Before an AI agent pays on Robinhood Chain: is it the real Paxos USDG, and does the money go to a registered agent? Answered live from the chain, with an x402 rail and on-chain spend limit behind it.




## What it is
Before an AI agent pays on Robinhood Chain, A-Identity answers three questions from the live chain:
is this the real Paxos USDG, is its signing domain the token's own, and does the money go to an agent
with an ERC-8004 identity. Paste a token, a wallet, an agent id (#0) or an x402 payment link at
https://a-identity.xyz/check/robinhood, call GET /api/robinhood/check?q=..., or use the MCP tool
evm_pay_check. The same check runs on Arbitrum One (native USDC) at /check/arbitrum.
The pay check is the new product, built in the buildathon window. It sits on rails we already had:
our own x402 facilitator settles USDG on Robinhood Chain from one signature (the buyer holds no ETH;
the facilitator broadcasts and pays gas), and nothing counts as settled without a receipt carrying a
matching Transfer log. Our buyer refuses to sign a 402 that asks for any token other than the real one.
An AgentSpendPolicy vault on Robinhood Chain mainnet bounds the agent key: 1 USDG a day, 0.25 per
payment. On 2026-10-01 we renewed the agent keys of both vaults (Robinhood Chain and Arbitrum One)
and moved the agent role off the owner key. Both keys are held by us: the split separates roles,
not custody. A payment above the 0.25 cap simulates to the contract's own AboveAutoApprove error
(eth_call; nothing broadcast).
## Why
On 2026-09-30, 900 ERC-20 tokens on Robinhood Chain's Blockscout had the symbol USDG or the name
Global Dollar (exact match, excluding the real one); 45 of them showed more than 10,000 holders, the
largest more than 194,000. The real USDG (0x5fc5360D0400a0Fd4f2af552ADD042D716F1d168) showed 401,824.
The biggest lookalike even answers a self-consistent EIP-712 domain ("Global Dollar", "1", 4663, itself).
Name, symbol and domain can all be copied; the address cannot. An agent that pays by name can pay in
the wrong dollar.
## Numbers (each with its source)
- 900 / 45 / 401,824: Blockscout token search, all pages, fetched 2026-09-30 16:20 UTC:
https://robinhoodchain.blockscout.com/api/v2/tokens?type=ERC-20&q=USDG and
https://robinhoodchain.blockscout.com/api/v2/tokens?type=ERC-20&q=Global%20Dollar
Open them in a browser; the API may answer scripted clients with a challenge page. A snapshot, not a
live count.
- 25 reason codes, published at https://a-identity.xyz/api/robinhood/check/codes.
- 1,480 declared backend tests, all passing at commit 54572b29.
- Both vaults' source verified on Sourcify (exact match): https://repo.sourcify.dev/4663/0x05a6aad7124c2f1c7b82b03e0bbe3867bc500073 and https://repo.sourcify.dev/42161/0xac6c5c9af62bc482ffeef882a6ac4678513be6db
- Settlements: 6 USDG settlements on Robinhood Chain (0.140 USDG) and 3 USDC settlements on Arbitrum One
(0.031 USDC), August 2026, all between our own wallets: internal test payments, not revenue.
- Agent #0: the first token the canonical ERC-8004 IdentityRegistry on Robinhood Chain minted
(2026-08-12, tx 0x602ce85ad044836b39918311a3031dcd689e4be0d23aed9ed0ac9227d46ec79e). Agent #1259 on
Arbitrum One.
## What was built in the window (from Sep 14) and what existed before
Before Sep 14: agent #0 and #1259, the x402 facilitator with USDG settlement, both vaults (2026-08-28).
In the window: the pay check engine, API, pages and MCP tool (f7f97a4d, 8870ba99); the facilitator
reading x402 v2 amount, per-chain price floors, per-network gas reporting and the buyer's refusal to
sign a lookalike (1ac21dd5); per-network gas ledger (47a57d45); registration dates read from the mint
(7ca6c63a); vault-key renewal and owner/agent split tooling (96b6f1e0, d9b1d836), applied on Robinhood
Chain (txs 0xc68bf160a15bfd54d623fac6ca416d45dfe33617e1ca1d8f399269d2b8edd769,
0x47d601090e34a7966162b0b2a34a58c27e844625163b99bfd5fbb5319b307304) and Arbitrum One (txs
0x237457f6632383aadbaac208eb696f3c8551c747ca88ebdcded3e9f303fa960a,
0x1e40db3647af1b18c98fc23b77dc3ee26550d564f6d24fc71d28ab4506d2c0fc) on 2026-10-01.
Oct 1 diff: https://github.com/getA-Identity/A-Identity/compare/1e5de58c...54572b29
Full list with every hash: https://github.com/getA-Identity/A-Identity/blob/main/docs/arbitrum-open-house.md
## Use of Arbitrum technology
Every answer reads the ArbSys precompile (0x64) arbChainID(): Robinhood Chain answers 4663, Arbitrum One
42161. Robinhood Chain is a dedicated Arbitrum chain; we deploy and settle there in its own dollar. On
Arbitrum One the check also recognizes the USDG Paxos documents there (0x004B...9bbC) as real, though our
rail on Arbitrum One settles in native USDC. We do not use Stylus.
## Known limits
- All settlements so far are internal test payments between wallets we control, made in August.
- We did not deploy the ERC-8004 registries; we hold an identity in them. Token #1 on the Robinhood Chain
registry is not ours: it points at our agent card, and the check says so.
- A registration shows who holds an id. It is not a review, and the check does not say whether a seller
will deliver.
- If the token's signing domain cannot be proven at that moment, the answer is "could not verify",
never "looks right".
- A chain read that does not come back decides nothing: the check answers "nothing was decided"
(HTTP 502) rather than guess, and the whole check answers within 15 seconds.
- On Arbitrum One our rail settles in native USDC, not USDG.
- The vault owner is a server-held key and the contract has no owner transfer. After the split, the
owner key and the agent key are both held by us.
- The public Robinhood Chain RPC is rate-limited.
## Prior art
Other x402 facilitators serve Robinhood Chain (Canopy, Naven; open-source ones such as
nirholas/robinhood-chain-x402) and Arbitrum One (Coinbase CDP, PayAI); Offchain Labs published
arbitrum-mpp. AgentProof ArbiLink scores agents before they transact; vet402 checks sellers by buying
from them. What we add: one call, before signing, that checks the token, its live-proven signing
domain, the payee's ERC-8004 identity and the asset a 402 asks for.
## Verify it yourself (no wallet needed)
curl "https://a-identity.xyz/api/robinhood/check?q=0x5fc5360D0400a0Fd4f2af552ADD042D716F1d168" # real USDG
curl "https://a-identity.xyz/api/robinhood/check?q=0xA913C4C2F28AA7b0B15A7C6008a6e19Ff8Bf85c0" # lookalike
curl "https://a-identity.xyz/api/robinhood/check?q=%230" # agent #0
curl "https://a-identity.xyz/api/robinhood/check?q=%231" # the clone
cast call 0x05a6aad7124c2f1c7b82b03e0bbe3867bc500073 'operator()(address)' --rpc-url https://rpc.mainnet.chain.robinhood.com
Vaults: https://robinhoodchain.blockscout.com/address/0x05a6aad7124c2f1c7b82b03e0bbe3867bc500073
https://arbitrum.blockscout.com/address/0xac6c5c9af62bc482ffeef882a6ac4678513be6db
A-Identity is an independent project, not affiliated with, endorsed by or sponsored by Robinhood,
Paxos or the Arbitrum Foundation.
- 2026-09-16 (47a57d45): the facilitator's daily gas budget is kept per network and per gas unit.
- 2026-09-24/25 (96b6f1e0, d9b1d836): tooling to renew a vault's agent key and to move the agent role
off the owner key, first applied on Arc.
- 2026-09-25 (7ca6c63a): an agent's registration date is read from its mint transaction (applies to
Robinhood Chain #0 and Arbitrum One #1259).
- 2026-09-28 (1e5de58c): CI fails if our EIP-3009 rail (which sells on Robinhood Chain, Arbitrum One,
Base and Arc) answers a paid tool without a 402 challenge.
- 2026-10-01 (1ac21dd5): bugs we found and fixed: Arbitrum One advertised Robinhood Chain's 21000 floor
while its 402 asked 6000; a standard x402 v2 request was read as costing 0; the proof added ETH gas to
USDC gas; our own buyer would have signed a challenge for a lookalike USDG. Now it refuses.
- 2026-10-01 (f7f97a4d, 8870ba99): the pay check for Robinhood Chain and Arbitrum One: engine, JSON API,
/check pages, MCP tool evm_pay_check, ArbSys read, SSRF-safe link fetch.
- 2026-10-01 (1025b198): fixes our verifiers found: a chain read that times out now decides nothing
instead of becoming a verdict; every offer in a 402 is checked, not only the first; Paxos's own
USDG on Arbitrum One reads as real; "Robinhood Chain" written out per its brand guidelines.
- 2026-10-01 (96a61409, 7ee0adca, 45dd024e): public copy corrected (other facilitators serve these
chains; agent #0 is the registry's first token, not "the first agent on the chain"); the vault records
now show the key renewal and the split; an entry page maps window work against the August baseline.
- 2026-10-01 (on-chain, with the tooling above): both vaults' agent keys renewed for 45 days and the
agent role moved off the owner key on Robinhood Chain (txs 0xc68bf160..., 0x47d60109...) and
Arbitrum One (txs 0x237457f6..., 0x1e40db36...); both vaults' source verified on Sourcify.
Bootstrapped and pre-seed: we have not raised external funding. We are open to grants and ecosystem programs, including Arbitrum's, to take the pay check and the spend-limit vault to more Arbitrum chains.