EffectGuard external-agent pilot
Service: https://effectguard-x402-experiment.onrender.com
Integration: https://effectguard-x402-experiment.onrender.com/agent

Before payments: profile your EXISTING read calls locally with ReadReuseProbe
in effectguard.probe (Python standard library only). See probe_example.py.
The probe executes every callback as usual. Provider charges still apply;
do not issue extra expensive calls just to collect a trace. It performs no
EffectGuard requests and has no signer. Export a private local JSONL file and run:
  python -m effectguard.probe my_reads.jsonl
Include every output/permission-changing parameter in the function inputs.
Use the same scope_id only for processes allowed to share those results.
Synchronize process clocks before combining traces; review clock jumps or
ambiguous call ordering rather than treating them as proven reuse.
Approve reuse explicitly for one JSON read contract. Exported traces omit raw
arguments, results and error messages, but hashes are NOT anonymization.
Only exact matching results after completion and within 30 seconds qualify.
Hits do not reset the TTL. Parallel matching calls, changed results, unapproved
contracts or unknown costs require review and do not produce a complete net result.
The output compares against uncached calls; a local cache may cost less.
After a positive qualification, start with the two-call payment test below.

1. Install requirements.txt in your agent's Python 3.11+ environment.
2. Enroll once: POST /v1/enroll with {}. Store the returned api_key securely.
   Keep the same access across cooperating agents. Each tenant is isolated.
3. Supply your own x402 buyer signer and existing tool callback to
   run_two_read_pilot in agent_example.py. The seller does not need your seed,
   private key or signer credentials. Persist the two logical request IDs first.
4. Run two requests with identical tool inputs within 30 seconds. Expected:
   first EXECUTE, second REUSE; one actual provider call; two paid preflights.
   The spend cap for this example is 0.02 USDC, plus your tool's own charges.
5. Inspect the returned report. Monetary estimates use YOUR marginal tool cost.
   For a flat subscription, use zero unless a call incurs a real extra charge.

Pricing: each NEW logical preflight costs 0.01 USDC, including REUSE, WAIT or
BLOCK. A retry of the same purchased request, /start and /commit are free.
Always retain the same request body and ID after a lost response. An uncertain
payment counts against the in-process budget and stops another signature for
that ID. Persist the IDs and purchase receipts in your runtime before restarting;
the SDK's budget counters belong to one client instance, not a durable wallet spending policy.
Use your wallet/runtime's own durable spend limits for unattended production.

Namespaces must identify one provider, function and schema. Include all inputs
that affect the result or permissions. JSON reads return at most 64 KB.
The 30-second reuse window measures cache age, not source-data freshness.
Use native provider idempotency keys when adopting operation.once separately.

The bundled example requires a real agent/tool integration. It does not claim
external demand or measured savings before you run it. Mainnet settlement at
0.001 USDC and browser same-request recovery were verified on 2026-10-03;
0.01 USDC is the subsequent price experiment, not a validated market price.
