Recomputable Ed25519 ISO 10383 Fail-closed
Standards
Headless Oracle is cryptographically verifiable market-state infrastructure, built so that venue state can be checked from the bytes by anyone holding the public key. The regulator documents that shaped its design are cited below.
What is a Signed Market-State Attestation (SMA)?
A Signed Market-State Attestation (SMA) is a cryptographically signed claim about the current trading state of a regulated venue at a specific moment in time. Every response from Headless Oracle is an SMA: a structured payload describing whether a market is open, closed, in pre-auction, in lunch break, or on an early-close schedule, together with the exchange's ISO 10383 MIC code, an RFC 3339 timestamp, and an Ed25519 signature over the canonical form of the payload.
The design goal is simple: make market state a signed, checkable record rather than an unsigned claim. A smart contract, trading agent, or compliance process can independently validate an SMA against Headless Oracle's published Ed25519 public key, without ever calling back to our service. If the public key verifies the signature, the payload is exactly what Headless Oracle signed. It records Headless Oracle's observation, not a guarantee of fact.
SMAs are short-lived by design. Each attestation carries a 60-second time-to-live, after which downstream consumers must refuse to act on it. This bounds the window in which a stale reading can drive an incorrect decision — a critical property for autonomous systems handling real capital.
Headless Oracle co-authors the IETF draft family defining environmental constraints for Verifiable Intent.
Regulatory References
Two regulator documents shaped this design and are cited here as references, not as approvals: CFTC Staff Letter 25-39 on tokenized collateral (December 2025) and the SEC Crypto Task Force Project Blueprint on Tokenized Collateral (November 2025). Both discuss cryptographic attestation and multiple independent oracles as architectural building blocks, and this operator took its direction from them. No regulator has reviewed or endorsed this service.
Cryptographic signing
Ed25519 signatures
Every response is signed with Ed25519 (RFC 8032). The public key is published at /ed25519-public-key.txt and can be pinned by consumers for deterministic verification without external trust.
Freshness guarantee
60-second TTL
Attestations are valid for 60 seconds from issuance. Consumers must reject expired receipts. This bounds the risk window for autonomous settlement and matches the cadence at which regulated venues publish state transitions.
Venue identification
ISO 10383 MIC codes
Every SMA identifies its venue using the ISO 10383 Market Identifier Code — the same standard used by the SEC, ESMA, and global clearing infrastructure. No ambiguous aliases, no custom identifiers.
Safe defaults
Fail-closed architecture
When Headless Oracle cannot confirm a venue's state with confidence, it returns an explicit unknown with a 4xx status — never a permissive default. Agents treating "unknown" as "open" fail safe.
Note on regulatory status: Headless Oracle is infrastructure, not a regulated financial institution, and no regulator has reviewed or endorsed it. An SMA is evidence that a trading decision was made with reference to authentic, timely venue state; whether that evidence is useful under a given obligation is for the regulated party and its counsel to judge. Consult your compliance counsel for how SMAs fit into your specific regulatory obligations.
Multi-Oracle Verification
A single oracle is a single point of failure — and a single point of trust. For high-value settlement and tokenized collateral flows, we recommend consuming attestations from three or more independent oracles and acting only on majority consensus.
Multi-oracle consensus converts the question "do you trust Headless Oracle?" into "do you trust that three independent operators all signed the same claim?" — a materially stronger guarantee. Divergent readings are a first-class signal: they indicate an upstream venue issue, an oracle outage, or an attempted data-integrity attack, and should trigger a fail-closed response in downstream systems.
3+
Independent oracles recommended for high-value settlement
N-1
Byzantine-fault tolerance: consensus survives one oracle compromise per three
Signed
Every oracle's attestation carries its own Ed25519 signature — trivially aggregatable
Open Standards & Family Specs
environment.market_state is a proposed member of the environment.* constraint family. Sibling implementations cover adjacent constraint surfaces, and an IETF Internet-Draft filed May 11, 2026 formalises the family and vocabulary layer.
Sibling spec
→Sibling Spec: environment.wallet_state
environment.wallet_state, the sibling type in the same family, is specified by Douglas Borthwick, co-author of the environment-state draft.
Standards body
filed · May 11, 2026
IETF Internet-Draft
Family-definition specification for the environment.* constraint family — draft-borthwick-msebenzi-environment-state. Authors: D. Borthwick, InsumerAPI; M. Msebenzi, Headless Oracle. Live at the IETF Datatracker as a citable archive.
28 Global Exchanges
Coverage spans the primary regulated venues across every major time zone, plus the derivatives and 24/7 crypto venues most relevant to autonomous settlement. Every venue is addressed by its ISO 10383 MIC code.
Americas
3 venues- NYSEXNYS
- NASDAQXNAS
- B3 São PauloXBSP
Europe
6 venues- London (LSE)XLON
- Euronext ParisXPAR
- SIX SwissXSWX
- Borsa ItalianaXMIL
- Nasdaq HelsinkiXHEL
- Nasdaq StockholmXSTO
Middle East & North Africa
3 venues- Borsa IstanbulXIST
- Saudi Exchange (Tadawul)XSAU
- Dubai Financial MarketXDFM
Africa
1 venue- Johannesburg (JSE)XJSE
Asia-Pacific
10 venues- Tokyo (TSE)XJPX
- Hong Kong (HKEX)XHKG
- Singapore (SGX)XSES
- Australia (ASX)XASX
- Shanghai (SSE)XSHG
- Shenzhen (SZSE)XSHE
- BSE MumbaiXBOM
- NSE IndiaXNSE
- Korea (KRX)XKRX
- New Zealand (NZX)XNZE
Derivatives & Crypto
5 venues- CMEXCBT
- NYMEXXNYM
- Cboe OptionsXCBO
- Coinbase (24/7)XCOI
- Binance (24/7)XBIN
Total: 28 venues.
Built for the Agentic Economy
Human-facing market data APIs assume a human operator will handle ambiguity, read documentation, and retry on error. Autonomous agents cannot. Headless Oracle is designed for consumers that must act on the response without human mediation.
Model-agnostic
No lock-in to a single LLM provider or agent framework. HTTP, JSON, and standard crypto primitives work for any runtime — from LangGraph and Claude Agent SDK to bespoke Go and Rust stacks.
Protocol-native
Discoverable over MCP for agent runtimes and billable via x402 micropayments. No bespoke SDKs required.
Fail-closed by default
Ambiguous or unverifiable states return an explicit unknown status with a 4xx code. An agent that treats 4xx as "do not act" will always fail safe. Never a 200 with an error body.
Autonomous agent payments
x402 lets an agent pay per-request in USDC on Base with no human-in-the-loop onboarding, no API key provisioning, and no subscription management. The agent settles its own invoice.
For Developers
Every resource below is designed to be consumed by a build tool, an agent runtime, or a CI pipeline — not just a human reading a docs page.
MCP Quickstart
→Drop-in .mcp.json config for Claude Code and compatible agent runtimes.
llms.txt
→Machine-readable API summary for LLM ingestion and agent discovery.
OpenAPI 3.1 spec
→81 paths, strict schemas, fail-closed error contracts. Generate a client in any language.
Sandbox endpoint
→Signed demo responses with no API key required. Start testing in 10 seconds.
Receipt verifier
→Client-side Ed25519 verification — paste a receipt, confirm authenticity without trusting us.
x402 discovery
→Autonomous agent payment metadata — chain, asset, per-request price, settlement address.
Reference verifier (demo-agent)
→~100-line Node.js reference verifier (MIT). Demonstrates fail-closed verification of HO receipts. github.com/headlessoracle/demo-agent
Architectural essays
→Long-form writing on environment-state attestation. Latest: The Trust Primitive, v1.6.4, April 2026 (CC BY 4.0). github.com/headlessoracle/essays
Ready to build on verifiable market state?
Get a free API key in under 10 seconds. No credit card, no signup form.