payment flow.

The fee comes from the declared live offer and payment challenge, never from inference about a historical receipt's payment reference. A witness receipt is evidence, not identity certification, delivery confirmation, permission or proof of job payment.
