@prefix dbr: <http://dbpedia.org/resource/> .
@prefix post: <https://x.com/kidehen/status/2100648607712002179#> .
@prefix prov: <http://www.w3.org/ns/prov#> .
@prefix rdfs: <http://www.w3.org/2000/01/rdf-schema#> .
@prefix schema1: <http://schema.org/> .
@prefix xsd: <http://www.w3.org/2001/XMLSchema#> .

<https://linkeddata.uriburner.com/DAV/demos/daas/food-bookmark-webid-tls-obo-ogilvy-grok-2.html> a schema1:WebPage ;
    schema1:about post:articleGrok2 ;
    schema1:dateModified "2026-09-24"^^xsd:date ;
    schema1:headline "One URI. Four outcomes. Linked Open Agentic Commerce — without the browser login UI."@en ;
    schema1:isBasedOn <https://linkeddata.uriburner.com/DAV/demos/daas/food-bookmark-webid-tls-obo-ogilvy-grok-1.html> ;
    schema1:version "grok-2" .

post:callerDiscovery a schema1:Action ;
    schema1:description "Anonymous GET returns 401; unauthenticated OPTIONS returns 204 with Link rel=https://schema.org/offers and seller. Discovery only — no credentials. Verified 2026-09-24."@en ;
    schema1:name "Discovery probe (GET 401 then OPTIONS 204)"@en ;
    schema1:object <https://linkeddata.uriburner.com/DAV/demos/daas_paid/food-bookmark-collection-snapshot-2026-09-08.html> ;
    schema1:result "401 then 204 with offer and seller Links"@en .

post:callerAgentAlone a schema1:Action ;
    schema1:description "Identity: Agent certificate without On-Behalf-Of. Outcome: 302 → 402 Payment Required ($2.99). Decoded request.externalId equals the OPTIONS offer IRI. Verified 2026-09-24."@en ;
    schema1:name "Agent alone"@en ;
    schema1:result "302 → 402 Payment Required ($2.99)"@en .

post:callerAgentObo a schema1:Action ;
    schema1:description "Identity: Agent certificate + On-Behalf-Of: principal NetID URL. Outcome: 200 OK. Delegation asserted; the agent acts for the principal. Verified 2026-09-17."@en ;
    schema1:name "Agent + On-Behalf-Of"@en ;
    schema1:result "200 OK"@en .

post:callerAnonymous a schema1:Action ;
    schema1:description "Identity: No client certificate. Outcome: 401 Unauthorized. Triggers the OPTIONS discovery probe. Verified 2026-09-24."@en ;
    schema1:name "Anonymous GET"@en ;
    schema1:result "401 Unauthorized"@en .

post:callerPrincipal a schema1:Action ;
    schema1:description "Identity: Principal PKCS#12 (label + SAN NetID only). Outcome: 200 OK. Verified 2026-09-17."@en ;
    schema1:name "Principal WebID-TLS"@en ;
    schema1:result "200 OK"@en .

post:optionsProbe a schema1:Action, schema1:HowToStep ;
    schema1:name "Unauthenticated OPTIONS discovery probe"@en ;
    schema1:description "After an initial 401, send OPTIONS with no credentials; read Allow and Link headers for schema.org/offers and seller before choosing Digest, WebID-TLS, or OAuth."@en ;
    schema1:object <https://linkeddata.uriburner.com/DAV/demos/daas_paid/food-bookmark-collection-snapshot-2026-09-08.html> ;
    schema1:result post:discoveredOffer ;
    schema1:position 2 .

post:discoveredOffer a schema1:Offer ;
    schema1:name "Food Bookmark Collection (HTML) — File Access on URIBurner (One-Time Purchase)"@en ;
    schema1:url <http://data.openlinksw.com/oplweb/offer/FoodBookmarkCollectionHtmlFileAccessOneTimeOfferURIBurner#this> ;
    schema1:seller <https://ods-qa.openlinksw.com/shop#this> ;
    schema1:price "2.99" ;
    schema1:priceCurrency "USD" ;
    schema1:description "Offer IRI advertised by OPTIONS Link rel=https://schema.org/offers and named as externalId in the agent 402 Payment request (amount 299 cents). Offer document itself did not dereference on 2026-09-24."@en .

<http://data.openlinksw.com/oplweb/offer/FoodBookmarkCollectionHtmlFileAccessOneTimeOfferURIBurner#this> a schema1:Offer ;
    schema1:name "Food Bookmark Collection (HTML) — File Access on URIBurner (One-Time Purchase)"@en ;
    schema1:seller <https://ods-qa.openlinksw.com/shop#this> .

<https://ods-qa.openlinksw.com/shop#this> a schema1:Organization ;
    schema1:name "ODS-QA Shop"@en ;
    schema1:url <https://ods-qa.openlinksw.com/shop/> .

dbr:Access_control_list a schema1:DefinedTerm ;
    schema1:description "Access Control List: rules that map authenticated identities (and delegated agents) to permissions on a resource. The food-bookmark HTML is ACL-gated on URIBurner."@en ;
    schema1:inDefinedTermSet post:glossaryGrok2 ;
    schema1:name "ACL"@en .

dbr:Digital_identity a schema1:DefinedTerm ;
    schema1:description "Machine-verifiable claim of who is calling — here proven by WebID-TLS certificate presentation and optional On-Behalf-Of delegation, not by a shared password."@en ;
    schema1:inDefinedTermSet post:glossaryGrok2 ;
    schema1:name "Digital identity"@en .

dbr:HTTP_402 a schema1:DefinedTerm ;
    schema1:description "Micropayment Protocol pattern using HTTP 402 Payment Required. Agent-alone path: 302 then 402 at $2.99 (299 cents); externalId matches OPTIONS offer. Verified 2026-09-24."@en ;
    schema1:inDefinedTermSet post:glossaryGrok2 ;
    schema1:name "MPP / HTTP 402"@en .

dbr:Public_key_infrastructure a schema1:DefinedTerm ;
    schema1:description "System of certificates, public keys, and trust anchors used to authenticate parties. WebID-TLS is a decentralized PKI pattern that binds a TLS client cert to a NetID."@en ;
    schema1:inDefinedTermSet post:glossaryGrok2 ;
    schema1:name "Public-key infrastructure"@en .

dbr:Virtuoso_Universal_Server a schema1:SoftwareApplication ;
    schema1:name "OpenLink Virtuoso"@en ;
    schema1:provider dbr:OpenLink_Software ;
    schema1:url <https://virtuoso.openlinksw.com/> .

<https://kingsley.idehen.net/DAV/home/kidehen/Public/YouID/link-in-bio-agent-credentials/index.html#netid> a schema1:Person,
        schema1:SoftwareApplication ;
    schema1:description "Agent NetID for the Phenny secretary acting on behalf of Kingsley Uyi Idehen."@en ;
    schema1:name "Phenny"@en ;
    prov:actedOnBehalfOf <https://www.linkedin.com/in/kidehen#this> .

<https://x.ai/grok> a schema1:SoftwareApplication ;
    schema1:description "xAI language model; Grok TTS voice leo narrates the screencast."@en ;
    schema1:name "Grok"@en .

post:faqGrok2 a schema1:FAQPage ;
    schema1:isPartOf post:articleGrok2 ;
    schema1:mainEntity post:faq1, post:faqWhyOptions, post:faqNoCreds, post:faqOptions401, post:faqTieIn, post:faq2, post:faq4, post:faq5, post:faq6, post:faq7, post:faq8 ;
    schema1:name "Frequently Asked Questions"@en .

post:faq1 a schema1:Question ;
    schema1:acceptedAnswer post:faq1Answer ;
    schema1:name "Why keep the conventional browser login UI out of the way?"@en .
post:faq1Answer a schema1:Answer ;
    schema1:text "Because access here is decided by cryptographic identity and delegation on the HTTP request itself. A form-based login would hide discovery and the distinct outcomes behind a single session cookie narrative."@en .

post:faqWhyOptions a schema1:Question ;
    schema1:acceptedAnswer post:faqWhyOptionsAnswer ;
    schema1:name "Why send OPTIONS after the first 401?"@en .
post:faqWhyOptionsAnswer a schema1:Answer ;
    schema1:text "An immediate unauthenticated OPTIONS often exposes Allow and Link metadata including rel=https://schema.org/offers with a seller parameter, so the client can reorient to the merchant offer before choosing Digest, WebID-TLS, or OAuth."@en .

post:faqNoCreds a schema1:Question ;
    schema1:acceptedAnswer post:faqNoCredsAnswer ;
    schema1:name "Why are no credentials sent on the OPTIONS probe?"@en .
post:faqNoCredsAnswer a schema1:Answer ;
    schema1:text "The probe is discovery only. It does not authenticate, purchase, or authorize a retry."@en .

post:faqOptions401 a schema1:Question ;
    schema1:acceptedAnswer post:faqOptions401Answer ;
    schema1:name "What if OPTIONS also returns 401?"@en .
post:faqOptions401Answer a schema1:Answer ;
    schema1:text "Keep only the information the server actually exposed, and continue through normal authentication-selection."@en .

post:faqTieIn a schema1:Question ;
    schema1:acceptedAnswer post:faqTieInAnswer ;
    schema1:name "How does the OPTIONS offer tie to the agent's 402?"@en .
post:faqTieInAnswer a schema1:Answer ;
    schema1:text "The Link target from OPTIONS is exactly the externalId in the decoded Payment request: amount 299, currency usd, recipient https://ods-qa.openlinksw.com/shop/."@en .

post:faq2 a schema1:Question ;
    schema1:acceptedAnswer post:faq2Answer ;
    schema1:name "What is the hero resource and which port is used for WebID-TLS?"@en .
post:faq2Answer a schema1:Answer ;
    schema1:text "The food-bookmark collection snapshot HTML on linkeddata.uriburner.com under DAV/demos/daas_paid. WebID-TLS uses port 5443."@en .

post:faq4 a schema1:Question ;
    schema1:acceptedAnswer post:faq4Answer ;
    schema1:name "Why does the agent alone receive 302 then 402 at $2.99?"@en .
post:faq4Answer a schema1:Answer ;
    schema1:text "Without On-Behalf-Of, the agent is not the entitled principal. LOAC/MPP returns 402 Payment Required (299 cents). Payment id and raw base64 are redacted."@en .

post:faq5 a schema1:Question ;
    schema1:acceptedAnswer post:faq5Answer ;
    schema1:name "What does On-Behalf-Of add?"@en .
post:faq5Answer a schema1:Answer ;
    schema1:text "The same agent certificate plus On-Behalf-Of naming the principal NetID. Server returns 200 (verified 2026-09-17)."@en .

post:faq6 a schema1:Question ;
    schema1:acceptedAnswer post:faq6Answer ;
    schema1:name "What is shown from the PKCS#12 certificates — and what is never shown?"@en .
post:faq6Answer a schema1:Answer ;
    schema1:text "Only certificate label and SAN NetID URL. Never passphrase, PEM, private key, Digest nonce/opaque, Payment id, or raw base64 request."@en .

post:faq7 a schema1:Question ;
    schema1:acceptedAnswer post:faq7Answer ;
    schema1:name "Who authored and who posted this demonstration?"@en .
post:faq7Answer a schema1:Answer ;
    schema1:text "Kingsley Uyi Idehen is the accountable author. Phenny posts on his behalf. Grok TTS voice leo. Discovery verified 2026-09-24; principal/OBO 200 verified 2026-09-17."@en .

post:faq8 a schema1:Question ;
    schema1:acceptedAnswer post:faq8Answer ;
    schema1:name "What does the scoreboard prove in one line?"@en .
post:faq8Answer a schema1:Answer ;
    schema1:text "One URI, four outcomes: discovery reveals the offer; identity, authorization, and delegation decide access."@en .

post:howtoWalkthroughGrok2 a schema1:HowTo ;
    schema1:description "Follow the narrated screencast: title, OPTIONS discovery after 401, principal 200, agent 302→402 with offer tie-in, agent+OBO 200, scoreboard."@en ;
    schema1:isPartOf post:articleGrok2 ;
    schema1:name "How to read the one-URI, four-outcome walkthrough"@en ;
    schema1:step post:step1, post:stepDiscovery, post:step3, post:step4, post:step5, post:step6 .

post:screencastVideoGrok2 a schema1:VideoObject ;
    schema1:contentUrl <https://linkeddata.uriburner.com/DAV/demos/daas/2026-09-24-food-bookmark-options-discovery-with-voiceover.mp4> ;
    schema1:thumbnailUrl <https://linkeddata.uriburner.com/DAV/demos/daas/food-bookmark-grok-2-poster.jpg> ;
    schema1:description "Narrated screencast: OPTIONS offer discovery after 401, then WebID-TLS / On-Behalf-Of outcomes. Grok TTS voice leo."@en ;
    schema1:duration "PT3M4S" ;
    schema1:encodingFormat "video/mp4" ;
    schema1:name "Food bookmark OPTIONS discovery with WebID-TLS / On-Behalf-Of (with voice-over)"@en ;
    schema1:uploadDate "2026-09-24"^^xsd:date .

post:step1 a schema1:HowToStep ;
    schema1:name "Act 0 — Title frame"@en ;
    schema1:position 1 ;
    schema1:text "Confirm the subject: one URI, four outcomes. Linked Open Agentic Commerce starts with a discovery probe (401, then HTTP OPTIONS) against one protected HTML document."@en .

post:stepDiscovery a schema1:HowToStep ;
    schema1:name "Act 1 — Discovery probe"@en ;
    schema1:position 2 ;
    schema1:text "Anonymous GET returns 401. Send unauthenticated OPTIONS. Read Allow and Link rel=https://schema.org/offers with seller. No credentials. Then choose auth."@en ;
    schema1:url <https://linkeddata.uriburner.com/DAV/demos/daas_paid/food-bookmark-collection-snapshot-2026-09-08.html> .

post:step3 a schema1:HowToStep ;
    schema1:name "Act 2 — Principal WebID-TLS"@en ;
    schema1:position 3 ;
    schema1:text "Present the principal PKCS#12 (label + SAN NetID only). Expect HTTP 200 OK (verified 2026-09-17)."@en .

post:step4 a schema1:HowToStep ;
    schema1:name "Act 3 — Agent alone"@en ;
    schema1:position 4 ;
    schema1:text "Agent certificate without On-Behalf-Of. Expect 302 then 402 at $2.99; externalId equals OPTIONS offer (verified 2026-09-24)."@en .

post:step5 a schema1:HowToStep ;
    schema1:name "Act 4 — Agent + On-Behalf-Of"@en ;
    schema1:position 5 ;
    schema1:text "Same agent certificate plus On-Behalf-Of: principal NetID. Expect HTTP 200 OK (verified 2026-09-17)."@en .

post:step6 a schema1:HowToStep ;
    schema1:name "Act 5 — Scoreboard"@en ;
    schema1:position 6 ;
    schema1:text "Read the four outcomes side by side: Discovery, Agent 402, Principal 200, On-Behalf-Of 200."@en .

post:termOPTIONS a schema1:DefinedTerm ;
    schema1:name "OPTIONS (HTTP)"@en ;
    schema1:description "HTTP method used as a discovery-only probe after an initial 401. Unauthenticated. Returns Allow and Link metadata without credentials."@en ;
    schema1:inDefinedTermSet post:glossaryGrok2 .

post:termLinkHeader a schema1:DefinedTerm ;
    schema1:name "Link header"@en ;
    schema1:description "HTTP response header advertising related resources including meta, acl, and schema.org offers."@en ;
    schema1:inDefinedTermSet post:glossaryGrok2 .

post:termSchemaOffers a schema1:DefinedTerm ;
    schema1:name "rel=https://schema.org/offers"@en ;
    schema1:description "Link relation naming a schema.org Offer associated with the protected resource."@en ;
    schema1:inDefinedTermSet post:glossaryGrok2 .

post:termSellerParam a schema1:DefinedTerm ;
    schema1:name "seller parameter (Link)"@en ;
    schema1:description "Extension parameter on the offers Link naming the merchant store (https://ods-qa.openlinksw.com/shop#this)."@en ;
    schema1:inDefinedTermSet post:glossaryGrok2 .

post:termDiscoveryProbe a schema1:DefinedTerm ;
    schema1:name "Discovery-only probe"@en ;
    schema1:description "Unauthenticated OPTIONS after a first 401. Discovers offer and seller; does not authenticate, purchase, or retry with credentials."@en ;
    schema1:inDefinedTermSet post:glossaryGrok2 .

post:termAgentVsPrincipal a schema1:DefinedTerm ;
    schema1:description "The principal is the entitled identity that owns access. The agent may act only when On-Behalf-Of names the principal."@en ;
    schema1:inDefinedTermSet post:glossaryGrok2 ;
    schema1:name "Agent vs principal"@en .

post:termLOAC a schema1:DefinedTerm ;
    schema1:description "Linked Open Agentic Commerce — puts the Web's existing connectivity infrastructure to work for Agentic Commerce: globally addressable resources, open protocols, cryptographically verifiable identities and relationships, and machine-discoverable access controls."@en ;
    schema1:inDefinedTermSet post:glossaryGrok2 ;
    schema1:name "LOAC"@en .

post:termNetID a schema1:DefinedTerm ;
    schema1:description "Network identity HTTP URI (WebID) naming a person or agent profile document."@en ;
    schema1:inDefinedTermSet post:glossaryGrok2 ;
    schema1:name "NetID"@en .

dbr:WebID a schema1:DefinedTerm ;
    schema1:description "TLS client-certificate authentication where the certificate SAN carries a WebID (NetID) HTTP URI."@en ;
    schema1:inDefinedTermSet post:glossaryGrok2 ;
    schema1:name "WebID-TLS"@en .

<https://linkeddata.uriburner.com/DAV/demos/daas_paid/food-bookmark-collection-snapshot-2026-09-08.html> a schema1:WebPage ;
    schema1:description "ACL-gated HTML collection on URIBurner DAV demos/daas_paid. WebID-TLS on port 5443."@en ;
    schema1:name "Food bookmark collection snapshot (2026-09-08)"@en ;
    schema1:url <https://linkeddata.uriburner.com/DAV/demos/daas_paid/food-bookmark-collection-snapshot-2026-09-08.html> ;
    schema1:offers <http://data.openlinksw.com/oplweb/offer/FoodBookmarkCollectionHtmlFileAccessOneTimeOfferURIBurner#this> ;
    rdfs:seeAlso <https://linkeddata.uriburner.com:5443/DAV/demos/daas_paid/food-bookmark-collection-snapshot-2026-09-08.html> .

post:termDPKI a schema1:DefinedTerm ;
    schema1:description "Decentralized Public Key Infrastructure: identity and trust anchored in dereferenceable NetIDs and public keys."@en ;
    schema1:inDefinedTermSet post:glossaryGrok2 ;
    schema1:name "DPKI"@en .

post:termOnBehalfOf a schema1:DefinedTerm ;
    schema1:description "HTTP header carrying the principal NetID URL so an agent certificate can assert delegation."@en ;
    schema1:inDefinedTermSet post:glossaryGrok2 ;
    schema1:name "On-Behalf-Of"@en .

dbr:OpenLink_Software a schema1:Organization ;
    schema1:name "OpenLink Software"@en ;
    schema1:url <https://www.openlinksw.com/> .

<https://www.linkedin.com/in/kidehen#this> a schema1:Person ;
    schema1:jobTitle "Founder & CEO"@en ;
    schema1:name "Kingsley Uyi Idehen"@en ;
    schema1:url <https://www.linkedin.com/in/kidehen> ;
    schema1:worksFor dbr:OpenLink_Software .

post:articleGrok2 a schema1:Article, schema1:TechArticle ;
    schema1:about dbr:WebID, <https://linkeddata.uriburner.com/DAV/demos/daas_paid/food-bookmark-collection-snapshot-2026-09-08.html>, post:termDPKI, post:termOnBehalfOf, post:termDiscoveryProbe, <http://data.openlinksw.com/oplweb/offer/FoodBookmarkCollectionHtmlFileAccessOneTimeOfferURIBurner#this> ;
    schema1:abstract "After the first anonymous 401, the client sends an unauthenticated OPTIONS and reads Link rel=https://schema.org/offers (with seller) before choosing Digest, WebID-TLS, or OAuth. The same URI then yields four outcomes: discovery 401→OPTIONS 204 with offer and seller (2026-09-24); agent alone 302→402 at $2.99 with externalId equal to the OPTIONS offer (2026-09-24); principal WebID-TLS 200 (2026-09-17); agent with On-Behalf-Of 200 (2026-09-17)."@en ;
    schema1:accountablePerson <https://www.linkedin.com/in/kidehen#this> ;
    schema1:alternativeHeadline "After 401, OPTIONS reveals the offer and seller — discovery only, no credentials — then identity and On-Behalf-Of decide access."@en ;
    schema1:author <https://www.linkedin.com/in/kidehen#this> ;
    schema1:citation <https://x.com/kidehen/status/2100648607712002179> ;
    schema1:contributor <https://kingsley.idehen.net/DAV/home/kidehen/Public/YouID/link-in-bio-agent-credentials/index.html#netid> ;
    schema1:datePublished "2026-09-17"^^xsd:date ;
    schema1:dateModified "2026-09-24"^^xsd:date ;
    schema1:description "One URI, four outcomes: Linked Open Agentic Commerce on the Web's existing infrastructure. After an initial 401, an unauthenticated OPTIONS discovers the schema.org offer and seller; then Agent 402 Payment Required, Principal 200, and On-Behalf-Of 200 against the same ACL-gated food-bookmark HTML, all determined by cryptographically verifiable identity, authorization, and delegation."@en ;
    schema1:hasPart post:faqGrok2, post:glossaryGrok2, post:howtoWalkthroughGrok2 ;
    schema1:headline "One URI. Four outcomes. Linked Open Agentic Commerce — without the browser login UI."@en ;
    schema1:isBasedOn <https://linkeddata.uriburner.com/DAV/demos/daas/food-bookmark-webid-tls-obo-ogilvy-grok-1.html>, <https://x.com/kidehen/status/2100648607712002179> ;
    schema1:keywords "OPTIONS, schema.org/offers, seller, WebID-TLS, On-Behalf-Of, DPKI, LOAC, HTTP 402, ACL, NetID, agent delegation, URIBurner, discovery probe"@en ;
    schema1:mentions dbr:Virtuoso_Universal_Server, <https://x.ai/grok>, <https://ods-qa.openlinksw.com/shop#this> ;
    schema1:name "One URI. Four outcomes. Linked Open Agentic Commerce — without the browser login UI."@en ;
    schema1:publisher dbr:OpenLink_Software ;
    schema1:video post:screencastVideoGrok2 ;
    schema1:version "grok-2" ;
    rdfs:seeAlso <https://linkeddata.uriburner.com/DAV/demos/daas/food-bookmark-webid-tls-obo-ogilvy-grok-2.jsonld>, <https://linkeddata.uriburner.com/DAV/demos/daas/food-bookmark-webid-tls-obo-ogilvy-grok-2.ttl>, <https://linkeddata.uriburner.com/DAV/demos/daas/food-bookmark-webid-tls-obo-ogilvy-grok-1.html>, <https://x.com/kidehen/status/2100648607712002179> ;
    prov:wasDerivedFrom <https://linkeddata.uriburner.com/DAV/demos/daas/food-bookmark-webid-tls-obo-ogilvy-grok-1.html>, <https://x.com/kidehen/status/2100648607712002179> .

<https://x.com/kidehen/status/2100648607712002179> a schema1:SocialMediaPosting ;
    schema1:author <https://www.linkedin.com/in/kidehen#this> ;
    schema1:datePublished "2026-09-17"^^xsd:date ;
    schema1:headline "Same protected HTML. Four callers. Four outcomes. DPKI without credentials in the chat UI."@en ;
    schema1:url <https://x.com/kidehen/status/2100648607712002179> .

post:glossaryGrok2 a schema1:DefinedTermSet ;
    schema1:description "Terms used in the food-bookmark OPTIONS discovery + WebID-TLS / On-Behalf-Of demonstration (grok-2)."@en ;
    schema1:hasDefinedTerm dbr:Access_control_list, dbr:Digital_identity, dbr:HTTP_402, dbr:Public_key_infrastructure, dbr:WebID, post:termAgentVsPrincipal, post:termDPKI, post:termLOAC, post:termNetID, post:termOnBehalfOf, post:termOPTIONS, post:termLinkHeader, post:termSchemaOffers, post:termSellerParam, post:termDiscoveryProbe ;
    schema1:isPartOf post:articleGrok2 ;
    schema1:name "Core Technical Glossary"@en .
