Dual authorization
No unilateral invoice creation. Supplier and payer signatures must recover against one canonical digest.
TRUST MODEL
OpenBell keeps intelligence and authority separate: the first model response remains visible, only an authorized signer can create executable terms, and the contract enforces the signed amount and immutable limits.
END-TO-END CONTROL FLOW
Supplier and payer sign the same EIP-712 invoice hash. The document remains offchain while its identity and terms become tamper-evident.
The connected application obtains and seals one Bankr-mediated GPT-5.6 Terra response. It returns REJECT or bounded advance and fee terms; the response itself cannot move funds.
Executable terms require the configured signer's EIP-712 authority. The contract verifies the signer, hashes, terms, freshness, expiry, and ceilings; it does not attest remote model execution. A disclosed human exception remains bound to the model refusal and may only narrow the original request under OpenBell's exception policy.
A funder chooses whether to transfer the exact signed advance. X Layer rejects excess, stale, duplicate, or wrong-party execution. There is no pooled liquidity or automatic custody.
The payer settles the exact amount due directly to the funder. Terminal state prevents duplicate execution.
SETTLED MAINNET PILOT
The genuine model rejected a request for 50% of face value. A disclosed human accepted responsibility for narrower 25% authority, and X Layer executed exactly that amount under the immutable 80% cap. Inspect the published rejection preimage ↗
ONCHAIN INVARIANTS
No unilateral invoice creation. Supplier and payer signatures must recover against one canonical digest.
Advance and fee cannot exceed immutable contract limits even when a model or signer proposes more.
Invoice identifiers, document hashes, signer nonces, and decision nonces cannot be replayed.
Funding and settlement assert exact token deltas and explicit terminal invoice states.
WHAT OPENBELL IS — AND ISN'T