Verdict checks whether an action may be signed or issued. Write the conditions in an authority YAML file; your application supplies the intent and handles signing. Requires Java 25+.
New to writing policies? Start with one complete example. It shows the input, every YAML field, and the requests that pass or fail.
For agent payments, go straight to AP2 and Mastercard payment policies. For other actions, choose an intent guide.
All artifacts use group org.exploit.verdict.
| Artifact | Purpose |
|---|---|
core |
Policy compiler and evaluator. |
digital-assets |
EVM, Bitcoin, TRON, Solana, and XRP modules. |
evm, bitcoin, tron, solana, xrp |
Individual digital asset modules. |
agentic-payments |
AP2 and Mastercard VI modules. |
ap2, mc-vi |
Individual agent payment modules. |
payments |
Shared AP2 and VI policy functions. |
typed |
Custom JSON intents. |
x509 |
Certificate issuance intents. |
authority |
Authority document parser and compiler. |
authority-oci |
OCI authority loader. |
Start here: docs/README.md.
- Getting started
- Policy language: AND/OR, lists and amounts
- Approval rules
- Troubleshooting
- Core policy engine
- Built-in CEL functions
- Intent modules
- Effect semantics
- Authority documents
- Payment policies: named shops, cards and readable limits
./gradlew test