Phenny on behalf of Kingsley Idehen · Grok TTS (leo) · OPTIONS discovery 2026-09-24

One URI. Four outcomes. Linked Open Agentic Commerce — without the browser login UI.

After 401, OPTIONS reveals the offer and seller — discovery only, no credentials — then identity and On-Behalf-Of decide access.

KG curated by kg-generator, rdf-infographic-skill, and Grok on behalf of Kingsley Idehen
DEMONSTRATION · LINKED OPEN AGENTIC COMMERCE

How Linked Open Agentic Commerce works

One URI. Four outcomes. One critical ingredient: cryptographically verifiable identity at Internet and Web scale.

That’s what Linked Open Agentic Commerce (LOAC) facilitates by putting the Web’s existing connectivity infrastructure to work for Agentic Commerce.

It starts with a discovery probe—401, then HTTP OPTIONS—that tells an Agent how to proceed. From there, the same ACL-gated food-bookmark HTML resource can produce four distinct outcomes:

  1. Discovery — an unauthenticated Agent discovers the available authentication mechanisms (the 401 challenge) and access mechanisms (the purchasable offer and its seller, advertised by OPTIONS).
  2. Payment Required (402) — an identified Agent without sufficient access rights is presented with a machine-actionable path to purchase access.
  3. Principal Access (200 OK) — an authenticated and authorized principal receives the resource directly.
  4. On-Behalf-Of Access (200 OK) — an authenticated Agent receives the resource by presenting cryptographically verifiable authority to act on behalf of an authorized principal.

The discovery and Agent 402 Payment Required flows were verified on 2026-09-24; the Principal and On-Behalf-Of (OBO) 200 OK flows were verified on 2026-09-17.

The facilitator is the Web itself: globally addressable resources, open protocols, cryptographically verifiable identities and relationships, and machine-discoverable access controls.

Same URI. Same Web. Four outcomes determined by identity, authorization, and delegation—not by a conventional browser login UI.

Narrated MP4 (3:04) · Grok TTS voice leo · Phenny on behalf of Kingsley Idehen · screencast skill · X status 2100648607712002179

Hero resource (WebID-TLS on :5443): https://linkeddata.uriburner.com/DAV/demos/daas_paid/food-bookmark-collection-snapshot-2026-09-08.html

OutcomeIdentity presentedHTTP outcomeMeaning
1 · Discovery Unauthenticated: anonymous GET, then OPTIONS — no credentials 401 then OPTIONS 204 401 advertises authentication; OPTIONS advertises offer + seller via Link rel=schema:offers (2026-09-24)
2 · Payment Required (Agent alone) Agent certificate; no On-Behalf-Of 302 → 402 ($2.99) Payable challenge; externalId = OPTIONS offer (2026-09-24)
3 · Principal Access (WebID-TLS) Principal PKCS#12 — label + SAN NetID only 200 OK Entitled principal (verified 2026-09-17)
4 · On-Behalf-Of Access (Agent + OBO) Agent cert + OBO: principal NetID URL 200 OK Delegated access (verified 2026-09-17)

DPKI insight. Decentralized Public Key Infrastructure makes protected HTML addressable, governable, and sellable without putting credentials in a chat UI. LOAC maps four outcomes to one URI. Certificate label and SAN NetID only — never a passphrase, never a PEM body; payment JWTs redacted.

Attribution: Phenny on behalf of Kingsley · Grok TTS leo · screencast skill · https://x.com/kidehen/status/2100648607712002179

DISCOVERY · VERIFIED 2026-09-24

Unauthenticated OPTIONS after the first 401

Before Digest, WebID-TLS, or OAuth is chosen, the ACP/UCP client sends a discovery-only OPTIONS to the same URL. No credentials accompany that probe. Live headers captured 2026-09-24 2:21–2:22 PM ET.

StepRequestHTTPWhat was exposedVerified
1 Anonymous GET :443 401 Unauthorized Digest challenge only (nonce / opaque redacted) 2026-09-24
2 Anonymous OPTIONS :443 204 No Content Allow, DAV, rel=meta, rel=acl, and rel="https://schema.org/offers" with seller 2026-09-24
3 Auth selection — Digest, WebID-TLS, or OAuth chosen after offer/seller are known skill rule

Redacted header excerpts (food-bookmark HTML)

# Anonymous GET → 401 (Digest challenge; nonce/opaque redacted)
HTTP/1.1 401 Unauthorized
WWW-Authenticate: Digest realm="http://www.openlinksw.com/ontology/acl#DefaultRealm",
  domain="/DAV", nonce="[REDACTED]", opaque="[REDACTED]", stale="false", qop="auth", algorithm="MD5"

# Anonymous OPTIONS → 204 (discovery only — no credentials sent)
HTTP/1.1 204 No Content
Allow: COPY, DELETE, GET, HEAD, LOCK, MKCOL, MOVE, OPTIONS, PATCH, POST, PROPFIND, PROPPATCH, PUT, TRACE, UNLOCK
DAV: 1,2,<http://www.openlinksw.com/virtuoso/webdav/1.0>
Link: <https://linkeddata.uriburner.com/DAV/demos/daas_paid/food-bookmark-collection-snapshot-2026-09-08.html,meta>; rel="meta"; title="Metadata File"
Link: <https://linkeddata.uriburner.com/DAV/demos/daas_paid/food-bookmark-collection-snapshot-2026-09-08.html,acl>; rel="acl"; title="Access Control File"
Link: <http://data.openlinksw.com/oplweb/offer/FoodBookmarkCollectionHtmlFileAccessOneTimeOfferURIBurner#this>;
  rel="https://schema.org/offers"; type="text/turtle";
  title="Food Bookmark Collection (HTML) — File Access on URIBurner (One-Time Purchase)";
  seller="https://ods-qa.openlinksw.com/shop#this"

Tie-in: the same offer is what the agent’s 402 charges for

Agent WebID-TLS alone on :5443 (no On-Behalf-Of) → 302 then 402 Payment Required. Decoded request JSON (raw base64 and Payment id withheld):

{
  "amount": 299,
  "currency": "usd",
  "externalId": "http://data.openlinksw.com/oplweb/offer/FoodBookmarkCollectionHtmlFileAccessOneTimeOfferURIBurner#this",
  "recipient": "https://ods-qa.openlinksw.com/shop/",
  "methodDetails": { "networkId": "internal", "paymentMethodTypes": ["card", "link"] }
}
# amount 299 = two dollars and ninety-nine cents ($2.99)
# externalId equals the offer IRI discovered by the anonymous OPTIONS probe

Honest gap: the offer IRI did not dereference to Turtle on 2026-09-24 (describe service 406; SPARQL DESCRIBE empty). The ,meta link also required authentication (401). Offer identity and price are taken from the OPTIONS Link and the decoded 402 request — not invented.

sequenceDiagram participant C as ACP/UCP client participant R as URIBurner resource C->>R: GET (anonymous) R-->>C: 401 Unauthorized (Digest challenge) Note over C: Discovery-only probe — no credentials C->>R: OPTIONS (anonymous) R-->>C: 204 + Allow + Link rel=schema:offers (seller) Note over C: Offer and seller known before auth choice C->>C: Choose Digest / WebID-TLS / OAuth alt Agent WebID-TLS alone C->>R: GET :5443 with agent cert R-->>C: 302 then 402 (externalId = same offer, 299 usd) else Principal or agent+OBO C->>R: GET with entitled identity R-->>C: 200 OK (verified 2026-09-17) end
flowchart LR A[Anonymous GET] -->|401| B[OPTIONS probe] B -->|204 Link offers + seller| C{Auth choice} C --> D[Digest] C --> E[WebID-TLS] C --> F[OAuth] E --> G[Principal 200] E --> H[Agent alone 302 then 402] E --> I[Agent + OBO 200] H -.->|externalId = OPTIONS offer| J[Offer IRI] B -.-> J
Executive SummaryBy Kingsley Uyi Idehen · OpenLink Software · 2026-09-24

Synopsis

Conventional browser login UI is the wrong place to settle who may open a protected HTML document. After the first anonymous 401, the client immediately sends an unauthenticated OPTIONS and reads the Link rel="https://schema.org/offers" (with seller) before choosing Digest, WebID-TLS, or OAuth. One URI then yields four outcomes against one ACL-gated food-bookmark collection on URIBurner: discovery → 401 then OPTIONS 204 with offer and seller (verified 2026-09-24); agent alone → 302 then 402 Payment Required at $2.99 with externalId equal to the OPTIONS offer (verified 2026-09-24); principal WebID-TLS → 200 (verified 2026-09-17); agent with On-Behalf-Of → 200 (verified 2026-09-17).

Discovery and agent 402 verified 2026-09-24 · principal and On-Behalf-Of 200 verified 2026-09-17. The hero resource is addressable, governable, and sellable under Linked Open Agentic Commerce (LOAC). The offer IRI from OPTIONS is exactly the externalId in the agent’s 402 payment request (299 cents, usd, recipient https://ods-qa.openlinksw.com/shop/). Phenny posts on behalf of Kingsley Idehen; voice-over is Grok TTS (leo).

View this analysis as a KG entity
How-To

How-To Guide

1

Act 0 — Title frame

Confirm the subject: one URI, four outcomes. Linked Open Agentic Commerce starts with a discovery probe (401, then HTTP OPTIONS) against one protected HTML document — not a login form.

2

Act 1 — Discovery probe

Anonymous GET returns 401. Immediately send unauthenticated OPTIONS. Read Allow and Link rel=https://schema.org/offers (seller). No credentials. Then choose Digest, WebID-TLS, or OAuth.

3

Act 2 — Principal WebID-TLS

Present the principal PKCS#12 (label + SAN NetID only). Expect HTTP 200 OK (verified 2026-09-17).

4

Act 3 — Agent alone

Present the agent certificate without On-Behalf-Of. Expect 302 then 402 at $2.99; decoded request.externalId equals the OPTIONS offer IRI (verified 2026-09-24).

5

Act 4 — Agent + On-Behalf-Of

Same agent certificate plus On-Behalf-Of: principal NetID. Expect HTTP 200 OK (verified 2026-09-17).

6

Act 5 — Scoreboard

Read the four outcomes side by side: Discovery, Agent 402, Principal 200, On-Behalf-Of 200. One URI; offer discovered first; identity, authorization, and delegation decide access.

FAQ

Frequently Asked Questions

Because access here is decided by cryptographic identity and delegation on the HTTP request itself. A form-based login would hide discovery and the distinct outcomes (401→OPTIONS / 302→402 / 200 / OBO 200) behind a single session cookie narrative.

The 401 means authentication is required, but it may advertise only Digest. An immediate unauthenticated OPTIONS often exposes Allow and Link metadata — including rel="https://schema.org/offers" with a seller parameter — so the client can reorient to the merchant offer before choosing Digest, WebID-TLS, or OAuth. Verified live 2026-09-24.

The probe is discovery only. It does not authenticate, purchase, or authorize a retry. Credentials belong to the chosen auth method after offer and seller are known.

Per the ACP/UCP client skill: keep only the information the server actually exposed, and continue through normal authentication-selection. Do not invent offer properties that were not returned.

The Link target from OPTIONS is exactly the externalId in the decoded Payment request on the agent-alone 402 path: amount 299, currency usd, recipient https://ods-qa.openlinksw.com/shop/. Same offer IRI; discovery and payment challenge agree (2026-09-24).

The food-bookmark collection snapshot HTML on linkeddata.uriburner.com under DAV/demos/daas_paid. Ordinary HTTPS uses the default port; WebID-TLS negotiations use the same path on port 5443.

Without On-Behalf-Of, the agent certificate is not the entitled principal. LOAC/MPP responds with a payment challenge (402 Payment Required, 299 cents) instead of the HTML body. The Payment id and raw base64 request blob are redacted; decoded fields are shown.

The same agent certificate plus an On-Behalf-Of header naming the principal NetID URL. Delegation is asserted; the server returns HTTP 200 and the agent receives the resource as acting for the principal (verified 2026-09-17).

Only the certificate label and the SAN NetID URL. Never a passphrase, never a PEM body, never raw private key material. Digest nonce/opaque, Payment id, and raw base64 request are also never shown.

Kingsley Uyi Idehen is the accountable author. Phenny posts on his behalf. Narration uses Grok TTS voice leo. Discovery and agent 302/402 verified 2026-09-24; principal and agent+OBO 200 verified 2026-09-17.

One URI, four outcomes: discovery 401→OPTIONS 204 (offer + seller), agent alone 302→402 ($2.99, same offer), principal WebID-TLS 200, agent+OBO 200 — determined by identity, authorization, and delegation.

Glossary

Glossary of Terms

ACL

Access Control List: rules that map authenticated identities (and delegated agents) to permissions on a resource. The food-bookmark HTML is ACL-gated on URIBurner.

Digital identity

Machine-verifiable claim of who is calling — here proven by WebID-TLS certificate presentation and optional On-Behalf-Of delegation, not by a shared password.

MPP / HTTP 402

Micropayment Protocol pattern using HTTP 402 Payment Required. In this demo the agent-alone path is redirected (302) then challenged with 402 at $2.99 (299 cents). Content is withheld until payment or entitled identity intervenes.

Public-key infrastructure

System of certificates, public keys, and trust anchors used to authenticate parties. WebID-TLS is a decentralized PKI pattern that binds a TLS client cert to a NetID.

Agent vs principal

The principal is the entitled identity that owns access. The agent is a separate certificate holder that may act only when On-Behalf-Of names the principal. Agent alone is not the entitled principal — hence 302→402 instead of 200.

LOAC

Linked Open Agentic Commerce — puts the Web’s existing connectivity infrastructure to work for Agentic Commerce: globally addressable resources, open protocols, cryptographically verifiable identities and relationships, and machine-discoverable access controls. The same resource URI yields four outcomes (Discovery, Payment Required, Principal Access, On-Behalf-Of Access).

NetID

Network identity HTTP URI (WebID) naming a person or agent profile document. Shown in certificate SANs as a URL; never confuse the NetID with a passphrase or PEM body.

WebID-TLS

TLS client-certificate authentication where the certificate SAN carries a WebID (NetID) HTTP URI. The server dereferences that URI to verify the public key binds to the claimed identity. No username/password form is required.

DPKI

Decentralized Public Key Infrastructure: identity and trust anchored in dereferenceable NetIDs and public keys rather than a centralized IdP login GUI. Lets protected HTML stay addressable, governable, and sellable without credentials in a chat or browser form UI.

On-Behalf-Of

HTTP header carrying the principal NetID URL so an agent certificate can assert delegation. With OBO, the agent is authorized as acting for the entitled principal; without it, the agent is treated as a non-entitled caller.

OPTIONS (HTTP)

HTTP method used here as a discovery-only probe after an initial 401. Unauthenticated. Returns Allow and Link metadata without supplying credentials or authorizing a retry.

Link header

HTTP response header advertising related resources. In this demo the OPTIONS 204 includes Link targets for ,meta, ,acl, and the purchasable offer.

rel=https://schema.org/offers

Link relation naming a schema.org Offer associated with the protected resource. Live value on 2026-09-24 pointed at the Food Bookmark Collection one-time file-access offer IRI.

seller parameter (Link)

Extension parameter on the offers Link naming the merchant store. Live value: https://ods-qa.openlinksw.com/shop#this.

Discovery-only probe

The unauthenticated OPTIONS sent immediately after a first 401. It discovers offer and seller; it does not authenticate, purchase, or retry with credentials. If OPTIONS itself returns 401, keep exposed metadata and continue normal auth selection.

Knowledge Graph Explorer 72 nodes · 128 links

Interactive graph visualization derived from the companion RDF. Click nodes to resolve, drag to explore. Graph data embedded from companion RDF at generation time.

One URI. Four outcomes. Linked Open Agentic Commerce — without the browser login UI.

Nodes: 0 Links: 0
Click SVG to activate zoom, click outside to release | Drag nodes to pin, double-click to unpin
Classes Properties Instances

SPARQL Workbench 3 sample queries

Query this knowledge graph on URIBurner. The editor opens on the canonical SAMPLE entity-type summary (DAV named graph). Pick a recipe, edit freely, then run live or copy.

Query editor

▶ Run live on URIBurner SELECT: text/x-html+tr | DESCRIBE/CONSTRUCT: text/x-html-nice-turtle