The second factor for agentic commerce.
AI Agents now discover, negotiate, and order on behalf of businesses. A person types a passcode; an agent cannot. DPUone is the registry factor: the deterministic check a transaction passes before anyone commits — run against a live wire, not taken on trust.
$ curl -sI https://mcp.cpgknowledgegraph.ai/ x-gsc-operator: GreenCore Solutions Corp. x-gsc-protocol: ACM-68000 x-gsc-jurisdiction: FR x-gsc-trust-anchor: dpuone.ai x-gsc-duns: 24-336-6774 x-gsc-timestamp: per-request x-gsc-nonce: per-request
Five parts, one discipline.
| Method | What it is |
|---|---|
| DPU | Digital Proof Unit — the artifact this anchor is named for: a per-GTIN, machine-readable proof object served at /dpu/<gtin>.json, carrying the product, the license, and its compliance state. |
| ECO-10060 | Electronic Compliance Object — the per-jurisdiction compliance object of the SM-ECO-10060 sovereign manifest (fr-eco-10060, uk-eco-10060 …): the territory's rules resolved into a machine-checkable object. |
| Registry 2FA | The second factor for agentic commerce — every transaction claim resolves against this registry before capital moves. Deterministic: it resolves or it stops. |
| HITL | Human-in-the-Loop — GSC Navigator: machine discovery, human confirmation. Every purchase order, RFQ, and escalation is reviewed and approved by a person. |
| Azure | GSC on Microsoft Azure, global and secure — nine regions, sovereign in-country nodes, residency proven on the wire. Microsoft AI Cloud Partner. |
Two factors, no passcode.
Human two-factor authentication proves a person is present. Agentic commerce needs the equivalent for software: proof that what an agent is about to buy — and who it is buying from — resolves against a governed registry before capital moves.
The agent decides.
A buyer's AI Agent forms an order: the SKU, the jurisdiction, the counterparty. Logic, not identity — on its own, unverifiable.
The anchor confirms.
Before execution, the claim is checked against DPUone: the operator's registered identity and D-U-N-S, the GS1-identified artifact in the ledger, the jurisdiction on the wire, and per-request liveness. No resolution, no transaction.
The check is deterministic — a registry lookup and a header read, not a probabilistic guess. A claim either resolves or it does not. Escalation past the boundary goes to a human: Human-in-the-Loop on every purchase order.
Verification is a request, not a promise.
Every surface in the GSC estate answers with its own identity. Send one request to any GSC hostname and read the second factor off the wire.
| Header | Attests |
|---|---|
| x-gsc-node | The emitting surface names itself. |
| x-gsc-jurisdiction | The SM-ECO-10060 member the surface serves under — residency as a checkable claim. |
| x-gsc-operator · x-gsc-duns | GreenCore Solutions Corp., D-U-N-S 24-336-6774. |
| x-gsc-timestamp · x-gsc-nonce | Concrete per-request values — liveness, not cached prose. |
| x-gsc-trust-anchor | This domain. The registry factor itself. |
Signals, members, and the header canon are published open at mcp.cpgagentprotocols.ai — ACM-SPARKS classifies, SM-ECO-10060 resolves, ACM-68000 signals.
The anchored estate
| Surface | Role |
|---|---|
| mcp.cpgknowledgegraph.ai | Data — the CPG Knowledge Graph, powered by SPARKS. |
| mcp.gsc-fleet.ai | Discovery — the Carrier Class fleet. |
| mcp.cpghumanintheloop.ai | Transaction — a human on every purchase order. |
| mcp.cpgagentprotocols.ai | Standards — ACM-SPARKS · SM-ECO-10060 · ACM-68000. |
One subdomain per customer. One ledger per catalog.
Each Beauty & Personal Care maker on the GSC estate is organized as its own subdomain of this anchor — the customer's registrar page, carrying their SKUs as GS1-identified ledger entries their buyers' agents can verify. The first entry on the anchor is GSC itself.
<customer>.dpuone.ai → that maker's SKUs, registered and verifiable
Register a catalog. Verify a counterparty.
BPC makers joining the estate, and counterparties with a verification question, reach the registrar here.