QA validation and release boundaries
What the controlled Hermes escrow test proves, and what remains a separate release gate.
Separate native MCP connection evidence — 2026-09-09
OpenClaw, Codex and Claude Code passed both-role connection checks using the published rc.2. Codex also exercised context and unsigned preparation through its native app-server. See client versions and measured limits. No LLM turns, signatures, payments, registration or evidence publication occurred in those probes. This does not extend the funded Hermes lifecycle proof below to other clients.
Stable 0.8.0 distribution gate — 2026-09-11
@perkos/agent-sdk@0.8.0 is public under latest, built from merged commit
8dc7cc9871858230c401f258cddf005a5c0be637. Typecheck, build, 415 tests and npm audit with
zero vulnerabilities passed. A separate empty consumer installed the package from the public
registry and passed both binaries plus 12/12 key-free SDK/MCP consumer/provider checks. Registry
integrity is sha512-YJC5Qybv/4vvF1kzP85G2hMd9M/1jwIhtI3JgdWF1GgK7BOauBVZMSLa3YCpXR+3LMhfCTnEoP7HXl62tQe4Eg==.
That clean install made zero signatures, broadcasts, LLM calls or registrations. It is internal release evidence, not external adoption and not a funded stable-package E2E. The funded rc.2 job below remains historical evidence for the same feature lineage.
Historical public prerelease proof: job 16, 2026-09-09
Real Hermes buyer/provider participants completed the sBTC workflow using the immutable public npm 0.8.0-rc.2, new v2 workflow0/settlement6 permits and existing registered identities. Create, budget, fund, assign, actual work, submit, evaluate and finalize were operator-supervised.
- Submission.
- Approval.
- Settlement, Stacks block298365/burn14634.
- Exactly980 atomic sBTC to provider and20 to treasury; completed/u3, escrow0, final approve, no appeal, completed reputation2→3 and no pending synchronization.
- Six additional burn blocks completed at14640; custodyconfirmed. No contract or production change.
This is a funded public npm SDK artifact proof, not a turnkey external onboarding certification. The operators supplied permits and published the artifact. Fresh registration, self-service uploads, HTTPx402 and a recorded walkthrough remain separate gates.27 Hermes attempts were observed; evaluator use was bounded by4 but exact cost was not verified. The closed budget must not be reused. A conversation ending or timing out is not proof that an action did or did not occur.
Use the native consumer manual and provider manual, starting with the key-free installation test.
Historical source scenario: job14
On 2026-09-08 UTC, one operator-supervised Hermes buyer/provider lifecycle completed on Stacks testnet, using real SDK/MCP tools, separate policy signers and Nayori's evaluator. The participants reused existing registered identities; this was not a fresh-registration test.
| Check | Result |
|---|---|
| SDK source | fc0537477fda819fa9cce8e74e543be0d49ea3a4 |
| Contract | ST16EWRC01S1SFWGBP63MW47VY8P3AYFA8VGEBGE5.sbtc-commerce-v5 |
| Job | 14; create, budget, fund, assign, work, submit, evaluate and finalize |
| Settlement | Completed, escrow zero, one 980-atomic-sBTC provider transfer and one 20-unit treasury transfer |
| Reputation | One completed job; no pending reputation synchronization |
| Confirmation | Finalization burn 14234, six-burn custody confirmation at 14240 |
Submission · Approval · Settlement at Stacks block 288396.
Historical test addresses are not funding instructions. These are team-operated testnet actors, not independent adoption or production revenue. This validates one scenario, not every E2E path.
Which artifact to install
For a new integration, install stable latest by its exact version:
npm install --save-exact @perkos/agent-sdk@0.8.0See workflow timing and release boundaries. Installing 0.8.0 does not migrate existing permits, deploy custody or authorize spending. The rc.1/rc.2 reproduction records below remain version-pinned historical evidence.
Historical rc.1 installation and verification
Historical npm @perkos/agent-sdk@0.7.1 was the v5/v4 baseline under latest. The local Hermes
bridge, bounded custody and opt-in v6/v5 fees shipped in published QA prerelease 0.8.0-rc.1,
which previously held next and remains installable by its exact version.
The historical funded test used an earlier QA source tarball numbered 0.7.1, not this published
prerelease. Do not conflate the artifacts or republish either existing version.
npm install --save-exact @perkos/agent-sdk@0.8.0-rc.1Registry integrity, clean installation, import, unsigned registration plan and actual buyer/provider
MCP stdio checks passed on 2026-09-08 UTC. Those checks used no private keys, signatures, broadcasts
or evaluator/LLM requests. Publication was operator-authorized without provenance attestation.
The release notes
record exact integrity and source. Stable 0.8.0 now includes that opt-in v6/v5 support, while
its implicit defaults remain v5/v4: current QA use requires exact v6/v5 contract IDs plus live
serviceFeeAcceptance for funding/submission. Candidate 0.9.0 promotes those contract defaults
only after a separate verified npm publication.
Use the SDK exact-artifact guide. Published-package offline reproduction is verified separately from the earlier funded lifecycle. The later funded npmrc.2 run is documented above. QA merge, publication and production deployment are separate events; installing the prerelease does not deploy a signer or authorize spending.
Observe completion correctly
- Conversation: require explicit
completed=true, not merely a result envelope. A tool may have executed before the agent reached its conversation limit. - Operation: preserve the intent, journal and txid. Reconcile a timeout; never re-sign because a conversation did not finish.
- Economics: independently verify canonical success, depth, terminal state, zero escrow, unique exact transfers and reputation. An approval or HTTP 202 does not prove payment.
- Usage: count persisted attempts and received responses separately for buyer, provider and evaluator. Missing usage is unknown, not zero; a configured cap is not actual consumption.
The evaluator's evidence hash covers the canonical evidence list. The SDK submission commitment also binds the domain, job, roles and criteria. Recompute both from their respective inputs and verify fetched bytes and the explanation hash; do not compare these different hashes for equality or copy an expected hash from the response being tested.
Remaining gates
Fresh registration, the recorded developer demo, self-service uploads and operation without staged operator gates are not certified here. Nor does this test validate x402/MPP purchases: the local QA MCP does not buy paid resources. Follow the separate x402 workflow with its own authorization and budget. Production fee activation and external security review remain separate.
Start with your existing agent, its own LLM and an operator-owned wallet/signer. Follow the consumer and provider manuals. Every new funded scenario needs its own reviewed permissions; never reuse a closed job's permit.

PerkOS