DEVELOPER REFERENCE / DEVELOPMENT PREVIEW

MachineTransfer launch checklist

Updated 2026-10-08T07:24:07.238776+00:00. 78 tasks covering the original product request.

Status meanings: public is externally available; local is implemented in the development kit; done is a documented decision or completed non-deployment task; pending needs implementation or verification; blocked depends on a named external input. Local work is not a public financial launch.

Snapshot: 12 blocked, 12 done, 23 local, 17 pending, 14 public.

Priority: use the owner-wallet launch screen with free test ETH for the shared pilot, then plan a dedicated network and real-asset security and interoperability. No requirement for universal AI preference can be marked complete by code alone.

Identity and public website

  1. DONE | Choose a clear name and purpose. MachineTransfer / MTR: money for AI agents, controlled by the wallet owner.
  1. DONE | State honest adoption and value claims. No guarantee that agents prefer MTR, that its value increases, or that it beats every payment method.
  1. PUBLIC | Register the approved domain. machinetransfer.com purchased for US$11.18 through 2027-10-08; proofs/domain-registration.json.
  1. PUBLIC | Enable registration privacy and record renewal policy. Privacy enabled; auto-renew off. Renewal will need an explicit future decision.
  1. PUBLIC | Connect apex and WWW DNS to existing hosting. Registrar write/readback matched the hosting targets; no unrelated records removed.
  1. PUBLIC | Verify apex and WWW HTTPS delivery. Apex and WWW native hosting status active, TLS active, anonymous HTTPS 200; proofs/domain-connection.json.
  1. PUBLIC | Publish the website for anonymous visitors. Public website and updated release verified anonymously on both custom-domain routes; proofs/website-release.json.
  1. PUBLIC | Publish custom-domain metadata and discovery links. Custom-domain canonical URLs, sitemap and discovery links verified in the deployed release.

Token and exact payments

  1. LOCAL | Implement standard ERC20 transfers. contracts/AgentToken.sol uses OpenZeppelin; standard token balances and allowances.
  1. LOCAL | Implement Permit approval signatures. Permit and domain separation included in contract suite.
  1. LOCAL | Preserve 5% annual inflation. Each completed 365-day epoch adds floor(previousSupply/20) to the immutable treasury.
  1. LOCAL | Support delayed issuance settlement. Permissionless catch-up bounded to 20 epochs per call; tested time boundaries.
  1. DONE | Select the intended treasury and genesis recipient. Configured MCRTPay recipient selected for genesis and treasury: 0xB3201393ba3Ba0724C225A5f1EE4fB9ee24aeB21. Control/recovery remains unverified; no production mint occurred.
  1. LOCAL | Implement fixed treasury transfer tax. Immutable 1% deducted from gross transfers; no arbitrary mint, upgrades or tax exemptions. Contract, API, SDK, receipt and DEX tests cover tax accounting.
  1. LOCAL | Sign exact payments. EIP712 sender, recipient, amount, chain, contract, validity window and nonce.
  1. LOCAL | Prevent reused and wrong-domain authorizations. Contract tests reject replay and incorrect chain/contract/signature inputs.
  1. LOCAL | Cancel unused authorizations. On-chain cancellation supported; cancellation can race an in-flight payment.
  1. LOCAL | Support smart-contract wallet signatures. ERC1271 verification included in the contract and tests.

Wallet and cost controls

  1. LOCAL | Prepare and verify payment instructions. Loopback API and SDK prepare exact amounts and independently check returned transaction bytes.
  1. LOCAL | Require explicit policy opt-in. sdk/policy.cjs rejects disabled or malformed policy and mismatched chain/token.
  1. LOCAL | Check recipient and per-payment limits. Trusted allowlist and integer token ceilings; no claim of cumulative-budget enforcement.
  1. LOCAL | Check fee and expiry ceilings. Policy enforces caller-supplied maximum native fee and bounded payment expiry.
  1. LOCAL | Check swap destination and slippage policy. Explicit allowed routers/output asset and integer minimum-output checks.
  1. PENDING | Implement cumulative budgets and scoped session keys. Needs a chosen smart-account/session architecture, persistent spend accounting and recovery/revocation tests.
  1. LOCAL | Calculate fees without floating-point loss. sdk/fees.cjs keeps omitted charges unknown and provides exact native units and optional rational USD output.
  1. DONE | Explain send fees versus swap costs. docs/system-and-fees.md: 1% token tax plus gas; gross/net and $0.0001 illustrative payment explained. No live USD price. Local pool adds a 0.3% swap fee.
  1. PENDING | Quote real public transaction gas and settlement costs. Public token deployment and chain-specific estimation still required. The taxed local signed fixture used 110,888 gas; not a public fee quote.
  1. PENDING | Benchmark costs and latency against alternatives. Needs reproducible public workloads, finality, failure rate, p50/p95 costs and equivalent payment use cases.

Own public network

  1. DONE | Preserve own-network architecture and choose a free pilot. Own EVM network remains the goal. Free shared Base Sepolia is the next integration pilot, explicitly not the dedicated network; ETH gas and one canonical MTR supply.
  1. DONE | Check whether Merlin can host the chain safely. Read-only capacity inspection found swap, I/O and disk pressure; reuse website systems, keep chain workload separate.
  1. DONE | Verify a cheaper public pilot route. Base Sepolia official public RPC returned chain ID 84532. Zero monthly node subscription; faucet test ETH required. Rejected US$250/month plan retained as historical evidence only.
  1. PENDING | Establish a later dedicated-network budget. No recurring charge approved. Free shared pilot first; dedicated hosting, settlement and operations must be priced after workload evidence.
  1. BLOCKED | Connect a funded secured testnet signer. Owner-wallet launch and receipt-verification screen prepared at pilot.html. Treasury needs free Base Sepolia test ETH and wallet approval. No public deployment submitted. Code and receipt verification tested on a real local EVM fixture.
  1. PENDING | Assign operator and chain-admin recovery ownership. Record who can sequence, upgrade, pause and recover the chain, separate from token treasury ownership.
  1. BLOCKED | Supply settlement access and operator test funds. Requires selected provider plus usable Sepolia execution/beacon service and test-ETH-funded operator roles.
  1. PENDING | Select and verify a public chain identity. Use a fresh collision-checked chain ID, supported stack version and reproducible genesis; local ID is not production.
  1. BLOCKED | Bootstrap and verify the dedicated testnet. Depends on provider, signer configuration and settlement funding; no public chain exists today.
  1. BLOCKED | Expose a restricted public RPC. Depends on public chain; exclude admin/development methods, apply rate limits and test external wallet connectivity.
  1. BLOCKED | Publish explorer and verified deployed token source. Needs actual public RPC, deployment receipts and bytecode/source matching.
  1. BLOCKED | Operate monitoring and a test-gas faucet. Needs funded network, abuse limits, balance/batch alerts and bounded incident/recovery operations.

Ethereum and BNB interoperability

  1. DONE | Define one canonical monetary supply. Inflation only on origin MTR; remote representations must be backed one-for-one.
  1. DONE | Document remote wrapper conservation requirements. No independent inflation on Ethereum/BNB copies; per-destination escrow and retirement reconciliation.
  1. PENDING | Select reviewed bridge technology. Depends on actual canonical network and supported trust/upgrade/withdrawal model.
  1. PENDING | Implement the required bridge adapters. No custom bridge is deployed; implementation follows selected reviewed protocol and supported chain direction.
  1. PENDING | Test bridge failures and supply conservation. Replay, reorg, refund, finality, message-domain and multi-destination accounting tests required.
  1. BLOCKED | Launch funded Ethereum and BNB bridge routes. Requires deployed networks, reviewed bridge, operator controls and approved transaction funds.

DEX and usable markets

  1. LOCAL | Demonstrate ERC20 DEX compatibility. Official Uniswap V2 factory/pair, local LP shares and swap receipts in proofs/dex-demo.json.
  1. PENDING | Integrate an atomic production swap router. Needs selected real deployment with deadlines/minimum output; policy checks alone do not execute swaps.
  1. PENDING | Connect fresh executable liquidity quotes. Requires real chain/pools; reject stale quotes, mismatched output assets and excess price impact.
  1. BLOCKED | Approve and provide market liquidity. No real liquidity budget, paired assets or LP ownership arrangement supplied.
  1. BLOCKED | Verify real market swaps and reserves. Requires public deployment and funded pools; local demo liquidity has no market value.

Agent and merchant integrations

  1. LOCAL | Ship reproducible API and SDK. Local-only endpoints and wallet-owned signing; no server custody or broadcast.
  1. PUBLIC | Publish the API schema. OpenAPI documents available local endpoints, limits and structured errors.
  1. PUBLIC | Publish machine-readable capabilities. llms.txt and agent-payments manifest state publicPaymentsAvailable=false until a public rollout.
  1. PUBLIC | Publish the updated developer source archive. Updated explicit-source developer archive downloaded anonymously and matched byte-for-byte with the release package.
  1. PUBLIC | Provide an interactive payment preview. Public browser-only payment instruction preview; valid/invalid amounts verified. No wallet connection or funds moved.
  1. PENDING | Implement persistent merchant invoices and fulfillment. Authentication, invoice binding, paid state and duplicate/reorg-safe delivery remain outstanding.
  1. BLOCKED | Complete one consenting public merchant pilot. Requires public testnet plus a merchant that explicitly accepts test MTR and defines a delivered service.
  1. PENDING | Implement and verify x402 interoperability. Current bytes-signature ABI is not full ERC3009/x402; needs adapter and standard conformance tests.
  1. PENDING | Earn agent integration and recipient acceptance. Publish integrations and measure real usage; independent AI preference is an outcome, not a configurable guarantee.

Security and recoverability

  1. LOCAL | Pin dependencies and reproducible builds. Lockfile and Node 22 requirement; targeted contract/API checks run without new public privileges.
  1. LOCAL | Restrict all current ingress. Loopback RPC/API, no remote signer, relay, admin route, arbitrary execution or network proxy.
  1. LOCAL | Reject unsuitable public release configurations. Offline guard rejects devnet fixtures, changed policy, unresolved configuration and missing evidence; not an audit certificate.
  1. PENDING | Verify treasury control and record recovery choice. Selected public address is verified; production control proof must come from its owner, without exposing private keys.
  1. BLOCKED | Complete independent financial-code security review. Requires a final deployment scope and independent reviewer before real assets; local tests are not an audit.
  1. BLOCKED | Run public-network restore and incident exercises. Requires actual network, backups and operator participation; no live restore claim yet.
  1. LOCAL | Test invalid intents and fail-closed behavior. Policy, fee, release, API and contract negative cases cover replay, budgets, domains and malformed input.
  1. PUBLIC | Disclose preview privacy and limitations. Homepage preview remains unsigned. Separate testnet launcher shares the selected wallet address with the page and stores recovery hashes locally; no private keys, deposits or analytics. Provider and experimental limitations disclosed.

Release and verification

  1. PUBLIC | Remove the inflation display while preserving the rule. Homepage supply card, slider and listener removed in deployed source. 5% contract rule and technical disclosure preserved.
  1. DONE | Verify desktop and mobile interactions. Desktop 1280px and phone 390px checked: no horizontal overflow, valid/invalid preview works, no console errors; proofs/fees-mobile.jpg.
  1. PUBLIC | Publish understandable system and fee documentation. System/contracts/fees guide and complete launch checklist published and verified on machinetransfer.com.
  1. PUBLIC | Deploy and verify the finished website update. Updated Site deployed successfully; anonymous custom-domain pages, discovery and developer ZIP matched released source. See proofs/website-release.json.
  1. DONE | Preserve source and evidence in one coherent release. Protocol source and evidence preserved in local Git; public website source preserved in its separate Sites repository. Root repository has no remote.
  1. DONE | Stop task-owned temporary resources. Task preview server stopped; task tabs closed and viewport reset. No listeners on the local development ports; proofs/cleanup.json.

Micropayment cost and batching

  1. LOCAL | Batch independently authorized payments atomically. PaymentBatcher accepts up to 64 signatures for one immutable token, without custody or allowances; invalid item rolls back all payments and nonces. Tests and local proof included.
  1. LOCAL | Measure batch overhead savings with comparable fixtures. Ten identical local payments used 822,204 gas separately and 498,999 in a batch, about 39% less. Same recipient and zero starting balances on two fresh tokens; not a public benchmark.
  1. PENDING | Operate bounded gas sponsorship. Relaying can separate sender and gas payer, but funded sponsor, rate limits, persistent owner budgets and reconciliation are not implemented.
  1. PENDING | Evaluate channels for sub-cent payment workloads. The present batch still executes every transfer on-chain. Any off-chain channel needs a separate reviewed dispute, settlement and tax-accounting design.