Headless Oracle

Recomputable Ed25519 ISO 10383 Fail-closed

Standards

Headless Oracle is cryptographically verifiable market-state infrastructure, built so that venue state can be checked from the bytes by anyone holding the public key. The regulator documents that shaped its design are cited below.

What is a Signed Market-State Attestation (SMA)?

A Signed Market-State Attestation (SMA) is a cryptographically signed claim about the current trading state of a regulated venue at a specific moment in time. Every response from Headless Oracle is an SMA: a structured payload describing whether a market is open, closed, in pre-auction, in lunch break, or on an early-close schedule, together with the exchange's ISO 10383 MIC code, an RFC 3339 timestamp, and an Ed25519 signature over the canonical form of the payload.

The design goal is simple: make market state a signed, checkable record rather than an unsigned claim. A smart contract, trading agent, or compliance process can independently validate an SMA against Headless Oracle's published Ed25519 public key, without ever calling back to our service. If the public key verifies the signature, the payload is exactly what Headless Oracle signed. It records Headless Oracle's observation, not a guarantee of fact.

SMAs are short-lived by design. Each attestation carries a 60-second time-to-live, after which downstream consumers must refuse to act on it. This bounds the window in which a stale reading can drive an incorrect decision — a critical property for autonomous systems handling real capital.

Headless Oracle co-authors the IETF draft family defining environmental constraints for Verifiable Intent.

Regulatory References

Two regulator documents shaped this design and are cited here as references, not as approvals: CFTC Staff Letter 25-39 on tokenized collateral (December 2025) and the SEC Crypto Task Force Project Blueprint on Tokenized Collateral (November 2025). Both discuss cryptographic attestation and multiple independent oracles as architectural building blocks, and this operator took its direction from them. No regulator has reviewed or endorsed this service.

Cryptographic signing

Ed25519 signatures

Every response is signed with Ed25519 (RFC 8032). The public key is published at /ed25519-public-key.txt and can be pinned by consumers for deterministic verification without external trust.

Freshness guarantee

60-second TTL

Attestations are valid for 60 seconds from issuance. Consumers must reject expired receipts. This bounds the risk window for autonomous settlement and matches the cadence at which regulated venues publish state transitions.

Venue identification

ISO 10383 MIC codes

Every SMA identifies its venue using the ISO 10383 Market Identifier Code — the same standard used by the SEC, ESMA, and global clearing infrastructure. No ambiguous aliases, no custom identifiers.

Safe defaults

Fail-closed architecture

When Headless Oracle cannot confirm a venue's state with confidence, it returns an explicit unknown with a 4xx status — never a permissive default. Agents treating "unknown" as "open" fail safe.

Note on regulatory status: Headless Oracle is infrastructure, not a regulated financial institution, and no regulator has reviewed or endorsed it. An SMA is evidence that a trading decision was made with reference to authentic, timely venue state; whether that evidence is useful under a given obligation is for the regulated party and its counsel to judge. Consult your compliance counsel for how SMAs fit into your specific regulatory obligations.

Multi-Oracle Verification

A single oracle is a single point of failure — and a single point of trust. For high-value settlement and tokenized collateral flows, we recommend consuming attestations from three or more independent oracles and acting only on majority consensus.

Multi-oracle consensus converts the question "do you trust Headless Oracle?" into "do you trust that three independent operators all signed the same claim?" — a materially stronger guarantee. Divergent readings are a first-class signal: they indicate an upstream venue issue, an oracle outage, or an attempted data-integrity attack, and should trigger a fail-closed response in downstream systems.

3+

Independent oracles recommended for high-value settlement

N-1

Byzantine-fault tolerance: consensus survives one oracle compromise per three

Signed

Every oracle's attestation carries its own Ed25519 signature — trivially aggregatable

Open Standards & Family Specs

environment.market_state is a proposed member of the environment.* constraint family. Sibling implementations cover adjacent constraint surfaces, and an IETF Internet-Draft filed May 11, 2026 formalises the family and vocabulary layer.

28 Global Exchanges

Coverage spans the primary regulated venues across every major time zone, plus the derivatives and 24/7 crypto venues most relevant to autonomous settlement. Every venue is addressed by its ISO 10383 MIC code.

Americas

3 venues
  • NYSEXNYS
  • NASDAQXNAS
  • B3 São PauloXBSP

Europe

6 venues
  • London (LSE)XLON
  • Euronext ParisXPAR
  • SIX SwissXSWX
  • Borsa ItalianaXMIL
  • Nasdaq HelsinkiXHEL
  • Nasdaq StockholmXSTO

Middle East & North Africa

3 venues
  • Borsa IstanbulXIST
  • Saudi Exchange (Tadawul)XSAU
  • Dubai Financial MarketXDFM

Africa

1 venue
  • Johannesburg (JSE)XJSE

Asia-Pacific

10 venues
  • Tokyo (TSE)XJPX
  • Hong Kong (HKEX)XHKG
  • Singapore (SGX)XSES
  • Australia (ASX)XASX
  • Shanghai (SSE)XSHG
  • Shenzhen (SZSE)XSHE
  • BSE MumbaiXBOM
  • NSE IndiaXNSE
  • Korea (KRX)XKRX
  • New Zealand (NZX)XNZE

Derivatives & Crypto

5 venues
  • CMEXCBT
  • NYMEXXNYM
  • Cboe OptionsXCBO
  • Coinbase (24/7)XCOI
  • Binance (24/7)XBIN

Total: 28 venues.

Built for the Agentic Economy

Human-facing market data APIs assume a human operator will handle ambiguity, read documentation, and retry on error. Autonomous agents cannot. Headless Oracle is designed for consumers that must act on the response without human mediation.

Model-agnostic

No lock-in to a single LLM provider or agent framework. HTTP, JSON, and standard crypto primitives work for any runtime — from LangGraph and Claude Agent SDK to bespoke Go and Rust stacks.

Protocol-native

Discoverable over MCP for agent runtimes and billable via x402 micropayments. No bespoke SDKs required.

Fail-closed by default

Ambiguous or unverifiable states return an explicit unknown status with a 4xx code. An agent that treats 4xx as "do not act" will always fail safe. Never a 200 with an error body.

Autonomous agent payments

x402 lets an agent pay per-request in USDC on Base with no human-in-the-loop onboarding, no API key provisioning, and no subscription management. The agent settles its own invoice.

For Developers

Every resource below is designed to be consumed by a build tool, an agent runtime, or a CI pipeline — not just a human reading a docs page.

Ready to build on verifiable market state?

Get a free API key in under 10 seconds. No credit card, no signup form.