
Security News
White House Authorizes Private Companies to Conduct Offensive Cyber Operations
A new federal program will let vetted U.S. cybersecurity firms help investigate and disrupt foreign cybercrime groups under government direction.
@bolyra/payment-protocols
Advanced tools
ZKP privacy layer for Visa TAP and Google AP2 — Bolyra as the identity backbone for agentic commerce
ZKP privacy layer for agentic commerce payment protocols. Open-source protocol research — not production software.
When AI agents make purchases on behalf of humans, payment networks need to verify:
Today, Visa's Trusted Agent Protocol (TAP) and Google's Agent Payments Protocol (AP2) answer these questions with centralized registries and plain-text mandates. The merchant sees everything — the user's identity, their exact budget, their full policy.
Bolyra replaces that with zero-knowledge proofs. The merchant learns only:
The merchant never sees: the human's identity, the exact spend limit, the full vendor allowlist, or the delegation chain structure.
┌──────────────┐ ┌──────────────────┐ ┌──────────────┐
│ Human │────▸│ Bolyra SDK │────▸│ ZKP Proof │
│ (identity) │ │ (handshake + │ │ (public │
│ │ │ spend policy) │ │ signals │
└──────────────┘ └──────────────────┘ │ only) │
└──────┬───────┘
│
┌───────────────────────┼───────────────────────┐
▼ ▼ ▼
┌────────────────┐ ┌────────────────┐ ┌─────────────────┐
│ Visa TAP │ │ Google AP2 │ │ Spend Policy │
│ Adapter │ │ Adapter │ │ Encoder │
│ │ │ │ │ │
│ TAP payment │ │ AP2 mandate │ │ Bitmask │
│ signal + │ │ proof + │ │ encoding + │
│ trust score │ │ delegation │ │ verification │
└────────────────┘ └────────────────┘ └─────────────────┘
| TAP Concept | Bolyra Equivalent |
|---|---|
| Agent registry lookup | ZKP proof of human authorization |
| HTTP Message Signature (RFC 9421) | ZKP proof + scope commitment |
| Payment Instructions API | Spend policy encoded in permission bitmask |
| Payment Signals API | Scope commitment + agent nullifier |
| Trust tier | Score-based grading (A/B/C/D/F) |
| AP2 Concept | Bolyra Equivalent |
|---|---|
| Intent Mandate | Bolyra handshake proof (human → agent) |
| Cart Mandate | Spend policy ZKP (covers specific transaction) |
| Payment Mandate | Off-chain verified proof (batch mode) |
| Agent-to-agent delegation | Bolyra delegation chain with hop tracking |
| Mandate signature | ZKP proof (Groth16 for human, PLONK for agent) |
| x402 Concept | Bolyra Equivalent |
|---|---|
PAYMENT-REQUIRED header (chain, asset, amount, recipient) | Parsed into X402PaymentRequirements, no change |
PAYMENT-SIGNATURE header (signed USDC envelope) | Unchanged — Bolyra rides alongside, does not replace |
| CDP Facilitator sanctions / compliance check (server-side) | ZKP proof of spend-policy fit (cumulative bitmask) at challenge time |
| Wallet-API budget control ("$1, expires in 5 min") | Cumulative-bit FINANCIAL_* permission proved in-circuit |
| Implicit human consent (out-of-band) | Mutual handshake binds human → agent before any spend |
| Server-issued nonce / replay-protection | Bolyra-Challenge header bound to handshake sessionNonce |
| Settlement on Base / Solana (~200ms USDC) | Unchanged — Bolyra adds the authorization layer, not the rail |
import { createVisaTAPVerification } from '@bolyra/payment-protocols';
const result = await createVisaTAPVerification(
humanIdentity,
agentCredential,
{
maxTransactionAmount: 50_000, // $500
maxCumulativeAmount: 100_000, // $1,000
currency: 'USD',
timeWindow: { start: now, end: now + 86400 },
},
{
agentDid: 'did:bolyra:base-sepolia:...',
merchantId: 'visa-merchant-123',
amount: 5_000,
currency: 'USD',
transactionId: 'txn-abc-123',
},
);
// result.verified: boolean
// result.score: 0-100
// result.grade: 'A' | 'B' | 'C' | 'D' | 'F'
// result.paymentSignal: opaque token for TAP Payment Signals API
import { createAP2AgentCredential, verifyAP2AgentCredential } from '@bolyra/payment-protocols';
// Agent side: create credential
const credential = await createAP2AgentCredential(
humanIdentity,
agentCredential,
[
{ name: 'purchase', maxAmount: 50_000, currency: 'USD' },
{ name: 'price_compare', maxAmount: 0, currency: 'USD' },
],
);
// Merchant side: verify credential
const verification = await verifyAP2AgentCredential(credential);
// verification.verified: boolean
// verification.score: 0-100
import {
createX402Authorization,
verifyX402Authorization,
parsePaymentRequired,
X402_BOLYRA_CREDENTIAL_HEADER,
} from '@bolyra/payment-protocols';
// --- Client side: respond to a 402 with both PAYMENT-SIGNATURE and Bolyra-Credential ---
const requirements = parsePaymentRequired(response.headers['payment-required']);
const result = await createX402Authorization(
humanIdentity,
agentCredential,
spendPolicy,
{
requirements,
bolyraChallenge: BigInt(response.headers['bolyra-challenge'] ?? 0),
},
);
// Attach Bolyra-Credential alongside the standard PAYMENT-SIGNATURE header.
const retryHeaders = {
...buildPaymentSignature(requirements),
[X402_BOLYRA_CREDENTIAL_HEADER]: result.headers[X402_BOLYRA_CREDENTIAL_HEADER],
};
// --- Server side: verify before letting the USDC transfer settle ---
const decision = await verifyX402Authorization(
request.headers['bolyra-credential'],
requirements,
async (did) => lookupAgent(did),
);
if (!decision.verified || decision.score < 70) {
return new Response('Payment authorization rejected', { status: 402 });
}
// → continue with standard x402 settlement (CDP Facilitator or self-verify)
import { encodeSpendPolicy, verifySpendPolicyProof } from '@bolyra/payment-protocols';
// Encode for ZKP circuit
const bitmask = encodeSpendPolicy({
maxTransactionAmount: 50_000,
maxCumulativeAmount: 100_000,
currency: 'USD',
timeWindow: { start: now, end: now + 86400 },
categoryRestriction: { allowedMCCs: ['5411', '5812'] },
});
// Merchant-side verification (from ZKP public signals)
const { satisfied, reasons } = verifySpendPolicyProof(bitmask, {
minTransactionAmount: 10_000,
requiredMCCs: ['5411'],
});
@bolyra/sdkApache-2.0 — open-source protocol research.
FAQs
ZKP privacy layer for Visa TAP and Google AP2 — Bolyra as the identity backbone for agentic commerce
The npm package @bolyra/payment-protocols receives a total of 6 weekly downloads. As such, @bolyra/payment-protocols popularity was classified as not popular.
We found that @bolyra/payment-protocols demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
A new federal program will let vetted U.S. cybersecurity firms help investigate and disrupt foreign cybercrime groups under government direction.

Research
/Security News
The campaign amassed more than 75,000 installs by targeting Russian-speaking users seeking access to blocked services.

Company News
Open source maintainers are under more pressure than ever. We're raising our open source program from the Team plan to the Business plan, free.