The Problem This Standard Solves
The x402 whitepaper (Coinbase Developer Platform, May 2025) solved a real problem: legacy payment rails were designed for humans, not machines. API keys, subscriptions, manual billing — none of it works for autonomous agents that need to transact at machine speed. x402 implemented the long-reserved HTTP 402 status code, enabling any server to charge any caller in stablecoin with 200ms settlement and near-zero fees. That is a genuine contribution.
It also created a new attack surface. Simultaneously, three protocols are assembling a machine-native payment economy with no constitutional layer: x402 (HTTP 402, pay-per-call), MCP (Model Context Protocol — agents accessing tools and data), and AP2 + TAP (Google and Visa's agent identity and payment standards via Stripe and Coinbase). These protocols enable autonomous agents to initiate, authorize, and execute financial transactions faster than any human compliance review can operate — with no identity verification, no authorization chain, no asset classification, and no jurisdictional anchor.
This is not hypothetical. The Conduent breach of September 2025 exposed 25 million government and healthcare records through a single unguarded pipe. Not through the agency. Through the connection. 80% of 2025 ransomware attacks now leverage AI tools. The attack surface is widening every quarter and the controls have not changed.
AP2 + TAP gives agents an identity owned by the platform, not the person.
MCP gives agents access to tools and data with no credential verification.
M5x402 turns agents into licensed economic citizens of specific sovereigns — every agent credentialed, every payment TCID-signed, every action auditable back to the accountable human.
M5 is a fresh start for the world. The USC standard is designed with Nash Equilibrium mathematics — the incentive structure rewards participation and makes sovereignty valuable, rather than punishing deviation with exclusion. No nation is permanently locked out. Every sovereign has the same path. The gate is identical for everyone: five human rights commitments derived from the Cyrus Cylinder (539 BCE), the world's first known charter of human rights.
Nations currently under sanctions, in conflict zones where banking infrastructure has collapsed, in the Global South structurally excluded from developed-market financial access — all have the same path to Internet 3.0 as the largest economies on earth. The Cyrus Protocol asks less of any sovereign than the existing correspondent banking system demands, while asking more in terms of human dignity. That is the design. Internet 3.0 is not the world map. It is the world map of sovereigns that choose to commit to their own people. M5Canon enforces ratification at Layer 0 before any chain activates — not to exclude, but to ensure that every chain that activates is one that has made that commitment.
+ M5-AAIF (Linux Foundation)
Wyoming DUNA
CEDECO.eth — Certificate of Issuance for M4 Securities (financial instruments). Requires DTTC membership (U.S.) or equivalent clearing participant (Euroclear · JASDEC · CCASS · CREST globally).
CFTC Commodity Credentials — CPO (Commodity Pool Operator): operates pooled M2 commodity token investment vehicles trading futures and forex. CTA (Commodity Trading Advisor): advises on M2 commodity token positions within the MINERA, VIRDIS, TERRAVERTE, and other M5 index channels.
BRIDGE (Blockchain Registry Interbank Digital Asset Gateway Exchange) — 11,000+ SWIFT BIC codes and participant codes mapped to sovereign ENS BOI accounts. Legacy financial institutions bring their existing SWIFT identity; BRIDGE maps it to their M5 sovereign routing identifier and M4/M5 member account. No existing institution abandons its legacy infrastructure to participate.
Adjudication pools (NYCP©, state pools, unitednationschain.eth) are the constitutional enforcement mechanism. Pamela Norton retains founding authority as CEA. Governance is decentralized. No single entity controls the standard.
Sovereign Banking Service Licence
Enterprise Licensee
The M5 Asset Classification Standard (M1–M5)
Every device a M5HUM account holder owns — mobile phone, tablet, laptop, smart glasses, watch, eSIM, IoT sensors, and any agent connected to them — is registered, titled, and controlled as a sovereign M3 asset under the M5HUM credential. The human holds the title. The human holds the keys. No platform, no government entity, and no agent can access, revoke, or transfer device control without explicit human authorization via the M5Mandate — and no M5Gov entity can compel access without serving due process through the adjudication pool system, following the laws of the jurisdiction embedded in the device's USC code at the moment of registration.
M5Canon determines asset classification from the asset definition — you do not choose it. Attempting to misclassify an asset to access lower-friction rails is detectable at Layer 0 and constitutes a compliance failure logged to the tamper-evident event chain. The rails listed below are representative examples of the verified settlement infrastructure available to each class — not an exhaustive market listing. Rail access requires a verified M5Bank account. The M5Wallet is the credential gate to all markets.
| Class | Name | What It Is | Examples | Cred Min | Rail Examples (not exhaustive) |
|---|---|---|---|---|---|
| M1 | Utility | Cash-equivalent platform credits and payment tokens. Broadest rail set — any verified M5Bank account, any compatible chain | TCUSD credits, compute tokens, API access, gig labor, time-denominated services, private stablecoins, MTL-licensed transfers | L1 | Cosmos/IBC · Base L2 · Bitcoin/Lightning · EVM chains · Solana · XRP · OpenFX · BorderLess · Circle/USDC · MTL rails · Formance Numscript · Dfns multi-chain |
| M2 | Commodity | Sensor-verified measurable production output. Lives on M5Bank member books. M5 Global Index private pools as primary liquidity venue | RECs, gold-backed certificate tokens, carbon offsets, minerals, agricultural, biodiversity credits | L2 | M5 Index pools · BTC Ordinals/Taproot · Cosmos IBC · EVM chains · Solana · Cardano · Ondo Finance · Chainlink oracles · Storj/Arweave |
| M3 | Titled Asset | Cryptographic proof-of-title. TitleChain is the legal chain-of-custody registry for every M3 asset regardless of which chain holds it. The chain provides issuance, transfer, and settlement infrastructure. TitleChain provides the immutable chain of title. M5Wallet is the access gate to all M3 markets. | Sovereign identity tokens, real estate, classic cars, luxury goods, tickets, mileage, IP rights, device titles, genomic SNP tokens | L3 | M5 Index pools · Solana · Polygon · Aptos · Avalanche (AVAX) · Cardano (ADA) · Sui · Hedera · Stellar · Base/EVM · Cosmos IBC · BTC Ordinals · Arweave/Storj · Chainlink |
| M4 | Security | Investment-grade instruments backed by M2/M3 assets. CEDECO.eth Certificate of Issuance required before any market access. Traded on regulated institutional venues — not public DEXes. BOI account + SwiftBRIDGE mapping required. | PCM Gold Bond, Kisosen REC offering, equity tokens, notes, certificates, SAFEs | L4 + BOI | Canton/DAML · EVM chains · Bullish · Liquid Mercury · Hiive · Zoniqx · Rialto Markets · tZERO · INX · Kraken SPDI · XRP · USDC/USDT |
| M5 | Sovereign/Gov | Intergovernmental settlement layer for Cyrus Protocol-ratified sovereigns only. CBDCs move between sovereign chains — nation-to-nation, state-to-state, intergovernmental. Never retail. Never M5x402-accessible. Never issued to individuals or businesses. CBDC firewall blocks all access at Layer 0. | CYRUS Protocol ratification records · TCID system · M5Gov BOG accounts · intergovernmental treaty instruments · sovereign CBDC issuance · Cyrus Cylinder (539 BCE) — constitutional basis | BOG only | Intergovernmental only · Canton CBDC-grade · Federal Reserve |
1.1 TCUSD — Platform Credits, Not a Retail Stablecoin
TCUSD is the credit unit that members hold in their M5Bank account to operate on the platform. It is M1 class. It is not a retail stablecoin, not listed on exchanges, and not a consumer payment instrument. It is the unit of account the M5Canon engine uses to record activity on the internal ledger — the way a bank's general ledger uses a base currency before external settlement occurs.
When an entity pays for registration, credentials, API access, or any platform service, the payment is made in an approved sovereign stablecoin or the entity's own private stablecoin — then recorded as TCUSD credits on the internal ledger. The TCUSD balance is what M5Canon reads when processing any platform action.
Every TCUSD credit carries a USC (Universal Sovereign Code) — the jurisdictional identifier that anchors the credit to the sovereign chain of the issuing entity. USC is not a token. It is a classification and routing code embedded in every TCID and transaction record:
SWIFT BIC — routing tables via SwiftBRIDGE mapping
FASB ASC 718/740/810 — equity, tax, consolidation jurisdiction
IFRS 9/15/16 — international financial instrument standards
SEC / FinCEN — regulatory reporting schemas
UCC Article 12 CER — 2022 UCC Amendments · 33 U.S. jurisdictions enacted · NY effective June 3, 2026
GENIUS Act (S.1582) — signed July 18, 2025 · Senate 68–30 · House 308–122 · federal stablecoin framework
EIA-923 / EIA-860 — generation and fuel data reporting
NERC CIP — Critical Infrastructure Protection, grid security
IEEE 2030 — smart grid interoperability standard
REC Tracking — WREGIS, GATS, M-RETS, NC-RETS
ISO 50001 — energy management systems standard
GHG Protocol — Scope 1/2/3 greenhouse gas accounting
FASB ASC 818 — Collaborative Arrangements · governs joint ventures, cooperative energy partnerships, and multi-party REC/carbon production arrangements on M5 (Kisosen, tribal energy JVs, West Edge Energy, ONE.BALI and equivalent cooperative structures)
NAICS 22 — utilities sector codes · UN SDG 7
HL7 FHIR R4/R5 — health data interoperability. USC maps to FHIR Organization.identifier
ICD-10 / ICD-11 — WHO diagnosis codes in M3 health asset records
CPT / HCPCS — AMA procedure billing codes for health service tokens
LOINC — lab and clinical observation identifiers for SNP/genomic tokens
SNOMED CT — clinical terminology for diagnosis and procedure M3 assets
NPI / NDC — CMS provider registry · FDA drug identification
CMS-1500 / UB-04 — claim form standards for health payment rails
SE4 — Self-Determination standard for sovereign consent gates
VCF / FASTQ / BAM — genomic file format standards for 23andmine vault records
Layer 2 Notarized Sovereign Consent (SE4 self-determination)
Layer 3 Digital Twinning Guard — prevents derivative reconstruction of original sequence. Member controls every gate. Revocable at any time.
23andmine.eth BOU cooperative — opt-in personalized medicine research on member's terms. Member earns SNP tokens for each contribution. Retains revocation rights.
M4 securities corridor: full CEDECO.eth issuance authority under New York law. m5GSIX institutional settlement via Rialto Markets, tZERO, INX — all New York-regulated or SEC-registered. nycp26.eth arbitration pool (NYC Protocol 2026) — New York courts of competent jurisdiction as enforcement backstop.
NYC wallet split: community treasury, nycp26.eth adjudication pool, city chain operating fee, borough-level sub-pools available for member-voted distribution. NYC Protocol 2026 (nycp26.eth) is the adjudication authority — the updated successor to the 1958 New York Convention enforced in 172 countries. Federal Hall is the genesis anchor. The date is IV · VII · MMXXVI.
UCC Art.12 CER
SWIFT NYCB
FASB ASC 740
FASB ASC 740
FASB ASC 810
BIA Tribal codes
SWIFT TREAS33
SWIFT BNBTBTBT
Multi-jurisdiction
(approved sovereign stablecoin
or private M1 stablecoin) → M5Capital Holdings
Platform operator
secures the network → wallet split →
Every split is on-chain and verifiable. Fees are local-first — majority stays in the sovereign jurisdiction where value was created. ICSN/federal-layer fees fund resilience infrastructure. This is the constitutional answer to extractive platform economics.
1.2 Private Stablecoins and Sovereign Approved Stablecoins
NOT YET ENACTED (as of April 2026)
Alaska · Arkansas · Connecticut · Idaho · Kansas · Maryland · Michigan · Mississippi · Missouri · Montana · New Jersey · North Carolina · Ohio · Oregon · South Carolina · Texas · Utah · Vermont · Wisconsin · Wyoming
These states still treat digital assets as general intangibles under Article 9 — perfection by filing only, no control-based priority, no take-free rule for qualifying purchasers. Entities operating in these states should specify an enacted-state jurisdiction in their CER records where possible. Check ULC tracker at uniformlaws.org for current status as legislatures continue to act.
⚠ NOTE ON WYOMING — M5 HOME JURISDICTION
Wyoming has led the nation in digital asset legislation across many fronts — SPDI charter, DAO LLC law, digital asset property exemptions, and the Wyoming Utility Token Act. However, Wyoming has not yet enacted UCC Article 12 CER. This means Wyoming citizens and entities do not currently have the legal protections that 33 other jurisdictions now provide — including control-based perfection of digital assets, the take-free rule for qualifying purchasers, and the clear chain-of-title framework for CERs. Wyoming-registered M5 entities should specify an enacted-state jurisdiction (such as Delaware, California, or New York after June 3, 2026) in their TCID and CER records as the governing CER jurisdiction until Wyoming acts. M5 is part of the advocacy infrastructure pushing Wyoming to close this gap — the state that chartered the SPDI and the DAO LLC should be the first to complete UCC Article 12 enactment, not among the last.
Every M5Bank member can issue their own private M1 stablecoin on any chain, denominated in their jurisdiction's approved currency, representing the value of their products or services. Entities that prefer not to issue their own stablecoin default to the approved sovereign stablecoin list for their chain — Wyoming's approved list, California's, the Navajo Nation's — determined by the sovereign chain under the GENIUS Act (Guiding and Establishing National Innovation for U.S. Stablecoins Act, S. 1582, 119th Congress, signed into law July 18, 2025 by President Trump — Senate vote 68–30, House vote 308–122) and UCC Article 12 CER (enacted in 33 jurisdictions as of December 2025; New York effective June 3, 2026). The GENIUS Act establishes the first federal regulatory framework for payment stablecoins — restricting issuance to approved permitted stablecoin issuers, requiring 1:1 reserves backed by U.S. dollars or low-risk assets, and subjecting issuers to Bank Secrecy Act obligations. The USC code embedded in every M5 transaction record is the jurisdictional anchor that determines which state's approved stablecoin list applies. External stablecoins are the settlement medium. TCUSD is the internal ledger representation.
1.3 TC-MGT — Treasury Reserve Only
TC-MGT (Minera Gold-Backed Token) is the M5Bank treasury reserve instrument. It is M2 class, not M1. TC-MGT is backed by verified in-situ gold assets held by credentialed M5Bank member entities in the mining sector — spanning junior explorers and development-stage operations such as Portuguese Creek Mine through to major producers and institutionally recognized counterparties such as Newmont, Agnico Eagle, and Barrick Gold, with settlement and assay standards governed by the London Bullion Market Association (LBMA). The LBMA Good Delivery standard is the benchmark: every gold asset backing TC-MGT must be traceable through a credentialed M5Bank BOB or BOI account in the MINERA sovereign index, sensor-oracle verified, and auditable to chain of custody on TitleChain.
TC-MGT is never used for platform services, API fees, credential purchases, or any operational transaction. The M5Canon engine enforces this as a hardcoded dual-token policy — any attempt to route TC-MGT through platform service rails is blocked at classification and logged to the tamper-evident event chain. TC-MGT is a treasury reserve instrument. TCUSD is the platform credit unit. They are architecturally distinct and M5Canon enforces that distinction at Layer 0 with no override.
1.4 BPS Fee Schedule — BP1 Through BP15
| Code | Event | BPS | Scope | ZK | Rail |
|---|---|---|---|---|---|
| BP1 | Tokenization | 50 | Customer | — | Base L2 |
| BP2 | BTC Notarization | 5 | Customer | REQUIRED | Bitcoin Taproot |
| BP3 | Title Transfer | 15 | Customer | REQUIRED | TitleChain |
| BP4 | Trade Execution | 25 | Customer | optional | Exchange tier |
| BP5 | Retirement | 10 | Customer | REQUIRED | TitleChain |
| BP6 | Cold Custody | 2/mo | Customer | — | M5LightLocker |
| BP7 | Registry Node Update | 0.5 | Customer | optional | Base L2 |
| BP8 | Hot Wallet Transfer | 1 | Customer | — | Base L2 |
| BP9 | Compliance Screening | 2 | Full | REQUIRED | CEDECO oracle |
| BP10 | Dispute Resolution | 3 | Full | — | Adjudication pool |
| BP11 | Cross-Chain Bridge | 3 | Full | REQUIRED | ICSN IBC |
| BP12 | Governance Vote | 0.5 | Full | — | ICSN Global |
| BP13 | TitleChain Registry | 1 | Complete | — | TitleChain |
| BP14 | NYCP Arbitration | 2 | Complete | — | NYCP© |
| BP15 | Index Update | 3 | Complete | — | GGP oracle |
Customer scope BP1–BP8: 114 BPS | Full scope BP1–BP12: 122 BPS | Complete scope BP1–BP15: 128 BPS
M5Bank Account Framework, ENS Identity & WSW Addressing
Every entity on the M5 platform has an account type that determines what asset classes they can handle, what actions they can initiate, and what their public registry ENS identity looks like. Account type is determined by the entity's legal form and registration — confirmed by their sovereign chain's Secretary of State or equivalent governing body.
2.1 The Five Account Types
| Type | Full Name | Who | Asset Access | Key Distinction |
|---|---|---|---|---|
| BOM | Bank of Me | Individual sovereign person. The complete financial life of a human being in one sovereign private cloud — their own M5POD container. | M1 (base access) · M2/M3 assets they hold as investor · M4 as qualifying purchaser via BOI counterparty | A person can hold BOG-level credentials within their BOM account. The account remains BOM. The credential is the authority. The account type is the legal entity form. See BOM Architecture below. |
|
BANK OF ME (BOM) — THE SOVEREIGN HUMAN OPERATING SYSTEM
M5SCORE — YOU ARE YOUR SCORE. NOT A THIRD PARTY'S ASSESSMENT OF YOU.
The M5Score is not a credit score. It is not FICO. It is not a risk model built from data you never consented to share with people who never asked your permission. It is the sovereign reputation of a sovereign human — built from what you actually do, what you contribute, what you create, what you learn, what you build — over time, under your verified identity, anchored to your TCID. The longer your wallet has been active and uncompromised, the more transactions you have fulfilled, the more you have contributed to your community and creative economy, the higher your score. Not because of how much money moved — because of the quality and consistency of your sovereign economic life.
LONGEVITY
Time your wallet has been active, verified, and uncompromised under your control. Time is trust.
INTEGRITY
Pattern of economic activity — consistency, reciprocity, fulfillment. 500 small contracts completed matters more than large amounts moved.
CONTRIBUTION
Verified contributions to cooperative pools, environmental stewardship, governance participation, community infrastructure. These are titled M2/M3 assets — scored and owned.
SOPHIA SCORE
Every credential earned, course completed, skill certified, IP registered. The more you learn and create, the higher your SOPHIA component. Your knowledge compounds over time and cannot be taken.
AGENT QUALITY
The agents you have trained, credentialed, and deployed. When they perform well under your mandate, your score reflects their quality — they are extensions of your sovereign OS.
HOW REWARDS FLOW — NOT ADVERTISING, ENGAGEMENT
Companies that want to access the talent, knowledge, creative output, and community influence of high-M5Score holders do not buy advertising to reach them. They cannot. There is no advertising layer in the sovereign OS. Instead, they request access through the sovereign OS — presenting opportunities, compensation offers, and collaboration invitations that the human can accept, reject, or negotiate through their Vaulta. The human's agents evaluate offers against their mandate without the human needing to review every one. The company is not buying attention. They are requesting access to a sovereign human's capabilities on that human's terms. Rewards flow from engagement value, not eyeball value. From knowledge, not surveillance. From contribution, not consumption.
WHEN YOU GET HIRED — YOUR AGENTS COME WITH YOU
When a high-SOPHIA-score M5HUM holder is hired by any company, their credentialed agents come with them as verified extensions of their sovereign OS. The employer can verify every agent's credential, training history, and capability on M5Scan.io. The agents work for the human — not the company. The human can take them to the next engagement. The more you train your agents, the more they learn under your credential, the more valuable they become as part of your sovereign economic identity. Your SOPHIA score, your agent portfolio, your contribution history — these travel with you across every job, every gig, every enterprise you build or join. They are yours. They compound. They cannot be deleted by a platform or revoked by an employer.
FIVE LAYERS INSIDE EVERY SOVEREIGN ACCOUNT
LAYER 1 — SOVEREIGN IDENTITY
TCID · M5HUM credential · Sovereign soul ENS address · W3C DID/VC · Biometric binding (ZK-committed, never stored in plaintext) · Phone sovereignty (Telnyx FIND→ATTEST→CONTROL→TOKENIZE) · Device registry (all owned devices as M3 titled assets) · Social accounts and email accounts as sovereign identity records · 23andmine genomic vault · MyDNA health records
LAYER 2 — PERSONAL BUSINESS LEDGER
The BOM holder's own private portfolio and business ledger — their complete financial picture in one place:
· Traditional finance: bank accounts, brokerage, 401k/IRA, credit cards (read-only secure bridge) · Digital assets: M1 TCUSD credits, M2 commodity tokens, M3 titled assets, M4 securities held as investor · Stocks and equities: traditional holdings bridged via SwiftBRIDGE-equivalent consumer connection · Invoices issued and paid: gig work, contract work, sole proprietor income — every invoice a titled record · Income streams: salary, gig payments, BOU cooperative distributions, SNP token licensing income, REC token distributions · Tax records: automated FASB/IFRS journal entries on every transaction LAYER 3 — BANK OF US MEMBERSHIPS
Every BOU account the BOM holder is a member of, visible inside their M5POD:
· Credit unions they belong to · Trade unions and labor organizations · Cooperative pools: 23andmine.eth, energy cooperatives, producer cooperatives, agricultural cooperatives · DAOs and ICSN working groups they participate in · Each BOU shows: share/stake, governance rights, voting history, distribution history, and the BOM holder's current standing LAYER 4 — BUSINESS CREDENTIALS & WORK ACCESS
Credentials the person holds giving access to BOB/BOI/BOG systems:
· Employment: employer's BOB/BOI account connection, payroll integration, benefits records · Gig work: verified contractor relationships across platforms, rated work history, payment records · Professional certifications: SOPHIA developer credentials, industry licenses, academic degrees from BOI educational institutions · Government credentials loaded into BOM: the BOG-level credential a governor or official carries inside their personal BOM account — the credential is the authority, not the account type LAYER 5 — CUSTODIANS, DIGNITY AGENTS & GUARDIANS
Trusted agents the person selects at any point in their life:
· Custodians — hold keys on behalf of the BOM holder: estate planning, incapacitation, minor accounts managed by parent custodians. Time-locked. Consent-gated. Revocable at any time while the person has capacity. · Dignity Agents — AI agents the person names to act with dignity in specific circumstances: health directives, end-of-life instructions, mental health support protocols, crisis intervention preferences. They surface the person's wishes to the right humans at the right moment — they do not act unilaterally. · Guardians — trusted humans named by the person (family members, attorneys, medical proxies) who can act through the M5 adjudication pool system if the person is unable to. No guardian can take unilateral control — guardian activation requires adjudication pool approval under the laws of the person's registered jurisdiction. THE PRIVATE CLOUD — M5POD ENCRYPTION STACK
· M5POD — SOLID Protocol sovereign data container. The person's own cloud. No platform sees inside.
· AES-256-GCM — all data encrypted at rest · Signal Protocol — E2EE for all pod communications · FHE via M5LightLocker — computation on sensitive data without decryption · ZK proofs — prove qualification without revealing underlying data · Five protecting agents — SOPHIA, LENORE, MILNER, ROWBOAT, 23andMine each guard specific domains · No agent supersedes the human — M5HUM is the constitutional authority VAULTA — PERSONAL SOVEREIGN DATA ROOM
Every BOM account includes a Vaulta — a private sovereign data room within the M5POD: identity attestations (TCID, phone/SIM, biometric binding, CER records) · personal documents (IDs, passports, certificates, deeds, titles) · assets ledger: tangible (real estate, vehicles, art) and intangible (IP, credentials, tokens) · Ricardian contract repository (identity attestation, CER control forms, jurisdiction-specific templates from M5Canon) · full provenance chain — every document and asset carries a TCID and provenance hash chain anchored on TitleChain.
ODEA — WORKFLOW INTELLIGENCE AGENT
Odea is the workflow intelligence agent embedded in every M5POD. It knows which forms, attestations, Ricardian contract templates, and regulatory filings apply to each entity type and jurisdiction, and surfaces the right workflow at the right moment — eliminating formation and migration complexity. Serves five roles: SELF/Guardian (personal documents, CER control, health) · Co-op/BOU (governance docs, cooperative voting) · FSP/BOI (regulatory filings, compliance, custody) · Commissioner/BOG (oversight, audit access) · Investor (NDA-gated Private Data Room). Odea is also the workflow engine for Track A (legacy entity migration) and Track B (native sovereign formation).
PRIVATE DATA ROOM — BOB / BOI ENTITY LEVEL
For entities requiring investment review, every BOB and BOI account can activate a Private Data Room — NDA-gated, credential-enforced via SOPHIA + M5Canon: cap table (equity ledger, shareholder registry, SAFEs/T-SAFEs) · debt instruments (loans, credit facilities, convertible notes) · securities (stocks, bonds, future token allocations) · subscriber ledger · financial statements (P&L, balance sheet, cash flow) · legal documents (operating agreements, bylaws, board resolutions). M5Capital's own Private Data Room is the reference implementation.
|
||||
| BOU | Bank of Us | Cooperative, Trust, Wyoming DUNA, DAO | M1 + M2 | Wyoming DUNA (Decentralized Unincorporated Nonprofit Association) structures, 1,000-year trusts, cooperative entities. ICSN Global converts to a Wyoming DUNA upon the first 100 M5Bank members joining the working group cooperative. TitleChain Foundation is a Wyoming Sovereign Purpose Trust. Both are BOU. Governed by cooperative rules — member-voted, on-chain governance. |
| BOB | Bank of Business | LLC, Corp, holding company, tribal enterprise | M1 + M2 + M3 | Standard business entity. Tribal enterprises (the business arm of a tribe, distinct from the tribal government itself) are BOB. Cannot initiate M4 issuance. |
| BOI | Bank of Institution | Licensed institution — Special Purpose Depository Institution (SPDI), bank, university, research body, regulated entity | M1 through M4 |
Institutions operating under regulatory authority. Two pathways to BOI standing: Pathway A — Legacy Institution: Holds an active SWIFT BIC code (global correspondent banking participant). SwiftBRIDGE maps the SWIFT BIC to their sovereign ENS address, establishing identity, jurisdiction, and standing. The SWIFT code is their proof of institutional recognition. Pathway B — New Financial Services Entity: No SWIFT history. Applies for M5Bank BOI licence through the SOPHIA certification pathway — demonstrating regulatory and capitalization requirements for BOI standing. Receives a sovereign BRIDGE code as their routing identifier (the M5 equivalent of a SWIFT BIC). To initiate M4 issuance: BOI account + SwiftBRIDGE or BRIDGE code + DTTC membership (U.S.) or equivalent recognized clearing participant credential in their jurisdiction (Euroclear / JASDEC / CCASS / CREST / equivalent). |
| BOG | Bank of Government | Government agency legal entity only | M5-class access | The legal entity embodiment of a government agency: DoD, HHS, FDA, state health departments, tribal government bodies. Only agencies hold BOG entity status — a person holding government credentials remains a BOM account holder with BOG credentials loaded. |
2.2 The ENS Naming Convention — Account Type Encoded in Public Address
Account type is encoded directly in the public registry ENS address, making every entity's legal form and jurisdiction publicly verifiable on M5Scan.io without any off-chain lookup. Every M5Bank account also receives a World Sovereign Web™ address in the format m5s://[tcid].[chain].wsw/m5pod/[path] — the sovereign application-layer address that routes on the WSW protocol (m5s://) rather than HTTPS. The ENS address is the registry identity. The WSW address is the live network presence.
2.3 ENSv2 Native Registry — m5wallet.eth + m5standard.eth
M5 launches on ENSv2 as a native hierarchical registration system. ENSv2 is explicitly designed for hierarchical registries where each name defines its own registry and resolver behavior — exactly the architecture M5 requires for policy-controlled identity issuance across jurisdictions. The M5 registry roots are:
us.m5wallet.eth
business.m5wallet.eth
institution.m5wallet.eth
government.m5wallet.eth
credential.m5standard.eth
audit.m5standard.eth
hardware.m5standard.eth
schema.m5standard.eth
pamela@bankof.me while the canonical routed identity under the hood is pamela.wy.me.m5wallet.eth. Both point to the same TCID, vault, and policy engine.bankof.business → *.business.m5wallet.eth bankof.finance → *.institution.m5wallet.eth
bankof.government → *.government.m5wallet.eth
2.4 Federal, State, and Tribal Jurisdiction Rules
unitedstateschain.eth is the federated sovereign chain of the American people — citizens, businesses, state governments, tribal nations, territories, universities, and M5Bank account holders. Bottom-up. The union of sovereign states.unitedstatesfederalgovernment.eth (aliases: unitedstatesfederalgov.eth · unitedstatesgovernment.eth) is the federal government's sovereign identity chain — federal agencies, departments, military branches, regulatory bodies (SEC, CFTC, FinCEN, DoD, GSA). This separation is not a naming convention. It is a constitutional enforcement rooted in the CYRUS Protocol, which establishes that government authority and civilian life are constitutionally separate spheres. M5 enforces this at the infrastructure layer.Federal agencies sit under unitedstatesgovernment.eth — not under any state chain. DoD, DoE, HHS, FDA, USAF are all [dept].bog.unitedstatesgovernment.eth.
State agencies sit under their state chain: [dept].bog.[statechain].unitedstateschain.eth. The Wyoming Board of Medicine is wybom.bog.wyomingchain.unitedstateschain.eth.
Tribal sovereign chains are themselves BOG — sovereign governments. Tribal government body entities under them are [entity].bog.[tribename]chain.eth. The tribal enterprises (business arms) are [entity].bob.[tribename]chain.eth.
Michigan exception: Michigan is registered as michiganstatechain.eth (not michiganchain.eth) to avoid namespace conflict. All agencies and entities in Michigan follow the pattern: agency.michiganstatechain.unitedstateschain.eth. This is the only state exception in the 50-state + 6-territory registry.
Public registry addresses are fixed and assigned by the sovereign chain based on the entity's legal registration. Entities can create additional custom ENS addresses for commerce, branding, or products — but the public registry identity is canonical, state-determined, and verifiable at M5Scan.io.
ICANN to ICSN: Migrating Existing Identity to Internet 3.0
Every entity arrives at Internet 3.0 by one of two paths:
Every entity that has built brand equity on a legacy domain (.com, .gov, .org, .edu, .net) migrates that identity to its sovereign ENS equivalent. This is not abandonment — it is migration forward. Brand equity, SEO, customer relationships, all carry through. Domain ownership verification is Step 1 of developer onboarding — it establishes jurisdiction before any account type, credential, or API access is granted.
3.1 Domain Type Migration Reference
| Legacy Domain | Entity Type | Target ENS Pattern | Account Type |
|---|---|---|---|
.gov state agency | State government agency | [agency].bog.[statechain].unitedstateschain.eth | BOG |
.gov federal agency | Federal government agency | [dept].bog.unitedstatesgovernment.eth | BOG |
.com business | LLC, Corp, holding company | [entity].bob.[jurisdictionchain].eth | BOB |
.com bank/institution | Licensed financial institution | [entity].boi.[jurisdictionchain].eth | BOI |
.org cooperative/DAO | Nonprofit cooperative, DUNA | [entity].bou.[jurisdictionchain].eth | BOU |
.edu | University, research institution | [institution].boi.[statechain].eth | BOI |
| International TLD | Any international entity | [entity].[accounttype].[countrychain].eth | By legal form |
acmegold.com is your domain, you have priority on acmegold.bob.californiachain.eth. Once registered on TitleChain, the mapping cannot be reassigned. Register before July 4, 2026 to secure your sovereign namespace.From Underlying Asset to Certified Offering: The M4 Issuance Pipeline
CEDECO.eth IS NOT: An identity verification engine. Identity is handled at the account and credential layer — M5Scan.io, SFI L1–L5, W3C DID/VC. When developers see CEDECO in a transaction context, understand it as an issuance certification instrument, not an identity oracle.
DTTC Membership (U.S.): In the United States, CEDECO.eth issues Certificates of Issuance to DTTC member entities — recognized participants in the Depository Trust & Clearing Corporation system. DTTC membership is the U.S. institutional credential that qualifies a BOI entity to receive CEDECO.eth certification for M4 offerings.
Global Market Extension: Outside the U.S., CEDECO.eth extends the same certification structure to recognized clearing participants in each jurisdiction — Euroclear members (Europe) · JASDEC members (Japan) · CCASS members (Hong Kong) · CREST members (U.K.) · and equivalent recognized clearing bodies in other Cyrus Protocol-ratified sovereign markets. The membership credential in the local clearing system is the jurisdictional equivalent of DTTC membership. As new sovereign chains activate under Internet 3.0, their recognized clearing participant structures are mapped through ICSN Global and recognized by CEDECO.eth.
4.1 The Three-Layer Asset Journey
4.2 Nine-Step Issuance Pipeline — PCM Reference Implementation
portuguesecreekmine.boi.idahochain.unitedstateschain.eth registered on ICSN Internet 3.0. Certificate of Origination issued and Bitcoin-notarized via m5BtcNotaryProof.TitleChain records every step of this pipeline immutably. ICSN Global is the DAO governance layer — human-led working groups, adjudication pools (NYCP© federal pool, unitednationschain.eth international pool), and standards ratification. TitleChain records facts. ICSN Global governs standards. Developers interact with TitleChain through the m5-ledger-server MCP and the TitleChain COO API.
M5-x402 Endpoint Security: Three Constitutional Gates Before Execution
Every M5x402 transaction passes three constitutional gates before execution. These are not middleware suggestions — they are enforced by the M5Canon engine at Layer 0. A transaction that fails any gate is blocked, logged to the tamper-evident event chain, and a M5Watcher alert is issued. There is no retry without remediation. All M5-x402 transactions on the World Sovereign Web operate through the OPI™ (Open Protocol Interface) — three sequential layers governing identity exchange (OPI-1), data sovereignty (OPI-2), and economic settlement (OPI-3). M5-x402 is the settlement protocol for OPI-3.
TCID-CLASS-DOMAIN-HASH16 — is verified against the active sovereign chain before the endpoint responds. SFI credential level (L1–L5) determines which asset classes the caller can transact. Requests without a valid TCID receive a structured 403 response — not a 402. The payment is not the problem. The identity is.5.1 ZK_REQUIRED Events — Seven That Cannot Be Skipped
If proof generation fails for any ZK_REQUIRED event, a RuntimeError is raised — the transaction is blocked, not skipped. This is enforced in the M5Canon engine and the five Keelung Haskell circuits (871 lines, 310 passing tests, Groth16/BN128).
ZK — Keelung Circuits: Events proven valid without content disclosure. Groth16/BN128, 310 passing tests.
QCaaS Silicon Roadmap: BTQ QCIM FPGA → ASIC → QPerfect QLU. Proof generation hardware migrates to quantum-native silicon as it matures. Classical-resistant today. Quantum-native by design.
5.2 Endpoint Configuration — Node.js, Python, Rust
// npm install @m5bank/x402-middleware @m5bank/sdk import { m5PaymentRequired } from '@m5bank/x402-middleware'; import { M5Client, AssetClass } from '@m5bank/sdk'; const m5 = new M5Client({ tcid: process.env.M5_TCID, chain: 'californiachain.unitedstateschain.eth', sfiLevel: 2, // L2 = M1+M2 access }); app.get('/api/energy-data', m5PaymentRequired({ amount: '0.05', // TCUSD credits assetClass: AssetClass.M2, // REC data endpoint usc: 'USC-US-CA-0001',// California jurisdiction mandate: { maxPerDay: 500, permittedRails: ['base_l2', 'ondo'] }, zkRequired: false, // M2 data query — ZK optional }), (req, res) => { // Only executes after all 3 gates pass // req.m5.tcid, req.m5.usc, req.m5.assetClass all available res.json({ recs: getRECData(req.m5.tcid) }); } ); // Error responses: // 403 TCID_MISSING — no credential on request // 403 SFI_INSUFFICIENT — credential level too low // 403 CBDC_FIREWALL — M5-class asset blocked // 403 MANDATE_EXCEEDED — surfaced to human, not failed silently // 402 PAYMENT_REQUIRED — identity valid, payment needed // 503 ZK_PROOF_FAILED — ZK_REQUIRED event blocked
# pip install m5bank-sdk from m5bank import M5Client, AssetClass, m5_payment_required from fastapi import FastAPI, Depends import os app = FastAPI() m5 = M5Client( tcid = os.environ["M5_TCID"], chain = "californiachain.unitedstateschain.eth", sfi = 2, ) # Dependency: enforces all 3 gates before route body executes gate = m5_payment_required( amount = "0.05", # TCUSD credits asset = AssetClass.M2, usc = "USC-US-CA-0001", mandate = { "max_per_day": 500, "permitted_rails": ["base_l2", "ondo"], "human_threshold": 1000, # surface to human above this }, ) @app.get("/api/energy-data") async def energy_data(session = Depends(gate)): # session.tcid, session.usc, session.asset_class verified # ZK_REQUIRED events raise RuntimeError — blocked, not skipped return {"recs": get_rec_data(session.tcid)} # M5Canon classification endpoint — classify before deploying: # POST /api/m5-canon-validate # {"asset_definition": {...}} → {"class": "M2", "rails": [...], "bps": 114}
// Cargo.toml: m5bank-sdk = "1.0" use m5bank::{M5Client, AssetClass, M5Mandate, PaymentConfig, payment_gate}; use axum::{Router, middleware, routing}; let _m5 = M5Client::new() .tcid(std::env::var("M5_TCID")?) .chain("californiachain.unitedstateschain.eth") .sfi_level(2) .build()?; let gate = payment_gate(PaymentConfig { amount: "0.05".parse()?, asset_class: AssetClass::M2, usc: "USC-US-CA-0001", mandate: M5Mandate { max_per_day: 500, permitted_rails: vec!["base_l2", "ondo"], human_threshold: 1000, // surfaces above this — never fails silently ..Default::default() }, }); let app = Router::new() .route("/api/energy-data", routing::get(energy_handler)) .layer(middleware::from_fn(gate)); // ZK failures → Err(M5Error::ZkProofFailed) — blocked, not skipped // Mandate breach → Err(M5Error::MandateExceeded) — surfaced to human // CBDC firewall → Err(M5Error::AssetClassForbidden) — logged + alerted // All errors → structured JSON with error code + remediation hint
5.3 M5Watcher — Continuous Compliance Monitoring
M5Watcher monitors every active endpoint in real time, reading every M5Canon event across all three network layers. It surfaces compliance anomalies to human principals before any enforcement action is taken. For developers: if your endpoint generates an event pattern that triggers a M5Watcher alert, you receive a structured notification through the m5-audit-server MCP with the specific event, the compliance rule triggered, and the recommended remediation — before any enforcement action is taken. You are never blocked without notice.
Receiving Payment and Representing Real Value
6.1 Interoperable Settlement Rails — M5Wallet as the Access Gate
Critical requirement: Every M5Wallet is issued under a sovereign chain that has formally ratified the Cyrus Protocol. The wallet credential carries the USC code of a Cyrus-compliant jurisdiction. There is no M5Wallet that is not anchored to a ratified sovereign chain. A person living in a nation that has not ratified the Cyrus Protocol can still hold an M5Wallet — but it must be issued under the USC code of a jurisdiction they have legal standing in that has ratified. The wallet is the credential. The jurisdiction is the constitutional anchor. Both are required.
6.2 Representing Non-Cash Value Through M5x402
| Value Type | Token Standard | Class | Index Anchor |
|---|---|---|---|
| Time, labor, and salary | TCUSD-denominated M1 tokens. USC-anchored to issuing entity's jurisdiction. Time-bound M5Mandate authorization for recurring salary streams | M1 | VALEO |
| Environmental stewardship / RECs | M2 REC tokens, sensor-oracle verified. Double-counting eliminated at the protocol level — not policy | M2 | VIRDIS |
| Knowledge work and IP licensing | M3 IP licensing tokens issued at moment of conscious creation. Creator receives credits automatically via SOPHIA index | M3 | SOPHIA |
| Cooperative labor contribution | VALEO index tokens. Cooperative governance activity as titled economic output | M1 | VALEO |
| Biodiversity / natural capital | M2 biodiversity stewardship credits. The community performing stewardship earns the credit — not an intermediary | M2 | NATURA |
6.3 Protocol Integration Stack
m5-api-gateway-server (L1), m5-ledger-server (L2), m5-contracts-server (L3), m5-lightlocker-server (L4), m5-fedramp-auth-server (L4+BOI). Your credential is verified on every tool invocation — not just at session start.The Four Infrastructure Pillars
Identity, energy, finance, and health are the four sectors of critical infrastructure that underpin every other sector — and the four areas where ungoverned autonomous agents cause the most irreversible harm. Every SOPHIA developer credential maps to one or more pillars. These are not arbitrary categories. They are the four sectors where sovereign-credentialed edge infrastructure is most urgently needed, and where the M5 wallet creates the most immediate and measurable value for the humans it serves.
*.government.m5wallet.eth) for due process and notice · Licensed M4 professional wallets (doctor, lawyer, licensed institution) for regulated communications · Court-ordered delivery through adjudication poolWhat the 23andmine vault covers: Full genomic sequence ownership and titling under UCC Article 12 CER (2022 UCC Amendments, enacted in 33 U.S. jurisdictions) and U.S. Patents 11,720,888 and 12,518,273. SNP tokens — individual single nucleotide polymorphisms mapped to TCID ownership, making each genomic marker a titled M3 asset. Stem cell preservation records (Muse Bio Labs integration). Exome, methylation, and whole genome file custody. Sovereign Data Reclamation Notices served by the member's state BOG authority to any corporation holding their genomic data — requiring full extraction, destruction of all copies including de-identified data, elimination of all traceable breadcrumbs, and confirmed deletion. The 23andMe (TTAM) precedent is the reference implementation.
Consent gate architecture: Three layers before any access is granted — ZK proof of credentialed status (M5-Keelung m5CredentialProof circuit), Notarized Sovereign Consent (SE4 self-determination standard), and a Digital Twinning Guard that prevents any derivative data from being used to reconstruct the original sequence. The member controls every gate. Access requests from health providers, research institutions (BOI accounts), and cooperative pools all flow through this three-layer system. The member licenses their data on their terms. They receive the economic benefit — not the platform.
23andmine.eth cooperative: A BOU cooperative pool allowing M5HUM members to opt-in to personalized medicine research on their own terms — contributing genomic data under consent-gated agreements, earning M2/M3 SNP tokens for each contribution, and retaining revocation rights at any time. LOINC codes for lab observations, ICD-10/11 diagnosis codes, and SNOMED CT clinical terminology all embedded in vault records for full HIPAA and HL7 FHIR R4/R5 compatibility.
Certification: SOPHIA Developer Credentials
8.1 Developer Onboarding Flow
STEP 02 ICANN→ICSN migration — ICSN issues Certificate of Authority. ENS address registered and anchored to TitleChain.
STEP 03 M5Bank account activation — account type (BOM/BOU/BOB/BOI/BOG) determined by legal registration.
STEP 04 SOPHIA certification — complete the course module(s) for your target pillar(s) and credential level.
STEP 05 Credential issued — W3C VC loads to M5POD. LinkedIn publishes automatically. M5Scan.io verifiable immediately.
STEP 06 API access granted — M5x402 endpoints, MCP servers, and SDK unlock at your SFI credential level.
8.2 Three Developer Certification Tiers
Domain proof
BOM or BOB account
SFI Level 1–2
Curriculum maps to: Sections 1 (M1/M2), 2, 3, 5 (Gates 1–2), 6 (M1/M2 rails), 7 (Identity + Energy pillars).
L1 credential
BOB or BOI account
SFI Level 3
Curriculum maps to: Full Sections 1–6, 7 (Finance pillar), all appendices.
L2 credential
BOI account
SwiftBRIDGE mapping
SFI Level 4–5
Curriculum maps to: All sections plus extended M4 issuance practicum and sovereign chain deployment module.
8.3 LinkedIn Credential Publishing
Every SOPHIA developer credential publishes to the holder's LinkedIn profile automatically at issuance — not manually, not upon request. The credential is a W3C Verifiable Credential carrying: certification level, pillar(s) covered, issuing sovereign chain, TCID of the issuing authority, and a direct verification link on M5Scan.io. Any employer, counterparty, or institution can verify in seconds without contacting the issuer. The credential is owned by the developer, stored in their M5POD, portable across all platforms and jurisdictions, and valid until the ICSN working group ratifies a standard revision — at which point renewal is a single re-examination, not a full recertification.
The developers who built the x402 protocol built a fast, elegant payment pipe. The developers who build on M5x402 are building the constitutional layer that governs what moves through that pipe, who is accountable for it, and which sovereign jurisdiction holds it. That is a different kind of work. It requires a different kind of credential. It carries a different kind of weight.
The Preamble named the crisis: 525+ ransomware campaigns, $57B in projected annual damage, autonomous agents with a free pass across unguarded endpoints, no identity verification, no audit trail, no accountable human at the end of the chain. The standard you are now certified to build on is the constitutional answer to that crisis. Not a cybersecurity product. Not a compliance framework. A sovereign operating standard for the digital infrastructure of institutions, governments, and humans — built over eight years, patent-protected, and ready to deploy.
Build accordingly.
Apply at m5bank.app/developer
Reference Implementation and Developer Tools
| Tool | What It Does | Credential | Access |
|---|---|---|---|
| M5 Developer SDK | W3C DID, W3C VC 2.0, SOLID Protocol. Open source. Node.js, Python, Rust. Zero platform lock-in. | Open | github.com/m5bank/sdk |
| 47+ MCP Servers / 208+ Tools | Full backend access tiered by SFI level. m5-api-gateway (L1) through m5-lightlocker (L4). TCID verified on every tool call. | L1 min | m5bank.app/developer/mcp |
| M5Scan.io | Verify any TCID, credential, asset, CEDECO.eth certificate, ENS mapping, USC code, or WSW address in real time. m5scan.io publishes m5GCIX and m5GSIX real-time index feeds — cryptographically hashed at production origin, tamper-proof, publicly auditable. Publicly accessible. | Public | m5scan.io |
| M5Canon Validate | Classify any asset before deploying it. Returns class, permitted rails, credential requirements, applicable BPS fees. | L1 | POST /api/m5-canon-validate |
| M5Canon Sandbox | Test environment: pre-loaded wallets, mock M5x402 endpoints, ZK proof simulation, M5Mandate boundary testing. No real assets. | L1 | m5bank.app/developer/sandbox |
| ENS Resolver | Query ICANN→ICSN mapping status, domain ownership verification, Certificate of Authority status, ENS registration lookup. | Public | GET /api/ens-resolver |
| Odea Workflow Agent | Workflow intelligence embedded in every M5POD. Guides Track A (legacy migration) and Track B (native formation). Knows which forms, attestations, and Ricardian contract templates apply per entity type and jurisdiction. | L1 + account | m5bank.app/odea |
| ICSN Global GitBook | Canonical public record of sovereign identity for all 50 states, 6 territories, and 220+ nations. Every ENS subdomain, BRIDGE code, M5Bank Node ID, and USC Nation Code. Human-readable and machine-queryable. | Public | docs.m5bank.app |
| M5-API ENSv2 Record Schema |
Required identity records: m5.tcid · m5.class · m5.jurisdiction · m5.vault_uri · m5.notice_policy · m5.messaging_policy · m5.payment_policy · m5.issuer · m5.status · m5.provenance_hash
Signature authority (S0–S7): S0=none · S1=receipt · S2=consent · S3=personal execution · S4=delegated · S5=institutional · S6=fiduciary · S7=constitutional/title/sovereign authority Agent records: m5.primary_agent · m5.guardian_agent · m5.dignity_agent · m5.ward_agent · m5.agent_activations · m5.agent_states [available|pending|approved|accepted|active|paused|revoked|suspended] · m5.agent_skills Credential status (C0–C7): C0=unverified · C1=submitted · C2=under review · C3=verified · C4=provisional · C5=accredited · C6=privileged/regulated · C7=sovereign/constitutional authority Sophia score: m5.sophia_credential_level · m5.sophia_score · m5.sophia_confidence · m5.sophia_domains {financial-literacy, digital-sovereignty, identity-stewardship, governance-participation} Resolution flow: ENS name → TCID → Vault → Policy Engine → Agent Layer → Provenance → BTC Anchor | L1+ | docs.m5bank.app/api-schema |
| M5Node Operator Kit | Master MVNO sub-activation, dark fiber IRU preferential routing enrollment, eSIM sovereignty pipeline integration, USC Order Book MVNO capacity token + dark fiber IRU token first-look registration. Full seven-revenue-stream node operation setup. | L2 + BOB/BOI | m5bank.app/node |
| M5-AAIF (Linux Foundation) | M5-Agentic AI Foundation — M5's open-source AI agent economic framework donated to the Linux Foundation as the neutral global standard for how AI agents transact, credential, and operate across sovereign jurisdictions. Includes M5Canon Ricardian standards, USC token classification, and M5 MCP server architecture. Linus M5Agent is M5's sovereign orchestrator — named in honor of Linus Torvalds. | Open | linux.foundation/m5-aaif |
| Live Dashboard | M5Bank sovereign banking dashboard — accounts, ledger, digital assets, payments, compliance, cap table, 409A valuation. Includes MyDNA Chart (genomic files, SNP tokens, stem cell records, consent gates, 23andmine.eth cooperative pool), Health Providers, and Reclamation Notice pipeline. | L1 + account | quantum-proof-notary-app-wxnmj38y.devinapps.com |
9.1 Error Reference
// M5x402 structured error responses — handle each explicitly 402 + "TCID_MISSING" // No credential on request — return 402 with payment details 403 + "TCID_INVALID" // TCID fails sovereign chain verification 403 + "SFI_INSUFFICIENT" // Credential level too low for this asset class 403 + "CBDC_FIREWALL" // M5-class asset — blocked, logged, M5Watcher alerted 403 + "MANDATE_EXCEEDED" // Agent hit mandate boundary — surfaced to human, awaiting approval 403 + "ASSET_MISMATCH" // Asset class inconsistent with credential or settlement rail 503 + "ZK_PROOF_FAILED" // ZK_REQUIRED event — RuntimeError, blocked NOT skipped 503 + "SOS_PENDING" // OpenCorporates SOS 24-hour gate not yet cleared 503 + "WATCHER_ALERT" // M5Watcher compliance anomaly — human review required 503 + "SWIFT_BRIDGE_UNMAP" // BOI account missing SwiftBRIDGE mapping — required for M4 // All errors include: error_code, message, remediation_hint, m5scan_url
Why This Standard Exists, Right Now
Three protocols — x402, MCP, and AP2/TAP — assembled a machine-native payment economy in 2025. They did it fast, elegantly, and without a constitutional layer. They gave autonomous agents the ability to initiate, authorize, and execute financial transactions at machine speed, across any endpoint, with no identity verification, no asset classification, no jurisdictional anchor, and no audit trail back to an accountable human. This was not malicious. It was incomplete. The payment pipe was built. The constitutional layer was not.
The consequence is already visible. $57 billion in projected annual ransomware damage. 80% of attacks now leverage AI tools. The Conduent breach. 25 million government and healthcare records exposed through a single unguarded connection. The attack surface is not theoretical — it is live, it is widening, and the controls designed for the previous era of human-initiated transactions do not apply to machine-speed agent commerce.
The M5x402 standard is the constitutional answer to the open attack surface. It is also the economic answer to the infrastructure gap. And it is the human answer to a financial system that has spent decades using mathematical sophistication not to distribute opportunity but to concentrate it — not to secure identity but to monetize it — not to reward contribution but to extract it.
The Nash Equilibrium design of the USC standard means the incentive always points toward sovereign participation rather than extraction. The Cyrus Protocol gate means the infrastructure is built on human rights commitments, not geopolitical alignment. The M5Score means the sovereign human's reputation is built from what they actually do — not what a third party inferred from data they never consented to share. The M5Canon engine — licensed under the TitleChain Foundation Wyoming 1,000-Year Sovereign Purpose Trust — means the enforcement rules in any deployed version are constitutionally fixed. No licensee, no sovereign, and no working group can modify the engine unilaterally. New standards ratified by ICSN Global through member consensus are implemented in versioned engine releases, each licensed under the same sovereign purpose trust terms — making the path to change deliberate, governed, and transparent rather than unilateral or covert. What the engine enforces today it enforces permanently until a new version is deliberately and publicly released through the same constitutional process.
This is not infrastructure for the next startup cycle. It is infrastructure for the next era of human economic sovereignty. The window to build it correctly — before the defaults are set, before the attack surface is exploited at scale, before the regulatory moment closes — is open right now.
July 4, 2026. Federal Hall, New York City. The launch of Internet 3.0.
Certification opens now. The standard is ready. The infrastructure is built. The sovereigns are activating.
Account Type Decision Tree
Use this flowchart to determine the correct M5Bank account type for any entity. When in doubt, verify on M5Scan.io using the entity's SOS registration number or SWIFT BIC.
Account Type Permissions Matrix
| Capability | BOM | BOU | BOB | BOI | BOG |
|---|---|---|---|---|---|
| M1 Utility transactions | ✓ | ✓ | ✓ | ✓ | ✓ |
| TCUSD credit operations | ✓ | ✓ | ✓ | ✓ | ✓ |
| Private stablecoin issuance (M1) | — | ✓ | ✓ | ✓ | ✓ |
| M2 Commodity tokens — m5GCIX | — | ✓ | ✓ | ✓ | ✓ |
| M2 Token issuance | — | ✓ | ✓ | ✓ | ✓ |
| M3 Titled asset NFTs — m5GCIX | — | — | ✓ | ✓ | ✓ |
| M4 Security tokens — m5GSIX | — | — | — | ✓ | gov only |
| M4 Issuance — m5GSIX via CEDECO.eth | — | — | — | + DTTC + SwiftBRIDGE | — |
| M5 Sovereign instruments | — | — | — | — | ✓ |
| SwiftBRIDGE mapping | — | — | — | ✓ | ✓ |
| M5Mandate creation | ✓ | ✓ | ✓ | ✓ | ✓ |
| Agent deployment | ✓ | ✓ | ✓ | ✓ | ✓ |
| ICANN→ICSN migration | ✓ | ✓ | ✓ | ✓ | ✓ |
| BOG credentials (hold within BOM) | hold only | — | — | — | ✓ entity |
| Adjudication pool | view | view | participate | ✓ | ✓ |
| Base L2 settlement (M1) | ✓ | ✓ | ✓ | ✓ | ✓ |
| Ondo Finance settlement (M2) | — | ✓ | ✓ | ✓ | ✓ |
| Canton / XRP settlement (M3) | — | — | ✓ | ✓ | ✓ |
| Rialto Markets / tZERO / INX (M4) | — | — | — | ✓ | gov only |
| Ricardian contract deployment | — | L2+ | ✓ | ✓ | ✓ |
| M5Node validator operation | — | partial | ✓ | ✓ | ✓ |