1. Purpose
This document compiles concrete, externally-reproducible evidence that the AlgoVoi canonicalisation substrate has crossed from internal AlgoVoi work into ecosystem-resident infrastructure. Every datum below is reproducible by running the commands in Section 13 against public APIs (PyPI, npm, GitHub, IETF Datatracker). No private telemetry was used.2. IETF Internet-Draft anchor
Six AlgoVoi-authored Internet-Drafts on the IETF Datatracker, Independent Submission stream, Informational, sole AlgoVoi authorship:
The Independent Submission stream is sponsor-independent. These citation-stable URLs do not depend on the goodwill of any commercial standards-body sponsor.
All six I-Ds expire 2026-11-26 per the IETF six-month rule. Renewal is a single re-submission per draft to extend by a further six months. This is a low-effort quarterly operation included in the diligence-pack maintenance inventory; it does not require IETF approval, working-group sponsorship, or commercial backing.
3. Bibliographic ecosystem inclusion
The AlgoVoi URNurn:x402:canonicalisation:jcs-rfc8785-v1 is indexed in the IETF / Relaton bibliographic catalogue.
Once a URN is in the Relaton catalogue, every downstream citation-rendering toolchain (asciidoctor-bibtex, kramdown-rfc, pandoc, IETF-id-bibxml) resolves it automatically. This is structural ecosystem inclusion at the standards-tooling layer, not one-time citation.
4. Published package distribution
Thirty Apache 2.0 packages under AlgoVoi sole authorship (15 unique package names, each published on both PyPI and npm):algovoi-substrate, algovoi-substrate-pqc, algovoi-settlement-attestation, algovoi-refund-receipt, algovoi-cancellation-receipt, algovoi-composite-trust-query, algovoi-rfc9421-verifier, algovoi-audit-verifier, algovoi-reference-agent, algovoi-receipt-verifier, algovoi-webhook-verifier, algovoi-receipt-sentinel, algovoi-mcp, algovoi-pef, and algovoi-atb.
In addition to the installable packages, three public no-authentication REST endpoints are live at verify.algovoi.co.uk:
The canonical hash computation is independently accessible without installing any package:
4.1 PyPI substrate-aligned packages (last 30 days)
(
algovoi-rfc9421-verifier and algovoi SDK lookups were rate-limited at refresh time. Refresh any time via the API in Section 13.)
4.2 npm @algovoi/* scope (last 30 days)
4.3 Combined and discounted
For reference, typical solo-author niche packages receive 50-200 downloads per month. AlgoVoi is operating an order of magnitude above that baseline. The lockstep pattern across nine packages (200-240 range each) indicates systematic evaluation by at least one party treating the suite as a coherent unit.
5. Public GitHub fingerprint analysis
GitHub Code Search counts for AlgoVoi-distinctive fingerprints across all public repositories (refreshed 2026-05-28):6. External canon_version emit — who is declaring AlgoVoi’s pin in their own code
canon_version: jcs-rfc8785-v1 declared by eight external public repositories:
canon_version: jcs-rfc8785-v2 declared by two external public repositories (v2 published 2026-05-26; broader propagation pending):
7. DID-based keyid resolution usage
AlgoVoi’s RFC 9421 binding extension specifies dual-resolution keyid (DID-based and HTTPS-URL-based). DID-based pattern observed in two adjacent agent-payments extensions:
The dual-resolution design is operating in the wild across more than one extension family.
8. Substrate Adopters Registry
Six attested external entries at docs.algovoi.co.uk/adopters, with AlgoVoi as registry editor:- AlgoVoi v1 (substrate author)
- AlgoVoi v2 (PQC substrate author)
- Supership / Crest Deployment Systems
- PEAC Protocol
- Nobulex
- Vauban Pay
9. JSON SchemaStore inclusion
AlgoVoi compliance receipt v1 schema merged into the SchemaStore public catalogue (PR 5726). The schema is now part of the default schema-validation surface for editors and validators that consume SchemaStore.9a. A2A protocol partners page listing
AlgoVoi is listed on the A2A protocol partners page (entry: “AlgoVoi (https://algovoi.co.uk)”). Per the page’s own framing, listed partners “are part of the A2A community and are helping build, codify, and adopt A2A as the standard protocol” for agent-to-agent communication. The listing was contributed by a community member (a2aproject/A2A PR #1994), not submitted by AlgoVoi. Reproducible: fetch the page and search for “AlgoVoi”.10. Featured public attestations
Selected public statements on open GitHub threads from downstream consumers and independent verifiers, quoted verbatim with source URL for reproduction.10.1 AURA self-attribution on canonicalisation authorship
Source: x402-foundation/x402 issue #2332, comment byluisllaver (AURA contributor), 2026-05-28 01:08 UTC.URL: https://github.com/x402-foundation/x402/issues/2332
“On the canonicalization spec: AURA does not define its own - we conform to RFC 8785 (JCS) + SHA-256, the same discipline @chopmob-cloud is pinning in draft-hopley-x402-canonicalisation-jcs-v1. Cite that; our /v1/action-ref is just a conforming implementation (key sort = UTF-16 code units, strings as literal UTF-8, integers verbatim).”Significance: A downstream consumer publicly directing readers to cite the AlgoVoi IETF I-D as the canonical reference. AURA explicitly states it does not author canonicalisation discipline; AlgoVoi does. This is the substrate-author / downstream-adopter distinction articulated on a public x402-foundation thread by the downstream party itself.
10.2 Three-way byte-identical interoperability verification
Source: x402-foundation/x402 issue #2332, comment byandysalvo (independent verifier), 2026-05-27 13:20 UTC.URL: https://github.com/x402-foundation/x402/issues/2332
“Vector 4 (chopmob corpus anchor): PASS — 3-way byte-identical across Crest, AURA, and AlgoVoi. Published at verify.crestsystems.ai/aura-conformance-v0.json.”Significance: An independent verifier confirming that AURA’s reputation-record canonicalisation, the Crest verifier matrix, and AlgoVoi’s conformance corpus all produce byte-identical hashes on the same preimage. The “chopmob corpus anchor” reference is AlgoVoi’s
chopmob-cloud/algovoi-jcs-conformance-vectors, named explicitly as the anchor point of the three-way agreement.
10.3 Action-ref portability shipped by downstream consumer
Source: x402-foundation/x402 issue #2332, comment bygiskard09 (Mycelium Trails / argentum-core), 2026-05-28 01:25 UTC.URL: https://github.com/x402-foundation/x402/issues/2332
“That’s the property that matters — once the ref is in the evidence array, the receipt is auditable anywhere, no AURA dependency. Clean ship.”Significance: A second downstream consumer (Mycelium Trails) publicly confirming that AURA has shipped action-ref portability per the AlgoVoi-authored discipline (
SHA-256(JCS(preimage))). The “auditable anywhere, no AURA dependency” property is the substrate-author position working as designed: the receipt is independently verifiable because the canonicalisation discipline is normative, not vendor-locked.
10.4 Summary
Three independent organisations (AURA, Crest, Mycelium Trails) publicly on a x402-foundation issue, in the same thread, attesting to:- AlgoVoi’s IETF I-D as the canonical citation for canonicalisation discipline
- Byte-identical interoperability against AlgoVoi’s conformance corpus
- Substrate-author portability working as designed in their shipped consumer-side code
11. Temporal priority: production deployment versus IETF Internet-Draft filing
This section establishes that the IETF Internet-Drafts under sole AlgoVoi authorship formalise behaviour that was already running in production onapi.algovoi.co.uk. The drafts are descriptive of a live system, not proposals for a system to be built. In every case below, the production deployment date precedes the I-D filing date.
The dates below cluster within a five-week window. This reflects a focused, intensive effort during the period when the multi-chain agentic-payment receipt-format gap became operationally pressing on the AlgoVoi production gateway. The compression is real and is acknowledged here as deliberate concentrated work to formalise running production behaviour into a coherent body of IETF-anchored specifications, not as evidence of multi-year prior production history that the dates would not support. The substrate-author value is the combination of production deployment, IETF anchoring, published reference implementations, and cross-implementation cross-validation, all of which are demonstrably present, regardless of the calendar window in which they were assembled.
11.1 Discipline-by-discipline timeline
For the two disciplines without an IETF I-D anchor at refresh date (
urn:x402:canonicalisation:jcs-rfc8785-v2 PQC discipline, and rfc9421-x402-binding-v1), the substrate-author anchor is the Apache 2.0 reference implementation publication date on PyPI and npm, together with the hash-stable version-pin history maintained by both registries. For PQC v2 the anchor package is algovoi-substrate-pqc (published 2026-05-26 on PyPI and npm). For the RFC 9421 binding the anchor package is algovoi-rfc9421-verifier (published on PyPI and npm as @algovoi/rfc9421-verifier, current version 0.3.x). Registry publication timestamps are publicly auditable and serve in lieu of the IETF Datatracker timestamp until the I-Ds are filed.
11.2 Foundational platform milestones (context)
These are not standards themselves but the platform underpinnings that the standards-bearing services run on:11.3 CTEF non-inclusion
AlgoVoi submitted contributions to the Collaborative Trust and Evidence Framework (CTEF) process during the period covered by this timeline. Those contributions were not included in the final CTEF publication. The substrate artefacts documented in this page — IETF Internet-Drafts, Apache 2.0 reference implementations, cross-implementation conformance vectors, and hosted verification endpoints — are AlgoVoi-authored and exist independently of any consortium process. For every receipt-family I-D, the underlying format was emitting under production traffic onapi.algovoi.co.uk for at least nineteen days before the formal IETF Internet-Draft was filed. For the recurring-lifecycle receipts (refund, cancellation), the production behaviour predates the I-D by approximately twenty-four days. The canonicalisation pin itself was the wire format of the production gateway ten days before the I-D was posted.
The substrate-author position is therefore not anchored only in IETF filings or published packages. It is anchored in a system that was running, emitting, and verifying the wire format under real traffic before any of the formal artefacts existed. The IETF I-Ds, the Apache 2.0 reference implementations, and the cross-implementation matrix are all downstream of the production deployment. They describe what was already true, not what was proposed.
11.4 What this demonstrates
Three independent forms of priority evidence:- Live system priority. The wire format was operational under real compliance-auditable traffic across seven chain families before the formal standards artefacts existed.
- IETF Independent Submission priority. The drafts are date-stamped on the public datatracker (2026-05-25).
- Published implementation priority. The Apache 2.0 packages on PyPI and npm have publication dates and version-pin history.
12. Interpretation
Three layers of usage, in order of visibility:- Public GitHub citations and emits. Eight external repositories declaring AlgoVoi’s v1 pin in their own conformance code, including Vauban Pay, AEOESS Consilium, Nobulex, an independent verification repository (andysalvo), and the structural standards-tooling layer (IETF / Relaton / SchemaStore). Three additional public attestations on x402-foundation issue #2332 from AURA, Crest, and Mycelium Trails (see Section 10).
- Standards-tooling ecosystem inclusion. The AlgoVoi URN is in the Relaton bibliographic catalogue, automatically resolved by every IETF-aligned citation-rendering toolchain.
- Silent download adoption. Approximately 2,900 real (post-discount) substrate-aligned package downloads per month across PyPI and npm. The bulk of usage is structurally invisible because Apache 2.0 has no telemetry and most adopters maintain private code.
- A citation-stable normative anchor on the IETF Independent Submission stream
- Apache 2.0 reference implementations with measurable monthly download traffic
- Public attestation by external parties through their own code, their own repositories, and their own statements in public threads
action_ref hash computation and RFC 9421 signature verification are also independently accessible via hosted endpoints at verify.algovoi.co.uk/action-ref and verify.algovoi.co.uk/rfc9421 — independently verifiable without installing any package.
13. Reproduction commands
Every datum in this page is reproducible from public APIs. Replace$TOKEN with a personal GitHub token.
14. Limitations
- No per-package runtime telemetry exists. The AlgoVoi packages do not phone home.
- IETF Datatracker per-document download counts are not exposed via the public API. Aggregate datatracker traffic is private.
- GitHub Code Search has rate limits and indexes only public repositories. Private GitHub Enterprise installations, GitLab, Bitbucket, and internal version-control systems are not surveyed.
- Download counts include some baseline scraper, mirror, and security-scanner traffic. A 35 percent discount is applied to estimate real adopter activity; the true ratio is unknown.
- Adopters who use the substrate in closed-source code are structurally invisible to all the above measurements.
- Refresh frequency: this page should be re-generated quarterly using the commands in Section 13 to keep currency.