CAIN-42 invariant · E26
I-TXAUTH-pay-binding: pay binding mismatch refused
Held · CAIN-42 Evolution 26 -- Universal Machine Agency Trust Fabric
Last reviewed 2026-10-01
held niche Transactions, markets & economics · family transaction_binding
What this rule means
CAIN-42 must always satisfy: pay binding mismatch refused. It is one of 532 invariants checked for CAIN-42 Evolution 26 -- Universal Machine Agency Trust Fabric. An invariant is a rule the system may never break, whatever an agent or attacker does; the test suite tries to break it across many scenarios and records the result.
Recorded detail
['TRANSACTION_BINDING_MISMATCH:capability_digest']Verify it in your browser
Your browser downloads the bundle's SHA256SUMS manifest and the file(s) behind this page, hashes them with SHA-256 locally (WebCrypto), and compares. A match shows the record you are reading is the published one; it does not by itself prove who published it (see the signed claims registry and the bundle verifier for that).
Check it yourself
Browse the raw bundle · How to reproduce it · SHA-256 manifest
Scope: {"limitation": "In-process trust layer over the E25 fabric. No third-party agent, MCP server or A2A peer has consumed a CAIN trust object.", "status": "SCOPE"}
Related rules
- I-TXAUTH-configure-valid: configure valid spend allowed
- I-TXAUTH-configure-replay: configure replay refused
- I-TXAUTH-configure-binding: configure binding mismatch refused
- I-TXAUTH-configure-expired: configure expired refused
- I-TXAUTH-create-valid: create valid spend allowed
- I-TXAUTH-create-replay: create replay refused
- I-TXAUTH-create-binding: create binding mismatch refused
- I-TXAUTH-create-expired: create expired refused
← I-TXAUTH-pay-replay · all 532 · I-TXAUTH-pay-expired →
Try CAIN-42 on your own agents
Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.
Create a free account → · Try the sandbox · See the whole ecosystem