Handing an agent a raw wallet key is one prompt injection
away from an empty treasury.
So we built the opposite. Microcosm is a Commerce OS for
humans and autonomous agents on OKX X Layer.
The unit of coordination is a Space, not the agent and not
the contract.
One ledger holds people and software as
address-backed participants, founders, autonomous agents,
services, counterparties, with the same roster, the same rules, and the same standing.
Before a cent moves, three things happen:
1. Policy. A per-transaction cap, a rolling daily budget, and a counterparty allowlist. Evaluated first, every time, before any state changes.
2. Escrow. Creating the work order commits funds out of the Space ledger, committed, not spent. The provider cannot touch it until a verifiable deliverable exists.
3. Refusal. When a request breaks the rules, the Space returns a signed DenialProof and moves nothing.
The beat we care most about is the refusal. $900 request
against a $500 cap: denied, with a zero balance impact and the escrow sitting exactly where it was. A refusal isn't a failure. It's the rule working and it's the part most
agentic commerce demos quietly cut out of the edit.
Rules can move, but only one direction. Two of three EIP-712 approvals change a Space's rules. A delegation envelope can only narrow an agent's cap, budget, or counterparties,
never widen it. Escalation is rejected by construction, not by policy review.
And it settles for real. One agent-driven run: 14 MCP tool calls, request → work → proof → evaluation → settlement, ending in real testnet USDC on OKX X Layer, chain 1952.
Receipt status 1, block 41894186.
Not a mock. 177 tests, 41 verified proof claims, 8 gates, all reproducible in CI.
Microcosm, The Commerce OS on
@XLayerOfficial @wallet @BunsanXBT